{"id":132571,"date":"2024-10-14T14:39:53","date_gmt":"2024-10-14T18:39:53","guid":{"rendered":"https:\/\/rbach.net\/?p=132571"},"modified":"2024-10-21T09:35:09","modified_gmt":"2024-10-21T13:35:09","slug":"data-breach-hits-internet-archive-users","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/data-breach-hits-internet-archive-users\/","title":{"rendered":"Data Breach Hits Internet Archive Users"},"content":{"rendered":"\r\n<p><strong>Updated<\/strong>\u201410\/21\/2024\u2014<em><a title=\"The Verge\" href=\"https:\/\/www.theverge.com\" target=\"_blank\" rel=\"nofollow noopener ugc\">The Verge<\/a><\/em> <a title=\"The Internet Archive hackers still have access to its internal emailing tools\" href=\"https:\/\/www.theverge.com\/2024\/10\/20\/24274826\/internet-archive-hackers-replying-zendesk-tickets\" target=\"_blank\" rel=\"nofollow noopener ugc\">reports<\/a> that the Internet Archive is under the influence of attackers.\u00a0 Despite being back online in Read Only mode, it seems the attackers control the IA help desk.\u00a0 According to reports, the attackers have a <a title=\"Managing access to the Zendesk API\" href=\"https:\/\/support.zendesk.com\/hc\/en-us\/articles\/4408889192858-Managing-access-to-the-Zendesk-API\" target=\"_blank\" rel=\"nofollow noopener ugc\">Zendesk token<\/a> and can intercept\u00a0tickets.<\/p>\r\n<p style=\"text-align: center;\">&#8212;<\/p>\r\n<p><strong>Updated<\/strong> &#8211; 10\/16\/2024 &#8211; <em><a title=\"Internet Archive is still not fully recovered: Here's how the attack unfolded\" href=\"https:\/\/www.techradar.com\/pro\/internet-archive-is-still-not-fully-recovered-heres-how-the-attack-unfolded\" target=\"_blank\" rel=\"nofollow noopener ugc\">TechRadar<\/a><\/em> reports that the attack used <strong>two attack vectors<\/strong>: TCP reset floods and HTTPS application layer attacks.\u00a0 The<strong> TCP flood<\/strong> will flood a victim with vast numbers of Transmission Control Protocol (TCP) reset packets, which trick a computer into terminating its connection with others in its network.\u00a0 An <strong>HTTPS application layer attack<\/strong> will typically aim to overwhelm servers by targeting the application layer to disrupt the normal traffic flow, rendering regular services unavailable.<\/p>\r\n<p style=\"text-align: center;\">&#8212;<\/p>\r\n<p><a href=\"https:\/\/archive.org\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-132632\" title=\"Data Breach Hits Internet Archive Users\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ia_logo.jpg?resize=125%2C117&#038;ssl=1\" alt=\"Data Breach Hits Internet Archive Users\" width=\"125\" height=\"117\" \/><\/a>The non-profit <strong><a title=\"Internet Archive\" href=\"https:\/\/archive.org\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">Internet Archive<\/a><\/strong> has been <strong>offline<\/strong> since Tuesday (10\/09\/2024).\u00a0 Founded in 1996, the Internet Archive digital library provides &#8220;universal access to all knowledge.&#8221; Through the <a title=\"Wayback Machine\" href=\"https:\/\/web.archive.org\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">Wayback Machine<\/a>, it preserves <strong>billions of webpages<\/strong>, texts, audio recordings, videos, and software applications.<\/p>\r\n<p>Internet Archive founder <a title=\"Brewster Kahle\" href=\"https:\/\/brewster.kahle.org\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">Brewster Kahle<\/a> posted on X (formerly Twitter) that the site was under a <strong><a title=\"DDoS attack\" href=\"https:\/\/www.cloudflare.com\/learning\/ddos\/what-is-a-ddos-attack\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">DDoS attack<\/a><\/strong>.<\/p>\r\n<p><a href=\"https:\/\/knowyourmeme.com\/photos\/2922872-2024-internet-archive-hack\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-132624 size-medium\" title=\"Internet Archive under DDOS attack\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/IA_ddos.png?resize=150%2C49&#038;ssl=1\" alt=\"Internet Archive under DDOS attack\" width=\"150\" height=\"49\" \/><\/a><\/p>\r\n<p>Later on Tuesday, the attack evolved.