Sunday, August 14, 2011

Preparing for an Anonymous Attack

The Fullerton Police have now been targeted by Anonymous:

When you are targeted, I strongly recommend these actions:

1. List all the websites that use your logo with permission, and that store data about your users. Anonymous will not limit their attack to your main site--they will just try to harm and humiliate you and your employees, customers, and the people you work with, by any means necessary. Here are examples of their indirect targeting:

In OpOrlando, Anonymous targeted a site which had nothing to do with the government of Orlando, simply because it had "Orlando" in its name:

The data from 70 law enforcement agencies was taken from an online school, not from the agencies themselves:

The FBI-related data Anonymous revealed was taken from a branch of Infragard, not from,2817,2386411,00.asp

The BART data they dumped was from, not

2. For your main site, and EVERY other site that holds data relevant to you, ensure that they have DDoS proection AND a Web Application Firewall to block SQL Injection attacks. You can add both these security features to your site in 5 minutes using; or use more expensive appliances from many other vendors.

If you fail to do these things, you will face public ridicule and great expense and effort spent trying to clean up the mess after your passwords and email logs are published on the Internet.


@Awinee pointed out some additional measures to take, which I think should be performed after the attack is over, or if you have some time to prepare.

Make sure passwords are stored in a salted and hashed form, not as plaintext.

Force users to change passwords regularly.

Run vulnerability scanners on your sites and fix all the SQL Injection and other serious vulnerabilities you find.


