1. Mediaite
  2. Gossip Cop
  3. Geekosystem
  4. Styleite
  5. SportsGrid
  6. The Mary Sue
  7. The Jane Dough

Exclusive: ‘Gnosis’ Explains The Method And Reasoning Behind Gawker Media Hack

exclusive
» 18 comments

Over the last 24 hours Gawker Media’s network of sites have been under attack from a group who have identified themselves “Gnosis,” a seemingly mysterious collective of hackers who has been falsely considered part of the 4chan-related group of renegade vigilantes knows as Anonymous. Via several private email exchanges with Mediaite, an individual claiming to represent “Gnosis” has explained both the reasoning and methodology of his actions, which has led to a compromised commenter database and a content management system.

First and foremost, it appears that new Gawker Media passwords are secure, not available to the individual claiming responsibility for the security breach, at least according to Gnosis. As Mediaite reported earlier, when asked why Gawker was being subjected to a cyber-attack, Gnosis cited “arrogance” from management and staff with regard to the hacker community:

We went after Gawker because of their outright arrogance. It took us a few hours to find a way to dump all their source code and a bit longer to find a way into their database.

We found an interesting quote in their Campfire logs:

Hamilton N.: Nick Denton Says Bring It On 4Chan, Right to My Home Address (After
The Jump)

Ryan T.: We Are Not Scared of 4chan Here at 210 Elizabeth St NY NY 10012

I mean if you say things like that, and attack sites like 4chan (Which we are not affiliated to) you must at least have the means to back yourself up. We considered what action we would take, and decided that the Gawkmedia “empire” needs to be brought down a peg or two. Our groups mission? We don’t have one.

We will be releasing the full source code dump along with the database at 9PM GMT today. You are the only outlet we have told the release time.

When asked about further explanation about the specific attacks, Gnosis explained:

We cannot provide any more information as to how the attack was carried out, because this could be used against us.

We have been cracking the database for about 17 hours and have managed to retrieve 273,789 passwords. If our release schedule wasn’t so tight we could get 500,000+. Included in the dump are passwords linked to accounts from Nasa, about every .gov domain you could imagine and hundreds from banks. One can only pray that they do not use the same password everywhere. The actual database size is 1,247,897 rows, which is 80+% of their database.

(Private data redacted)

We have had access to all of their emails for a long time as well as most of their infrastructure powering the site. Gawkmedia has possibly the worst security I have ever seen. It is scary how poor it is. Their servers run horribly outdated kernel versions, their site is filled with numerous exploitable code and their database is publicly accessible.

We will be releasing the full source code to their site as well as the full database dump later today or tomorrow, when we get enough press to stir up the release. We will also be releasing a text file describing Gawkers numerous security failings.

Regards,
~Gnosis

Adding later in a follow up email:

The database is for the media more than anything. Releasing the source code to a site is all very well and will cause a splash, but
only niche users will be interested in viewing it and sharing it, because the average joe won’t really care about Gawkers (rather
interesting) PHP framework. However if we release the source with 1,300,000 emails and with a portion of them cracked it will (We hope) cause a bigger stir.

On an interesting side note there are 2650 users in the database using the password “password” or “querty”. Of these users one is registered under a .gov email address, 3 are from a .mil addres and 52 are from .edu addresses.

Finally, when asked if any future attacks were planned, Gnosis offered the following:

Nope, not right now. They didn’t like their frontpage being defaced with that post, so they have locked down pretty tight. We will still work on it for a while.

We don’t like being lumped with 4chan though, but I guess it was inevitable. People on twitter are saying “4chan’s Gnosis hacked Gawker”.

The email exchange came to us after our first report was published Saturday afternoon and was conducted with an individual using an untraceable email account. Also, Mediaite has shared some relevant information with Gawker sources to confirm the veracity of the hacker’s allegations, which in hindsight, have all been right on the money.

Follow us on Twitter.

Sign up for Mediaite's daily newsletter.

Email Twitter Facebook Digg Reddit Stumble Upon Yahoo Buzz LinkedIn Tumblr Delicious
  • Pablo

    It’s just the truth, right? How can that be wrong? Yay for transparency!

  • Magister

    First and foremost, it appears that new Gawker Media passwords are secure, not available to the individual claiming responsibility for the security breach, at least according to Gnosis.

    I’m highlighting the above because it appears to answer a question that’s been on a lot of people’s minds.

  • skyfet

    You are creating your own news. Get a life!

  • Just4thefax

    Fact: I posted two days ago.
    Fact: It’s clear to me that he formulated the same view as most journalist types that all have a right to know all things no matter what’s at stake. Just as Nancy Pelosi stated that we the democrats will be the most transparently ran government in history. Well you got it now Nancy and the goods are coming out so the swamp may still be drained. Can’t blame Bush for this one also. I on the other hand as do as Sarah believe that only people with a need to know clearance needs to know. Time now is dissemination time to flood the area with multiple leaks to fog or mask the real information so that all information leaked is shrouded with doubt. That’s the fact. I still stand by this statement!

