Live data from Hacker News

Google Hack Attack Was Ultra Sophisticated, New Details Show

wired.com

41–50 of 116 posts

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#41
post #35

Another aspect perhaps most of people ignored is: Chinese government has all the source code of Windows systems: http://news.cnet.com/2100-1016_3-5083458.html Including: Windows Vista, Windows XP, Windows Server 2003, windows 2000, Windows CE 6.0/5.0/4.2(PSK), Microsoft Office Pro 2003, Microsoft Office Systems It's reviewed by top three Chinese universities and other three government agencies. The Party is the new o…

Yeah, North Korea, Iran, and Afghanistan also have all of the source code of Linux. What is your point?

Linux security assumes source code visibility, Windows doesn't?

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#42
post #41

Earlier quoted context omitted.

Yeah, North Korea, Iran, and Afghanistan also have all of the source code of Linux. What is your point?

Linux security assumes source code visibility, Windows doesn't?

Yeah, so you give it to a government who is reviewing it for security problems. More than likely the NSA and CIA also have the source code for Windows.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#43
post #35

Another aspect perhaps most of people ignored is: Chinese government has all the source code of Windows systems: http://news.cnet.com/2100-1016_3-5083458.html Including: Windows Vista, Windows XP, Windows Server 2003, windows 2000, Windows CE 6.0/5.0/4.2(PSK), Microsoft Office Pro 2003, Microsoft Office Systems It's reviewed by top three Chinese universities and other three government agencies. The Party is the new o…

Yeah, North Korea, Iran, and Afghanistan also have all of the source code of Linux. What is your point?

Linux is very different issue IMO.

1. Customized compilation result different address offsets thus an exploit is not very generic portable.

2. Everyone can do a static vulnerability scan for Linux source code, so if there is a hole it's more likely to be well known in the industry

Recently series of events with google.cn suggests that this is just a test ground for industrialized 0day farming for closed source software as a strategic weapon.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#44
In other news, I was just sent an Email by Bank of America...

Said my card was compromised, I called in and they said their systems were hacked and he gave the name and location of the system...

You might not know it, but sounds like BoA was compromised as well.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#45
post #41

Earlier quoted context omitted.

Linux security assumes source code visibility, Windows doesn't?

Yeah, so you give it to a government who is reviewing it for security problems. More than likely the NSA and CIA also have the source code for Windows.

on the other hand iDefence itself has a conspiratable spooky background of CIA/DoD

http://www.reddit.com/r/netsec/comments/app8q/_/c0issy7

The more you poke into it the more it looks like a full scale war

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#46
post #13

Does anyone have a full list of the 34 companies?

Not yet, but you can probably make some educated guesses. What US companies have technologies that China might be interested in? -Google -Microsoft -Boeing -Intel -Cisco (imagine the value of their source code) -Apple -Any of the defense contractors etc.

So far what I heard:

Rackspace, Yahoo,Symantec,Northrop Grumman,Dow Chemical

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#47
post #33
post #23

Update from a Chinese anonymous source, credibility unknown http://www.brookswelding.com/ Undercover agents were sent to Google Shanghai Office, cracked Gmail source code and get away with a 1 million RMB reward

link to Google Translate'd in English: http://translate.google.com/translate?js=y&prev=_t&h...

Google, congratulate you on your return to the embrace of mercy of the Lord. Yes, we are here to congratulate you, rather than mourning. When the sun finally shining in Jerusalem tomb of your Lengji, we will meet your resurrection.

Huh?

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#48
post #12

I find the fact that the targets were source code repos very interesting. If you are a super-smart black-hat villain who wants to plan a mass global attack, what better place to start than with Google and Adobe's source code?

what better place to start than with Google and Adobe's source code?

Indeed -- and especially their auto-upgrade mechanisms.

There may yet be more to Google's anger that's not yet been revealed. What if the attackers didn't just look around, but changed (or tried to change) Google content/code at the source?

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#49
post #47
post #33

Earlier quoted context omitted.

link to Google Translate'd in English: http://translate.google.com/translate?js=y&prev=_t&h...

Google, congratulate you on your return to the embrace of mercy of the Lord. Yes, we are here to congratulate you, rather than mourning. When the sun finally shining in Jerusalem tomb of your Lengji, we will meet your resurrection. Huh?

Looks like the page is setup by a local Christian.

It's observable phenomenon that all Christian Chinese favor Google more than any other search engines.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#50

Their effort to obfuscate their tracks does sound pretty nifty, but part of me is disappointed that it all depended on the target clicking on something they shouldn't have. Glorified phishing schemes just don't have the pizazz of a remote buffer overflow exploit, for example.

This kind of attitude has to stop. "Glorified phishing" might not have pizazz, but it was DAMN effective in this case. Why go to the trouble of finding, coding, exploiting an increasingly difficult target when end users will do all the work for you? This is the kind of scenario that gives security people nightmares. It takes VERY sophisticated processes and technology to find covert backdoors on your network, and ver…

Effective or not, sending some bad links to a bunch of Google employees and hoping one of them clicks is not a 'VERY sophisticated process'. It's just a good example of how users will always be the weakest link in securing a network.
Post reply on HN