Live data from Hacker News

Phineas Fisher's account of how he took down HackingTeam

ghostbin.com

21–30 of 105 posts

Re: Phineas Fisher's account of how he took down HackingTeam

#21
post #20

Wow, this is great. Feels like reading phrack in the 90s. Anyone know of similar, contemporary resources on hacking? This stuff is gold: > NoSQL, or rather NoAuthentication, has been a great gift to the hacker community [1]. Just when I was worrying that all MySQL's sins of omission had finally been patched [2][3][4][5], these new databases appear, lacking authentication by design. Nmap found a few in Hacking Team's…

There was another one on the finisher attack, also on paste bin that is Worth a read.

Re: Phineas Fisher's account of how he took down HackingTeam

#22
> I want to dedicate this guide to the victims of the assault on the Armando Diaz school, and to all those whose blood has been spilled at the hands of Italian fascism.

For those who don't know, they are referring to the 2001 Armando Diaz school attack [1] (warning: graphic), where hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none of the policemen is serving any jail time.

[1]: https://en.wikipedia.org/wiki/2001_Raid_on_Armando_Diaz

Re: Phineas Fisher's account of how he took down HackingTeam

#25
post #4

Earlier quoted context omitted.

Could you expand on your comment? My understanding is that if a party can't tie a wallet to an identity then it is anonymous. So if you can acquire bitcoins (eg. mining) and purchase something (eg. VPS) without giving up your identity then you are solid.

I've heard conflicting information as far as this goes. Thinking this through- an adversary who's watching the block chain probably knows some inputs and some outputs. As in, these addresses belong to an exchange, these addresses belong to a hosting company. Okay, fine. Now remember than any user can literally create wallets out of thin air, and in fact doing so is considered basic security hygiene. Let's say Joe Use…

You have to use your bitcoins someday. Either to buy real currency or real goods. Then you know where the money went TO. Tracing the transactions back (where the money came FROM) is then not a big deal - full history is in the blockchain.

So as long as you don't do a transaction that connects your identity to any bitcoin address, you are fine. but to use bitcoins you are almost always required to do it (its an electronic financial transaction, they are governed by law to have an identity, but of course you can find entities who do not follow these laws).

Re: Phineas Fisher's account of how he took down HackingTeam

#26
post #17

For anyone who doesn't follow infosec: This guy is responsible for two of the most impressive hacks recently and still hasn't been doxed or arrested. And so the linked doc is awesome if only for the opsec tips it provides. And it provides much more than that. It really gives you some perspective on how much work an attacker will put into breaking into your network and the kind of structured approach they're taking. P…

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

Who exactly would be trying to track him down?

Is there some global force that would be active on him?

Re: Phineas Fisher's account of how he took down HackingTeam

#27
post #17

For anyone who doesn't follow infosec: This guy is responsible for two of the most impressive hacks recently and still hasn't been doxed or arrested. And so the linked doc is awesome if only for the opsec tips it provides. And it provides much more than that. It really gives you some perspective on how much work an attacker will put into breaking into your network and the kind of structured approach they're taking. P…

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

This text is a translation. The original is in Spanish. It might have its own mistakes and traces, although I am not knowledgeable to detect country-specific patterns. http://pastebin.com/raw/GPSHF04A

Presumably, given that they talk about EU culture^W^W^W^W (see comment below) have a https://securityinabox.org/es/… link, the author is from Spain, which would make it easier to pinpoint an origin, as Spain has a wider spectrum of language differences than in most other Spanish-speaking countries.

Since there is a link to http://madrid.cnt.es/, they maybe live in the capital, which weighs 3 million inhabitants.

Re: Phineas Fisher's account of how he took down HackingTeam

#29
post #17

Earlier quoted context omitted.

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

This text is a translation. The original is in Spanish. It might have its own mistakes and traces, although I am not knowledgeable to detect country-specific patterns. http://pastebin.com/raw/GPSHF04A Presumably, given that they talk about EU culture^W^W^W^W (see comment below) have a https://securityinabox.org/es/… link, the author is from Spain, which would make it easier to pinpoint an origin, as Spain has a wider…

That's an error on the translation, "EEUU" is the Spanish acronym for "Estados Unidos", referring to the United States of America, not the EU (in Spanish, "UE" for "Unión Europea")
Post reply on HN