Earlier quoted context omitted.
> By the way iOS is the only popular operating system I know that doesn't allow to execute files downloaded from web or emails. Windows 8, 8.1, and 10 don't allow it either. SmartScreen will block unsigned executables by default[0]. Enterprise customers should be using AppLocker which does a lot of what SmartScreen does, but with more flexibility and control. The issue arises when [bad] System Administrators disable…
"If Microsoft forced either SmartScreen OR AppLocker" Meh, just add a button or clickable link that allows the sysadmin to swiftly disable such warnings. Just make sure to put a scary-enough disclaimer that doing so can expose you to very bad, malicious stuff, from ill-intentioned people. It might get more application publishers to implement signing, just as Vista and 7 got rid of the "run everything as administrator…
Technical report on DNC hack [pdf]
181–190 of 502 posts
Re: Technical report on DNC hack [pdf]
#182Earlier quoted context omitted.
The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.
Could you elaborate? Once you have a password shouldn't it be as easy as just downloading all the emails? Any email client should have the functionality built in. edit: seeing some reports they used "sophisticated" SQL injection... okay...I mean for a lay person it seems sophisticated, sure. But for anyone in the industry it's one of the oldest and easiest tricks in the book. I really suspect news sources are knowing…
https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...
The summary: One used Powershell modules and Windows Scheduler to run scripts. Another used a combination of Twitter and public sites like Github/Dropbox for command and control.
In my opinion, neither is impressively sophisticated, and a skilled application developer could whip up something similar in a week or two. Using popular sites like Twitter/Dropbox for C&C has been common for years, and you can purchase similar backdoors/RATs for less than $100.
edit: Another interesting point from the link above: the two exploits stole exactly the same info once inside the DNC network. This would obviously be a big no-no for a sophisticated state actor as it doubles your chance of being compromised, but the author explains it away by claiming that Russia's intelligence agencies are disorganized and adversarial.
Re: Technical report on DNC hack [pdf]
#183I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…
The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.
Previous JARs have not attributed malicious cyber activity to specific
countries or threat actors. However, public attribution of these activities
to RIS is supported by technical indicators from the U.S. Intelligence
Community, DHS, FBI, the private sector, and other entities.
The report then discusses when the attackers did and mitigation strategies.Re: Technical report on DNC hack [pdf]
#184Earlier quoted context omitted.
The RNC was hacked as well, although they similarly circumvented the same security procedures.
That the RNC was also hacked seems to be a popular, but probably false, meme. http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...
Re: Technical report on DNC hack [pdf]
#185Re: Technical report on DNC hack [pdf]
#186Earlier quoted context omitted.
> This attacks could be easily mitigated. [...] second, we should start using physical cryptographic keys instead of passwords Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.
Can confirm. I did tech at the DNC in 2012. We pushed to get senior staff using 2FA and ran internal phishing drills. Obviously didn't take.
Re: Technical report on DNC hack [pdf]
#187Hope the main report due in 3 weeks has some substance.
Re: Technical report on DNC hack [pdf]
#188Earlier quoted context omitted.
It's rather naive to think these things didn't have an effect. The problem isn't the truth of the claims, it's that the illicitly gained information was strategically released to disrupt one specific campaign, effectively destabilizing our election. Much like Comey's last minute email announcement revealed nothing new, yet allowed the email narrative to renew its currency in the last days of the campaign. Imagine if…
> Imagine if the IRS "accidentally" released Trump's tax returns or been hacked to allow this data to come out. The NYT did publish Trump's stolen tax return, and were quite self-congratulatory about having done so... > Or if the alleged tapes went public of Donald Trump making openly racist remarks on his TV shows outtakes. ...and, the stories about the hacked material were outnumbered probably 100-1 by the simultan…
Since Trump was mic'd up on the bus (they were going to film a segment), I think there is a case to be made that he couldn't realistically make the case he didn't know he was being recorded or could be recorded. I think it'd be a hard sell that this was an illegally recorded conversation.
Re: Technical report on DNC hack [pdf]
#189It seems unlikely that email hacking will stop in the future. If the leaked emails actually influenced the elections, it was because of their content. I've heard exactly zero credible claims that the leaked emails were falsified in any way. Perhaps if political candidates/party executives are going to do unethical/illegal things, they shouldn't discuss them over email. Edit: changed "zero claims" to "zero credible cl…
And if you want to focus on foreign (illegal) involvement in U.S. elections, look no further than the alleged Chinese involvement in the 1996 presidential election https://en.wikipedia.org/wiki/1996_United_States_campaign_fi...
My point being, this is almost entirely political. It changes no ones mind.
Re: Technical report on DNC hack [pdf]
#190Earlier quoted context omitted.
The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.
This report merely points the finger at Russia; it does not purport to substantiate that allegation. Previous JARs have not attributed malicious cyber activity to specific countries or threat actors. However, public attribution of these activities to RIS is supported by technical indicators from the U.S. Intelligence Community, DHS, FBI, the private sector, and other entities. The report then discusses when the attac…
That's the point, its just another completely baseless, unsubstantiated accusation. This report contains nothing that suggests that the Russians were any more likely to be the source of the hack then countless other entities. The problem is that these baseless claims are being presented as evidence and being consumed uncritically as such. Take for example the headline in PcMag:
>Hacking Evidence in Hand, Obama Sanctions Russia
http://www.pcmag.com/news/350675/hacking-evidence-in-hand-ob...