  • http://www.facebook.com/people/Jon-Martin/43100610 Jon Martin

    Pablo said:
    It’s just the truth, right? How can that be wrong? Yay for transparency!

    You’re comparing hacking a website that has Lindsay Lohan stories everyday to Julian Assange being GIVEN confidential information?

    You have a really unfortunate outlook on the truth… and you make really bad comparison XD

    Honestly though, it’s scary that you can’t draw a distinction betweent he two. How does your brain work? Do you really say such dumb things on purpose?

  • http://www.facebook.com/people/Jon-Martin/43100610 Jon Martin

    Just4thefax said:
    Fact: I posted two days ago.
    Fact: It’s clear to me that he formulated the same view as most journalist types that all have a right to know all things no matter what’s at stake. Just as Nancy Pelosi stated that we the democrats will be the most transparently ran government in history. Well you got it now Nancy and the goods are coming out so the swamp may still be drained. Can’t blame Bush for this one also. I on the other hand as do as Sarah believe that only people with a need to know clearance needs to know. Time now is dissemination time to flood the area with multiple leaks to fog or mask the real information so that all information leaked is shrouded with doubt. That’s the fact. I still stand by this statement!

    Not really digging the new avatar. Also, here’s the definition of fact.

    A piece of information about circumstances that exist or events that have occurred;

    See? Now you know what a fact is :)

  • tws258

    Let’s hope that someone had the good sense to open these” private”e-mails on a stand alone computer.

  • Just4thefax

    Jon Martin said:
    You’re comparing hacking a website that has Lindsay Lohan stories everyday to Julian Assange being GIVEN confidential information? You have a really unfortunate outlook on the truth… and you make really bad comparison XD Honestly though, it’s scary that you can’t draw a distinction betweent he two. How does your brain work? Do you really say such dumb things on purpose?

    Jon Martin said:
    Not really digging the new avatar. Also, here’s the definition of fact. A piece of information about circumstances that exist or events that have occurred; See? Now you know what a fact is :)

    Fact: All your post are a shadow of your being and seeing that liberal socialism flows out your pores it a fact that you were born to fail!

    Fact: Liberals have a genetic brain disorder that allows them to lie about their real surroundings that no medication can cure the proper neurons to fire. This disorder allows them to know so much that isn’t so, hear so much that isn’t said. Causes kleptomania for other people belongings just because they believe they deserve it. The liberal disease Causes severe lack to want to work for a living and a need and desire to want to live off others incomes.

  • Just4thefax

    Jon Martin said:
    Not really digging the new avatar. Also, here’s the definition of fact. A piece of information about circumstances that exist or events that have occurred; See? Now you know what a fact is :)

    Fact: The word Fact: can also be used as a call sign. Hey dipshit look up dipshit!

  • JulianAssange

    This is Julian Assange. Gnosis is one of my many operations under the banner of wikileaks. We of wikileaks request a sovereign nation somewhere in the middle east or we will unleash upon you a plague of epic proportions.

  • Pablo

    Jon Martin said:
    You’re comparing hacking a website that has Lindsay Lohan stories everyday to Julian Assange being GIVEN confidential information?

    Whoever this is they’re revealing illegally obtained material. I’m constantly told lately that releasing the truth is always a good thing, regardless of how that truth comes to light. Do you agree or disagree? And what is your Social Security number?

  • benben

    An open letter to the dudes who hacked Gawker Media

    Gawker is a site that’s easy to hate, we know this. We’re sure that plenty of people were taking lots of joy in Nick Denton’s misery today. But the thing that bothers us about that stance is that, as harsh as Gawker and Denton come across sometimes, they prove they’re worth their weight in salt every time they get a scoop. When it comes to the Web, nobody tops them, honestly.

    * Why they’re unique They’re not afraid of taking on the tawdry story because it’s tawdry. They’re not afraid of paying a source because it requires paying a source. They’re not against digging into rumors just because they’re rumors. And they know just when to play each of those hands.
    * Why they matter As much as we’d like to hate Gawker and its sister sites for being the most arrogant content network on the entire internet, every time we want to hate them, they do something really freaking cool. They make reading the news online worthwhile, ‘cause they get it.
    * They hate you? So what? Gawker talks crap about 4chan or Anonymous or whomever? So what. They talk crap about everybody. And they deserve to get away with it. Because unlike the gossip sources of yore (think National Enquirer), they actually have substance. source

    » Oh yeah: One thing we cannot and will not get behind is making a million and a half commenters pawns in this silly game. Gawker may deserve it (to some degree), but the readers aren’t worth getting crapped on. We feel bad for them more than anyone else in this endeavor.

  • raincoaster

    Well, it IS funny to watch some tard commenting under Choire’s account. I don’t think there’s any particular reason to take this so seriously, if you’re not Nick Denton. There’s zero evidence that people’s emails have been interfered with, or that anyone has lost any money or had their commenter identities revealed to people who really could stir up shit. If those things had happened, that would have been heinous and worthy of outrage. All that actually happened was one post went up exposing Gawker’s weakness, and much talk was generated which presumably convinced people to stop using “Password” and “qwerty” as their passwords.

