Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.
To post in this sub-forum you must have made 100 posts or have Trust status or have completed our ID Verification

Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
1 | ... | 1476 | 1477 | 1478 | 1479 | 1480 | 1481 | 1482 | 1483 | 1484 | 1485 | 1486 | ... | 2317
ezbee
2405 posts

Uber Geek


  #2633976 11-Jan-2021 22:33
Send private message quote this post


This guy looks like he will be in a world of trouble when they catch up with him.

 

Ali Alexander

 

Code for today is "yet"

 

https://news.yahoo.com/stop-steal-organizer-hiding-denying-020833348.html

 


""
Alexander, who has described himself as one of the “official originators” of the Jan. 6 rally in Washington, went on to use “yet” as a code word for violence. Then Alexander told the Phoenix crowd about his plans for Washington.

 

“We’re going to convince them to not certify the vote on January 6 by marching hundreds of thousands, if not millions of patriots, to sit their butts in D.C. and close that city down, right?” Alexander said. “And if we have to explore options after that…‘yet.’ Yet!”

 

Alexander’s supporters cheered, yelling threats like “noose!” and “nothing’s off the table!”
""

 

""
Alexander first appeared in conservative politics in the Tea Party era under the name “Ali Akbar,” organizing a group called the National Bloggers’ Club that was tied to “shady data collection operations.”
""


neb

neb
11294 posts

Uber Geek

Trusted
Lifetime subscriber

  #2633997 12-Jan-2021 03:03
Send private message quote this post

Parler has been comprehensively doxxed! When they lost their 2FA provider they failed open, with no checks on account creation or anything else. Guess what you can do with an administrator account on a poorly-written social media platform?

 

 

All Parler user data is being downloaded as we speak!

 

 

Here is a description of what went down according to someone with far greater technical knowledge than me:

 

 

"so a group of developers latched onto the Press Release that Twilio put out at midnight last night. In that Press Release, Twilio accidentally revealed which services Parler was using. Turns out it was all of the security authentications that were used to register a user. This allowed anyone to create a user, and not have to verify an email address, and immediately have a logged-on account.

 

 

Well, because of that access, it gave them access to the behind the login box API that is used to deliver content -- ALL CONTENT (parleys, video, images, user profiles, user information, etc) --. But what it also did was revealed which USERS had "Administration" rights, "Moderation" rights.

 

 

Well, then what happened, those user accounts that had Administration rights to the entire platform... The hackers, internet warriors, call it what you will, was able to use the forgot password link to change the password. Why? Because Twilio was no longer authenticating emails. This meant, they'd get directly to the reset password screen of that Administration user.

 

 

This group of Internet Warriors then used that account, to create a handful of other ADMINISTRATION accounts, and then created a script that ended up creating MILLIONS of fake administration accounts.

 

 

Now that they had a way of creating admin accounts without interruption, they created a Docker Image (basically a virtual machine) called a Warrior, that anyone could download, and when fired up, would immediately start collecting data off of Parlre, in a coordinated fashion.

 

 

Consider it like SETI (Search for Extra-Terrestrial Intelligence) that people used to load up as screen savers when their computers were not being used. Same concept, crowdsourcing.

 

 

All of this data, the videos, the images, the posts, the metadata (including the GEO location of all images and videos, and the connections to the accounts that posted it, has been (since midnight) being uploaded to various cloud drives and storage arrays for the purposes of Archiving this information, for later retrieval by law enforcement, by the public, by Open Source Intelligence communities.

 

 

And the kicker.. is this: all of this information was thought to be secure and private by individuals who were making the posts. A significant number of those individuals went through the process of being a "Verified Citizen" on Parler. What does that mean?

 

 

It means they uploaded a picture of the front and back of their REAL State Driver's License........ Let that sink in for a second.

 

 

I am positive the FBI has been actively soaking in this information along with the Internet Warriors, but this is how they are going to officially track down.

 

 

And it's how the FBI, DHS, and FAA have been able to immediately and exhaustively create no-fly lists. Every verified attendee of the Capitol riot where they can find a real name has been placed on No-Fly Lists.

 

 

It might seem like a small geeky glitch or hack.. but in the age of Information warfare... this is the silver bullet for the people who used Parler as a place to organize their efforts.

 

 

Also, a lot of posts were deleted by Parler members after the riots on the 6th. Turned out... Parler didn't actually delete anything.. just set a bit as deleted.

 

 

Guess what has access to all "deleted" content?

