This report is a joke. I didn't find any reasoning about attribution. Here is the only valuable part: " rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = " 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } "
Did you read the first page? This report has nothing to do with detailing or justifying attribution
Technical report on DNC hack [pdf]
41–50 of 502 posts
Re: Technical report on DNC hack [pdf]
#42Earlier quoted context omitted.
>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?
Why trust them in the first place, look at the evidence and if you disagree with a conclusion, be able to say why. This is the whole problem we're dealing with right now - people just decide they do or do not trust something. Don't agree with a fact check? Just call it bogus and move on, even though it might be a 50 point case they make why bother finding a flaw in their reasoning and using that to refute their concl…
- Multiple state actors (or well-funded non-state actors) likely compromised the emails.
- A state actor could also have faked the "trail" that points to Russia.
- The rest of the evidence is circumstantial.
Sure, if we pretend we live in a pre-stuxnet, script kiddie sort of world, this was likely a high level state sponsored attack, but it seems preposterous that a state actor would be so sloppy:
If you were Putin wishing to try to use spearfishing to get access to specific accounts, you would not source that work to groups that were known to work with your government. You'd set up a fake Nigerian operation so that if found it would look like the email address had been randomly chosen from a list of many used by some Nigerian person to try to scam a few thousand dollars.
This is not akin to thinking three or four moves ahead, it's simply thinking one move ahead.
Re: Technical report on DNC hack [pdf]
#43The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.
Plus in some people's minds a private defense contractor being "hacked" is more along the lines of industrial espionage instead of a major political party being "hacked" during an election. Even worse, certain news outlets reporting that the election itself(!) was hacked which is misleading and could make people think that voting machines were actually hacked by a foreign power instead of the PsyOps which allegedly took place.
Re: Technical report on DNC hack [pdf]
#44Earlier quoted context omitted.
It seems notable that many of these comments are jumping on this for not providing proof that it was Russia, when that was not the intention of the report. The first page states- >This JAR provides technical indicators related to many of these operations, recommended mitigations, suggested actions to take in response to the indicators provided, and information on how to report such incidents to the U.S. Government.
The bloomberg article I read ( http://archive.is/j5wRd ) presented it as evidence. Maybe other publications are doing the same. >As part of the administration’s response, the FBI and Homeland Security Department also released a report with technical evidence intended to prove Russia’s military and civilian intelligence services were behind the hacking and to expose some of their most sensitive hacking infrastructure.
Quite predictable, since they also considered the wild accusations of various politicians of a high level Russian conspiracy to be evidence.
Re: Technical report on DNC hack [pdf]
#45Earlier quoted context omitted.
An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.
>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?
The best and only thing the average citizen can really do is try to put people in office who can intelligently parse classified information and evidence from intelligence agencies.
Re: Technical report on DNC hack [pdf]
#46Edit: changed "zero claims" to "zero credible claims"
Re: Technical report on DNC hack [pdf]
#47Earlier quoted context omitted.
Did you read the first page? This report has nothing to do with detailing or justifying attribution
Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.
Re: Technical report on DNC hack [pdf]
#48~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|grep -f exits -c 191 ~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|wc -l 876 At least 191 of the IOC IPs are (probably random) Tor exit nodes :) The actual number may very well be higher, I just grabbed current exit node list from https://check.torproject.org/exit-addresses Here's the PHP backdoor the YARA rule…
Re: Technical report on DNC hack [pdf]
#49The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.
Actually, Donna Brazile, who is inexplicably still the current chair of the DNC, claimed the emails were falsified: https://youtu.be/P_WHsr07cbY?t=458
Re: Technical report on DNC hack [pdf]
#50Earlier quoted context omitted.
Did you read the first page? This report has nothing to do with detailing or justifying attribution
Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.
If my boss drops a request on me to write a report on the "technical details regarding the tools and infrastructure used by the X to do Y", I don't spend time in the report explaining that X did Y. That's not the point of the report I was asked to make. That's a different report.