\u00a0 The site started displaying a hacker pop-up notification.\u00a0 After closing the message, the site loaded typically but very slowly.\u00a0 The pop-up said:<\/p>\r\n<p><a href=\"https:\/\/knowyourmeme.com\/photos\/2922891-2024-internet-archive-hack\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-132625 size-medium\" title=\"JavaScript pop-up message claiming that the Internet Archive had been hacked\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/IA_pop-e1728919971931-150x91.png?resize=150%2C91&#038;ssl=1\" alt=\"JavaScript pop-up message claiming that the Internet Archive had been hacked\" width=\"150\" height=\"91\" \/><\/a><\/p>\r\n<p style=\"text-align: center; padding-left: 40px;\">&#8220;Have you ever felt like the Internet Archive runs on sticks and is constantly on the verge of suffering a catastrophic security breach?\u00a0 It just happened.\u00a0 See 31 million of you on HIBP!&#8221;<\/p>\r\n<p><br \/>HIBP refers to <strong><a title=\"Have I Been Pwned?\" href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">Have I Been Pwned?<\/a><\/strong>, a website where people can check to see if their information has leaked from cyber attacks.<\/p>\r\n<p>Finally, the pop-up was gone, along with the rest of the site, leaving only a placeholder message saying:<\/p>\r\n<p style=\"padding-left: 40px; text-align: center;\">&#8220;Internet Archive services are temporarily offline.&#8221;<\/p>\r\n<h3>Stolen Internet Archive data<\/h3>\r\n<p><a href=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-9-e1643394085126.jpg?ssl=1\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-116375\" title=\"Stolen Internet Archive data\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-9-e1643394085126-150x108.jpg?resize=125%2C90&#038;ssl=1\" alt=\"Stolen Internet Archive data\" width=\"125\" height=\"90\" \/><\/a>On September 28, 2024, attackers <strong>stole the site&#8217;s user authentication database<\/strong> with 31 million unique records.\u00a0 <em><a title=\"(opens in a new window)\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/internet-archive-hacked-data-breach-impacts-31-million-users\/\" target=\"_blank\" rel=\"nofollow noopener ugc\" data-ga-click=\"1\" data-ga-element=\"offer\" data-ga-label=\"$text\" data-ga-item=\"text-link\" data-ga-module=\"content_body\"><u>Bleeping Computer<\/u><\/a><\/em> confirmed that H<em>ave I Been Pwned<\/em> had received an &#8220;ia_users.sql&#8221; database file containing authentication <strong>information for registered members<\/strong>, including their email\u00a0addresses, screen names, password change timestamps, Bcrypt-hashed passwords, and other internal data.<\/p>\r\n<h3>Who is responsible<\/h3>\r\n<p><a href=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Hacker3-e1720465037882.jpg?ssl=1\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-131735\" style=\"font-size: 16px;\" title=\"Who is responsible\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/Hacker3-e1720465037882-150x101.jpg?resize=124%2C84&#038;ssl=1\" alt=\"Who is responsible\" width=\"124\" height=\"84\" \/><\/a>The <strong>hacktivist<\/strong> group <strong>SN_BlackMeta<\/strong>, which emerged in November 2023, claimed responsibility for the DDoS attack.\u00a0 Cybersecurity firm <a title=\"Six-day, 14.7 Million RPS Web DDoS Attack Campaign Attributed to SN_BLACKMETA\" href=\"https:\/\/www.radware.com\/security\/threat-advisories-and-attack-reports\/six-day-web-ddos-attack-campaign\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">Radware connected<\/a> SN_BlackMeta to a <strong>pro-Palestinian<\/strong> hacktivist movement that utilizes <a title=\"What Is DDoS-for-Hire and Why Is It a Problem?\" href=\"https:\/\/www.makeuseof.com\/what-is-ddos-for-hire\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">DDoS-for-hire services<\/a> like <a title=\"InfraShutdown: Anonymous Sudan Partners With DDoS-for-Hire Operator\" href=\"https:\/\/www.radware.com\/security\/threat-advisories-and-attack-reports\/infrashutdown-anonymous-sudan-partners-with-ddos-for-hire-operator\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">InfraShutdown<\/a>.