Jackie Singh 🇺🇸 Profile picture
Jul 10, 2024 18 tweets 6 min read Read on X
I am reviewing this alleged hack of The Heritage Foundation.

I have identified very embarrassing data within this dataset. Why so many Chinese IP addresses? 🤔
The zipped file contains one single file:

"daily-signal_dev_database_new.sql"

This appears to be a combined set of exports from a SQL database. Here are the first lines Image
Because this is a combined export (likely from the command line) of various tables, the file is not readable by a typical SQL editor, and needs to be split into pieces to make it so.

I'd rather just turn it into CSV chunks to start cleaning up the dataset for further analysis
There are 215,000 lines or so in the WordPress Comments table. As you can see, comment_author_IP is available, which is broadly useful to get a sense of where people posting replies to the Heritage blog are coming from in the world.

Earliest date: 2008-01-04. Newest: 2022-11-09 Image
After creating a CSV chunk with only the WP comments table, now I can view columns and extract their content as needed. After extracting IP addresses from the author column, I can eliminate duplicates and work on analyzing their presumed geo origin, which is of interest to me Image
Dataset was a little dirty and a hassle to clean up.

Here are the 60K extracted IPs from the WP Comments table:

#HeritageFoundation defuse.ca/b/PTrmvlbs
Image
Sample geolocations from the first 100 IPs (these are sorted 'low to high', and many Asia-based netblocks start with the number 1) Image
Here are the 69.5K email addresses present within the complete dataset:



🤔 235 .mil and .gov email addresses
🤔 95 .ru and .cn email addresses

#HeritageFoundationdefuse.ca/b/mLXCi0iXsGFj…
Linked below is a statistical breakdown of the domain names associated with all email addresses in the dataset.

Stacking and counting are basic analytical tools which can help analysts identify outliers.

defuse.ca/b/GMCj2uAfvELn…
Image
I have a script running to grab geolocation information and will tweet when it finishes.

Those working at big companies with access to certain commercial tools can do this more quickly than I can.
Because the original host took the file down, you can now find it here:

This is a 368 MB .zip file which uncompresses to a single 1.94 GB flat file.

SHA256: 3dcc258331d9139a654402d20b756b57ca17228aa9e2f80a4b6451b96c8eac70tan-medieval-hornet-252.mypinata.cloud/ipfs/QmVwiYsr4…
The hacker group claiming responsibility for this action has released new information on their Telegram channel. Image
Here is the list of Administrators.

defuse.ca/b/ely6s7iwqpLF…
BREAKING: SiegedSec claims to have officially disbanded.

#HeritageFoundation
Image
Image
@CloudsEdgeArt1 I am the first person covering this.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Jackie Singh 🇺🇸

Jackie Singh 🇺🇸 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @HackingButLegal

Mar 2
Everyone now understands why I have publicly doxed multiple agents of foreign influence inside the U.S. and why those dudes have attacked me on a near-daily basis for several years as I pointed out their hidden acts of sabotage against the American people
My research on this topic has been ongoing for several years. The more I looked, the more I found.

Slides in description with added content
Most journalists do not have the expertise to untangle these topics and do not feel equipped to report on them.

Even without a cyber nexus, pure espionage stories are difficult to verify, and many will not or cannot do the legwork to verify.

Spies work hard to stay hidden.
Read 13 tweets
Feb 25
Journalists: Adam Ramada, who works for Musk inside DOGE to "help" the Dept of Education and was just blocked by name from accessing our data by a judge, has an interesting resume in finance involving managing foreign funds, and a history targeting the Dept on behalf of private corporate interests.

Entities:
- Purelake Capital LLC (DE, revoked?)
- Palindrome Investment Advisors LLC (CA, filings not up to date, some names wiped from co-founder bios)Image
Image
Image
Judge's order naming him (PDF, pg. 5): democracydocket.com/wp-content/upl…
Read 13 tweets
Feb 8
🚨 NEW: I regret to inform the public the individual blocking @RepMaxineWaters @MaxwellFrostFL et. al lawful entrance to the Dept. of Education today appears to be Tobie Jansen van Rensburg, an offensive cybersecurity expert from South Africa who runs "Grey Owl Cyber Defense". Image
Image
They wiped his face from PimEyes, but I still found him. Image
Image
They are seeding disinformation, seen here possibly using the stolen identity of a Black man on Threads.