 

 

Administrator accounts."

neb

neb
11294 posts

Uber Geek

Trusted
Lifetime subscriber

  #2633998 12-Jan-2021 03:26
Send private message quote this post

Oh, and a followup:

 

 

Every Deleted Parler Post, Many With Users' Location Data, Has Been Archived

 

 

Operating on little sleep, @donk_enby began the work of archiving all of Parler’s posts, ultimately capturing around 99.9 percent of its content. In a tweet early Sunday, @donk_enby said she was crawling some 1.1 million Parler video URLs. “These are the original, unprocessed, raw files as uploaded to Parler with all associated metadata,” she said. Included in this tranche of data, now several terabytes in size, @donk_enby confirmed the raw video includes GPS coordinates, which point to the locations of users when the videos were filmed.

 

 

@donk_enby later shared a screenshot showing the GPS position of a particular video, with coordinates in latitude and longitude.

 

 

The total stash is around 70TB of data.

neb

neb
11294 posts

Uber Geek

Trusted
Lifetime subscriber

  #2633999 12-Jan-2021 03:30
Send private message quote this post

neb: And the kicker.. is this: all of this information was thought to be secure and private by individuals who were making the posts. A significant number of those individuals went through the process of being a "Verified Citizen" on Parler. What does that mean?

 

 

It means they uploaded a picture of the front and back of their REAL State Driver's License........ Let that sink in for a second.

 

 

For followers of the political movement that gave the world "Your papers, please!", these guys are pretty stupid about handing over personal info. I guess they're expecting to be the ones asking for the papers, not the other way round.

kingdragonfly
11190 posts

Uber Geek

Subscriber

  #2634005 12-Jan-2021 07:22
Send private message quote this post

gzt: Trump supporters smashed a fair bit of media equipment at points during the rally/march


I guess their weren't any books to burn.

kingdragonfly
11190 posts

Uber Geek

Subscriber

  #2634007 12-Jan-2021 07:32
Send private message quote this post

My favourite is the real estate agent / radio host posting many videos of herself:

"Realtor Jenna Ryan’s posts on social media show her flying on a private jet to attend the Trump rally and later smiling and flashing a'“victory' sign in front of a broken Capitol window.

'Window at The capital,' Ryan posted in a now-deleted tweet. 'And if the news doesn’t stop lying about us we’re going to come after their studios next.'

She also bragged that 'we just stormed the capital' and that 'it was one of the best days of my life.'

In an erratic series of tweets Friday and Saturday, she made several Bible references and denied doing anything wrong. She also denied entering the Capitol during the riot."

She had to close her business.

Also

"Brock has yet to comment on the loss of his job. He told The New Yorker he assumed he was welcome to enter the Capitol and denied entering the office of House Speaker Nancy Pelosi in spite of video showing him exiting the office. He claimed he merely found the zip-ties on the floor."

Court House News: Trump Supporters Lose Jobs and Businesses After Participation in Capitol Riot

gzt

gzt
17104 posts

Uber Geek

Lifetime subscriber

  #2634008 12-Jan-2021 07:35
Send private message quote this post

UK Telegraph reporter talks about media experience at Trump rally:

Warning: NSFW yelling etc..


kingdragonfly
11190 posts

Uber Geek

Subscriber

  #2634010 12-Jan-2021 07:49
Send private message quote this post

neb: Parler has been comprehensively doxxed!


An update for you techies:

It looks like whitehats are exploiting several flaws:

Endpoint was not well written. It uses predictable sequential integer id, and you no permission check. Whitehats have written script to sequentially read.

Another whitehats decompiling the admin app. So far only enumerating admin account. However this would be handy for law enforcement. Whitehats trying to bypass security check

Unrelated email verification is down, probably due to Apple / Google de-certification. Anyone can create account. People spamming Parler.

Sideface
9350 posts

Uber Geek

Trusted
DR
Lifetime subscriber

  #2634016 12-Jan-2021 08:06
Send private message quote this post

 

kingdragonfly: ...  I guess their weren't any books to burn.

 



 

 


For your reading pleasure, here is the final version of the impeachment document, dated 10 Jan 2021:

 

The New York Times - Read the Article of Impeachment

 

today

 

House Democrats on Monday introduced an article of impeachment charging President Trump with “high crimes and misdemeanors” for inciting the mob that assaulted the Capitol on Wednesday.

