My thought while reading this: "There's someone at Google running IE?"
Google Hack Attack Was Ultra Sophisticated, New Details Show
21–30 of 116 posts
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#22What do you even call that kind of disinformation? False flag doesn't seem to cut it.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#23Undercover agents were sent to Google Shanghai Office, cracked Gmail source code and get away with a 1 million RMB reward
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#24This was ultra sophisticated, they used several layers of multi-encrypted malware to tunnel out and create reverse control channels. Not to mention used a 0day IE bug to install the malware in various targeted companies. This was gov sponsered...
And a team from the People's Liberation Army's signals intelligence branch will find themselves in jail soon for embarrassing the government...
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#25So in other words, I can launch an attack against any number of companies and organizations, and as long as I attack human rights activists accounts, everyone will blame the Chinese government? What do you even call that kind of disinformation? False flag doesn't seem to cut it.
The attack had originated from China, the company said.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#26What I wonder about is what do they mean by "stealth programming"? I can think of just programming with white text on a white background, but that wouldn't serve any security related purpose. From reading that, it's clear that the shellcode was obfuscated ('encrypting' it three times, though, would be unnecessary ), but that's just a good way to muddle things up. Although from reading that it's obvious that it was a…
In exploiting a remote system, which part of your attack would benefit from being encrypted?
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#27So in other words, I can launch an attack against any number of companies and organizations, and as long as I attack human rights activists accounts, everyone will blame the Chinese government? What do you even call that kind of disinformation? False flag doesn't seem to cut it.
Well this part of it also helps: The attack had originated from China, the company said.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#28Update from a Chinese anonymous source, credibility unknown http://www.brookswelding.com/ Undercover agents were sent to Google Shanghai Office, cracked Gmail source code and get away with a 1 million RMB reward
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#29Earlier quoted context omitted.
"Although the initial attack occurred when company employees visited a malicious web site, Alperovitch said researchers are still trying to determine if this occurred via a URL sent to employees via e-mail or instant messaging or some other method, such as Facebook or other social networking sites." It still needed an employee to make the usual "install the dancing pigs"-style gaff while using IE6. Also: Employees us…
Also: Employees using IE6, inside Google, in 2010. Why weren't they using Chrome? I guess they were testing something in IE6. Perhaps one of their own sites. Perhaps how some other site renders in it compared to Chrome. Who knows.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#30What I wonder about is what do they mean by "stealth programming"? I can think of just programming with white text on a white background, but that wouldn't serve any security related purpose. From reading that, it's clear that the shellcode was obfuscated ('encrypting' it three times, though, would be unnecessary ), but that's just a good way to muddle things up. Although from reading that it's obvious that it was a…
This is something I had a hard time understanding and which I thought the article did a poor job of explaining. In exploiting a remote system, which part of your attack would benefit from being encrypted?
There are all extremely advanced (but known) evasion steps for a very targeted attack. It's rare to see all of them successfully used in one attack because of the complexity and skill required.