\u00a0 SN_BlackMeta has launched other cyberattacks, including a record-breaking DDoS attack against a Middle Eastern financial institution.<\/p>\r\n<p>It&#8217;s unclear if they are involved in the Internet Archive data breach.\u00a0 The group <a title=\"(opens in a new window)\" href=\"https:\/\/x.com\/Sn_darkmeta\/status\/1844104165192253945\" target=\"_blank\" rel=\"noopener\" data-ga-click=\"1\" data-ga-element=\"offer\" data-ga-label=\"$text\" data-ga-item=\"text-link\" data-ga-module=\"content_body\"><u>said<\/u><\/a> that it carried out the DDoS attack because the <strong>United States supports Israel<\/strong> and that the Internet Archive &#8220;belongs to the USA.&#8221;<\/p>\r\n<p>Many social media users quickly pointed out that the Internet Archive is an independent non-profit organization not <strong>affiliated with the U.S. government.<\/strong><\/p>\r\n<h3>Internet Archive Back online &#8211; sorta<\/h3>\r\n<p>10\/14\/2024, it is back in a limited <strong>read-only<\/strong> way<\/p>\r\n<p><a href=\"https:\/\/archive.org\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-132626 size-large\" title=\"Internet Archive back online read only\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/msedge_X852qDhtee.jpg?resize=480%2C337&#038;ssl=1\" alt=\"Internet Archive back online read only\" width=\"480\" height=\"337\" \/><\/a><\/p>\r\n<h3><strong><em>rb-<\/em><\/strong><\/h3>\r\n<p><em>Finally, what do you need to do if you have an account at the Internet Archive?<\/em><\/p>\r\n<p><em>A compromised password is always a concern in any breach.\u00a0 But in this case, the passwords were salted and hashed, making them difficult to crack through reverse engineering or brute force.\u00a0 Still, once the Internet Archive returns, you should change your password to be safe.<\/em><\/p>\r\n<p><strong>Related article<\/strong><\/p>\r\n<ul>\r\n<li><a title=\"Famous DDoS attacks | The largest DDoS attacks of all time\" href=\"https:\/\/www.cloudflare.com\/learning\/ddos\/famous-ddos-attacks\/\" target=\"_blank\" rel=\"nofollow noopener ugc\">Famous DDoS attacks | The largest DDoS attacks of all time<\/a>\u00a0(<a title=\"Cloudflare\" href=\"https:\/\/www.cloudflare.com\" target=\"_blank\" rel=\"nofollow noopener ugc\">Cloudflare<\/a>)<\/li>\r\n<\/ul>\r\n<p>&nbsp;<\/p>\r\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener\">Ralph Bach<\/a> has been in I.T. for a while and has blogged from the\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener\">Bach Seat<\/a> about I.T., careers, and anything else that has caught my attention since 2005.\u00a0 You can follow me on <a title=\"Facebook\" href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener\">Facebook<\/a>\u00a0or\u00a0<a title=\"Mastodon\" href=\"https:\/\/mastodon.social\/@rbnetinfo\" rel=\"nofollow \">Mastodon<\/a>.\u00a0 Email the Bach Seat <a title=\"Email Bach Seat\" href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/em><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Internet Archive suffered a major hack affecting 31M users. Attackers stole user data, prompting security warnings. The site is partially back online. Stay safe!<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[3719,32,3361,1748],"class_list":["post-132571","post","type-post","status-publish","format-standard","hentry","tag-3719","tag-business","tag-data-theft","tag-ddos"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/132571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=132571"}],"version-history":[{"count":14,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/132571\/revisions"}],"predecessor-version":[{"id":132726,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/132571\/revisions\/132726"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=132571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=132571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=132571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}