 

A PDF version of this document with embedded text is available at the link below:

 

Download the original document (pdf)





Sideface


quickymart
13925 posts

Uber Geek

ID Verified

  #2634018 12-Jan-2021 08:12
Send private message quote this post

So...I'm confused. Has anything of value been downloaded from this Parler place? I just went to that lass's Twitter page and she says:

 

@donk_enby:

 

since a lot of people seem confused about this detail and there is a bulls--t reddit post going around: only things that were available publicly via the web were archived. i don't have you e-mail address, phone or credit card number. unless you posted it yourself on parler.   So does she have all these clowns' personal information?

 

I just tried going to the Parler page myself but no go - why didn't they just move the hosting somewhere else if it's so important?


Sideface
9350 posts

Uber Geek

Trusted
DR
Lifetime subscriber

  #2634022 12-Jan-2021 08:24
Send private message quote this post

The New York Times - An impeachment charge against Trump is introduced as Republicans block a measure demanding Pence act.

 

breaking

 


House Democrats on Monday introduced an article of impeachment against President Trump for inciting a mob that attacked the Capitol last week, vowing to press the charge as Republicans blocked a separate move to formally call on Vice President Mike Pence to strip him of power under the 25th Amendment.

 

The dual actions came as Speaker Nancy Pelosi and her caucus sought to ratchet up pressure on Mr. Pence to intervene and push Mr. Trump to resign. 

 

If they did not, the Democrats promised immediate consequences ...

 

As expected, Republicans objected to a resolution calling on Mr. Pence to invoke the 25th Amendment, meaning that the House would have to call a full vote on the measure, most likely on Tuesday.

 





Sideface


quickymart
13925 posts

Uber Geek

ID Verified

  #2634024 12-Jan-2021 08:29
Send private message quote this post

Why doesn't this surprise me? When will these idiots get it - their guy lost - and move on?

 

https://www.nzherald.co.nz/world/fbi-warns-that-trump-fans-are-planning-another-huge-uprising/ZZCFZB7YH2OQAHHAOIRL4774YU/

 

 


kingdragonfly
11190 posts

Uber Geek

Subscriber

  #2634027 12-Jan-2021 08:40
Send private message quote this post

Google and Apple have removed Parler from their respective app stores.

So if you don't have the app it's difficult (but not impossible) to install. Since it would involve rooting a phone, all but the most serious can't be bothered.

Apparently Parler's email verification no longer works (???), which was exploited to create spamming account. I'd guess Parler disabled account creation; that's what I'd do if I were an admin.

Parler contains a "who's who, and what's planned" for most white supremist groups. People can't help but bragging. Given enough references, you could quickly figure out a lot about key leaders. See self-doxing.

There's apparently "meta-data" given by the endpoint. At the least, all messages would have timestamps (possibly IP addresses). The timestamps may not seem important, but it's the "last nail in the coffin" for law enforcement.

It's often used to catch people in the "dark web." I seem to remember it being called an "correlation exploit"

Even using an anonymizer, a web proxy like Onion / TOR, if law enforcement knows broadly your location they can use an ISP reports to determine who was using it.

See FBI agents tracked Harvard bomb threats despite Tor

BarTender
3606 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2634040 12-Jan-2021 08:49
Send private message quote this post

kingdragonfly: Google and Apple have removed Parler from their respective app stores.

 

Parler is completely down as AWS has pulled their infrastructure as of last night.

 

But about 70TB or so was downloaded of all their public content starting with the newest and working backwards. None of their private information such as emails and personal information used for signup / proof of identity was downloaded using the archive process. But not sure if anyone else used the admin users to do that after it became public how poorly Parler was secured. Part of me thinks it was an inside job by a developer sick of the BS or they were just terrible developers and when Twilio pulled the 2FA/password reset for Parler and it allowed anyone to reset anyones password without needing to click the confirmation email. Check out the person who did the whole archive process on Sunday night / Monday until Parler went offline yesterday evening.

 


quickymart
13925 posts

Uber Geek

ID Verified

  #2634043 12-Jan-2021 08:52
Send private message quote this post

That was in my post :D

 

Ah I see - so that answers my question. She doesn't have all the information (drivers licences, etc) contrary to the other post.

 

Has this all been publicly uploaded somewhere? Or just passed on to the FBI.


1 | ... | 1476 | 1477 | 1478 | 1479 | 1480 | 1481 | 1482 | 1483 | 1484 | 1485 | 1486 | ... | 2317
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic



News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.