Live data from Hacker News

Phineas Fisher's account of how he took down HackingTeam

ghostbin.com

51–60 of 105 posts

Re: Phineas Fisher's account of how he took down HackingTeam

#52
post #46

> As far as I know, there's no free way of making inverse whois queries Whoisology [1] is good for this, though they've been more aggressively pushing their paid options as of late. Also WhoisMind [2], to some extent. [1] https://whoisology.com/ [2] http://www.whoismind.com/

Free alternative for anonymous requests is to hit the google caches, ex. site:whois.domaintools.com "Y Combinator" https://encrypted.google.com/search?q=site%3Awhois.domaintoo...

[deleted]

Re: Phineas Fisher's account of how he took down HackingTeam

#54

How did he record these step-by-step instructions with such high detail? Is this common practice?

This is pretty normal for a paid penetration test - but it's got far more technical detail than you'd normally see. I don't think the person behind this has revealed anything particularly new, they just know their tools really well.

Agreed. However, in a formal penetration testing engagement, the tester will usually only record and document their exact steps because they have to provide a detailed report to their client. This hacker didn't have that same obligation. I'm speculating that he is probably a habitual note taker. In this way, if he ever comes across similar challenges when attacking a new target, he has his notes to refer to.

I was curious to read this piece to see how closely the approach, techniques and tools he uses compare to how penetration testers are formally trained in the info sec industry. For what it's worth, the methodology in terms of reconnaissance, privilege escalation and lateral movement within the network are typical. Also, most of the tool set he uses (e.g. mimikatz, responder, meterpreter, powersploit, psexec) are part of any good penetration tester's arsenal.

I'm not trying to down play the achievement though. He is clearly very skilled and knowledgeable. Of particular note, it seems that the initial intrusion was only possible because 'after about two weeks of reverse engineering, I discovered a remote root exploit' in an embedded system. He doesn't provide technical details of the exploit but finding a 0-day in an embedded system is usually far from child's play.

Re: Phineas Fisher's account of how he took down HackingTeam

#55
post #4

Earlier quoted context omitted.

Could you expand on your comment? My understanding is that if a party can't tie a wallet to an identity then it is anonymous. So if you can acquire bitcoins (eg. mining) and purchase something (eg. VPS) without giving up your identity then you are solid.

I've heard conflicting information as far as this goes. Thinking this through- an adversary who's watching the block chain probably knows some inputs and some outputs. As in, these addresses belong to an exchange, these addresses belong to a hosting company. Okay, fine. Now remember than any user can literally create wallets out of thin air, and in fact doing so is considered basic security hygiene. Let's say Joe Use…

Nobody that I can remember has been able to identify the large bitcoin thefts over the years by tracking the coins, those people cashed out somehow. However the SEC filing on Pirateat40's ponzi scheme was remarkably detailed, they were able to track every single coin he received and prove he spent it on himself.

I would imagine others use JoinMarket to mix up the coins[1], use coin control[2] to exchange for other cryptocurrency p2p, or other obfuscation methods like buying up high demand items with bitcoin then selling them remotely for other bitcoins.

[1]https://github.com/JoinMarket-Org/joinmarket/wiki http://joinmarket.io/

[2]https://bitcointalk.org/index.php?topic=144331.0

Re: Phineas Fisher's account of how he took down HackingTeam

#56
post #35

Earlier quoted context omitted.

This text is a translation. The original is in Spanish. It might have its own mistakes and traces, although I am not knowledgeable to detect country-specific patterns. http://pastebin.com/raw/GPSHF04A Presumably, given that they talk about EU culture^W^W^W^W (see comment below) have a https://securityinabox.org/es/… link, the author is from Spain, which would make it easier to pinpoint an origin, as Spain has a wider…

After reading the original doc, by the style used and some slang (although it could be on purpose), I would say the author is from Chile. I'm glad to find people that still fight the system in this side of the world.

I would be willing to bet they are from Italy. I am Italian and they wrote about some stuff that you would know only if you followed Italian news.

They could be dropping some contradictory clues, BTW. I could definitely see that.

Re: Phineas Fisher's account of how he took down HackingTeam

#58
post #17

For anyone who doesn't follow infosec: This guy is responsible for two of the most impressive hacks recently and still hasn't been doxed or arrested. And so the linked doc is awesome if only for the opsec tips it provides. And it provides much more than that. It really gives you some perspective on how much work an attacker will put into breaking into your network and the kind of structured approach they're taking. P…

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

You comment about spelling and phrases reminds me of the NYT's Dialect Quiz Map. I tried it and it was accurately able to guess where I was originally from. While not useful by itself, I could see it being handy as part of an overall investigation.

Re: Phineas Fisher's account of how he took down HackingTeam

#59
post #41
post #31

Earlier quoted context omitted.

HT, Gamma, victims we aren't aware of, or any government who could believably threaten to prosecute then offer a deal for cooperation? Some people even do it out of curiosity: https://news.ycombinator.com/item?id=11304752

Thats the thing, HT or Gamma without the co-operation of international law enforcement presumably would have a very hard time finding these people in a legal manner. So whats going on up there.

HT Gamma can file a complaint with the relevant authority, just like any other hacked company, and this could trigger an international LE operation.

So I'm not sure what your trying to say.

Re: Phineas Fisher's account of how he took down HackingTeam

#60
post #56
post #35

Earlier quoted context omitted.

After reading the original doc, by the style used and some slang (although it could be on purpose), I would say the author is from Chile. I'm glad to find people that still fight the system in this side of the world.

I would be willing to bet they are from Italy. I am Italian and they wrote about some stuff that you would know only if you followed Italian news. They could be dropping some contradictory clues, BTW. I could definitely see that.

Did you verify that the stuff you refereed to as only being known if you follows Italian news is not on the net? Don't those Italian news outlets have websites?

This guy seems to be pretty good at googling around for stuff.

Post reply on HN