This works by seeding lies that aren't verifiable, yet appear highly passable at first blush.

David Fridie does exist, and did work at DoE, but has no Internet presence, including on LinkedIn, so it's impossible to verify without contacting him directly.Image
Image
Image
Read 6 tweets
Jan 24
Flashback to the American life I lived the week of Election Day, 2016.

This was my Before. Everything changed after that Image
Image
Image
Image
November 2, 2016. My tweet highlighted on stage during Ashton Kutcher’s speech.

What a different world it was, then. Image
Image
Image
The memes I have saved from around that time were fairly innocent and lighthearted. Stuff friends made, or that got passed around the office Image
Image
Image
Image
Read 12 tweets
Jan 22
European reactions to the American mess
European reactions to the American mess, continued
European reactions to the American mess, continued
Read 8 tweets
Jan 21
🧵 EXPLAINER: TRUMP'S EXECUTIVE ORDERS INCLUDING ENDING BIRTHRIGHT CITIZENSHIP/JUS SOLI

👀 This executive order aims to limit automatic birthright citizenship in the U.S. by reinterpreting the "subject to the jurisdiction thereof" clause of the 14th Amendment (DANGER!! THAT ONE PROVIDES EQUAL PROTECTION!!)

The order affects children born in the US after February 19, 2025 (30 days from the order's date) to two specific categories of parents:

1. Children born to mothers without legal status in the US and fathers who are neither US citizens nor permanent residents,
2. Children born to mothers with temporary legal status (like tourist or student visas) and fathers who are neither US citizens nor permanent residents.

Federal agencies including the State Dept, DoJ, DHS, and SSA will be required to:

- Stop issuing citizenship documentation to affected newborns
- Reject state or local documents claiming citizenship status for affected individuals
- Issue public guidance within 30 days explaining how they will implement these changes

The order applies these key limitations (FOR NOW!!!)
- Applies only to births occurring 30 days after the order's date
- Does not affect children of legal permanent residents
- Does not revoke existing citizenship for anyone born before the effective date

This executive order represents a seismic shift in how birthright citizenship has traditionally been interpreted and applied in the United States. It is already facing immediate legal challenges by ACLU and others, as it attempts to change a long-standing interpretation of the 14th Amendment through executive action rather than through legislation or constitutional amendment (WARNING! DICTATORSHIP AHEAD!!).

The practical implementation and enforcement of this order will depend on several factors, including:

- The response of state and local governments
- Legal challenges that may prevent or delay implementation
- The ability of federal agencies to verify parental status at the time of birth
- The capacity of agencies to implement new verification systems
Another order titled, "PROTECTING THE UNITED STATES FROM FOREIGN TERRORISTS AND OTHER NATIONAL SECURITY AND PUBLIC SAFETY THREATS" implements stricter vetting procedures for all foreign nationals, both those seeking entry and those already present in the United States. It requires continuous monitoring for security threats and establishes new standards for evaluating ideological alignment with American values and institutions.

That order states criteria for exclusion or removal includes individuals with "hostile attitudes" toward American institutions, which can easily be construed as including those who advocate for cultural or social changes deemed threatening to the administration.
BROADER IMPACT:

When viewed alongside the rescission order (INITIAL RESCISSIONS OF HARMFUL EXECUTIVE ORDERS AND ACTIONS) that eliminates numerous immigrant protection policies and the death penalty order's specific focus on crimes by non-citizens, these orders create a coordinated policy framework designed to:

- Prevent future unauthorized immigration through physical barriers and enforcement
- Identify and remove current unauthorized residents
- Eliminate programs and policies that provided humanitarian considerations
- Create severe consequences for violations

This comprehensive approach represents one of the most significant shifts in immigration policy and enforcement in U.S. history, and will fundamentally alter both future immigration patterns and the status of existing residents and citizens.
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(