    It’s not as if there’s much else happening on Gawker on a Sunday evening.

  • erincnyc

    The whole thing strikes me as silly. Wow, you’ve taken down a gossip site for an evening. Freaked out a bunch of snarky liberals for a second. Congratulations!

    What I find even funnier is why, if Gnosis is not related to 4chan or anonymous, Gnosis cares if some people who write for Gawker make fun of 4chan? I mean, to go to this much trouble because someone at 4chan got his feelings hurt? I haven’t noticed Gawker takes any swipes at anonymous, so I don’t understand where such allegations come from.

    And, really, let’s get to the most important point. Instead of screwing around with a gossip site and freaking out snarky liberals, don’t you think your time would be better spent posting torrents for Black Swan and Morning Glory? I’ve been waiting forever.

  • Just4thefax

    Fact: Disinformation is intentionally false or inaccurate information that is spread deliberately. It is synonymous with and sometimes called black propaganda. It may include the distribution of forged documents, manuscripts, and photographs, or spreading malicious rumors and fabricated intelligence. Disinformation should not be confused with misinformation, information that is unintentionally false.In espionage or military intelligence, disinformation is the deliberate spreading of false information to mislead an enemy as to one’s position or course of action. Might have a few rumors in the fog of deception to hide the real truth of leaked matterials here. Just saying?

  • http://www.verumserum.com John VS

    This is one hack that I can’t help but enjoy. The folks at Gawker have been such bastards in the recent past. I’m sure if Gnosis wanted to leak some of the behind the scenes e-mails relating to that sleazy Christine O’Donnell story, those would make the rounds.

  • Henry Vaughn

    If these people can hack into all these sites then why in the hell can’t I! All I want is someone – any one to help me take down hate sites on youtube – I’ve been doin some homework:

    While YouTube is an American phenomenon that provides a lot of enjoyment, it also contains hate. I’d go so far as to call many of the videos evil. The practical reality is that Google receives revenue from advertisements that accompany videos on its free video sharing site.

    http://techcrunch.com/2006/09/21/youtubes-magic-number-15-billion

    YouTube recently announced that 24 hours of video are uploaded every minute! There’s nothing inherently evil about free enterprise conducted in this manner except that to monitor the enormous amount of footage uploaded every day would cost a lot of money. However, Google’s guidelines for removal are narrow, thereby giving evil a place to flourish.

    Where Does YouTube Draw the Line?
    http://www.google.com/support/forum/p/youtube/thread?tid=4cf338888d00f758&hl=en

    YouTube’s TOS says: We encourage free speech and defend everyone’s right to express unpopular points of view. But we don’t permit hate speech (speech that attacks or demeans a group based on race or ethnic origin, religion, disability, gender, age, veteran status, and sexual orientation/gender identity).

    The pro-pedophilia movement says that pedophilia is a “sexual orientation;” therefore, YouTube won’t remove pro-pedophilia videos. I have asked. Many times. When contacted through YouTube’s protocol for reporting objectionable videos, they respond as follows:

    Hi there,

    We’ve been unable to identify a Community Guidelines violation ( http://www.youtube.com/t/community_guidelines ) with the content in question. We would encourage you to attempt to resolve any continuing issues directly with the uploader of the content in question. You may be able to contact the user through YouTube’s private messaging feature. Instructions on how to use this feature can be found at the following link:

    http://www.google.com/support/youtube/bin/answer.py?hlrm=en&answer=57955

    Sincerely,

    The YouTube Team

    the Fed’s just took this site down and now it’s back up!!? what nerve –

    http://www.youtube.com/user/CasperFriendly1

    That’s just ONE – out of many!

    Because YouTube will not act according to generally accepted community standards regarding what is uploaded to their website, I see no alternative but to remove these videos surreptitiously. IF I ONLY KNEW HOW….. hello hackers out there.

    I’ve read the Computer Fraud and Abuse Act. Even YouTube doesn’t consider the removal of videos by someone other than the account holder to be illegal hacking. They call this occurrence an “account compromise.”

    Thank you for taking the time to read this commen and view the links. If someone could just give me a hint on how to take those evil sites down……… bluejewel100@yahoo.com (a dummy email for purposes just like this)

    HV

  • http://www.facebook.com/people/Lisa-Downey-Merriam/587607462 Lisa Downey Merriam

    This is really no different from the people breaking store windows at WTO summits. Cyber-vandalism against brands is growing for the same reason as real brand vandalism took off–it works. Brands are an accessible and easy way to get attention and dramatize a message: http://bit.ly/f64afo

© 2012 Mediaite, LLC | About Us | Advertise | Self-Serve Advertising | Newsletter | Jobs | Privacy | User Agreement | Disclaimer | Power Grid FAQ | Contact | Archives | RSS RSS
Dan Abrams, Founder | Power Grid by Sound Strategies | Hosting by Datagram