Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

211–220 of 502 posts

Re: Technical report on DNC hack [pdf]

#211

Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future. So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.

> the point of this report is not to justify the punitive actions taken today.

You mean the point of the persons who wrote it? Probably not.

But the intent of those who decided to release it today? It most likely was. If so many HN commenters--sophisticated computer users and people with cognitive abilities way above average--feel like it doesn't go without saying, how many CNN or Fox News will realise it doesn't make the case against Russian?

They'll just remember that some documents were released by some US intel agencies, proving that the Russians did "it" (without even a clear idea of what "it" might be), while the US govt punished them. That's good enough for people who saw no problem with going to war against Iraq because of 9/11.

What worries me is that all of this Russian hackers + Fake News agitprop is that it looks like a perfect prelude to justify Internet censorship in Western democracies. When Internet allowed Obama to "steal" the Democratic party from Clinton in 2008, it was OK: maybe a bit embarrassing, but his policies weren't really that different from hers. But in 2016, with Sanders almost stealing the party again, and Trump taking the GOP then the general election by storm, politicians and their sponsors realised they didn't effectively influence voters through mainstream media any more. They've finally realised how scared they should be of Internet, and they'll want to "civilise" it, i.e. make it as controllable as billionaire-owned TV channels and newspaper. I hope they'll fail, but some of them will try to.

Re: Technical report on DNC hack [pdf]

#212
At least the report is short. As others have stated, it doesn't really lay out any new evidence to believe the Russian government was behind the hack. It lays out information that almost looks like evidence, such as a list of usernames, but doesn't discuss how the information is relevant to anything. There is an assertion that three teams were involved, and that two teams communicated with each other, but no discussion of where this information comes from or why anyone should care how many teams there were. I get the feeling that there's a message for someone, but I'm certainly not the intended recipient.

The advice on avoiding similar hacks in the future is a grab bag. Near the end it encourages using /etc/shadow on POSIX systems. I installed Linux on my personal computer in 1999. Since then, I've installed several Linux distributions, FreeBSD, OpenBSD, Plan 9, Inferno, etc. I can't remember any installation offering to store password hashes in /etc/passwd. Some of the advice is better, but not all of it is. I'm honestly disappointed. Perhaps this is a wake-up to somebody, but I would hope Sony's hack would have already served that purpose.

Re: Technical report on DNC hack [pdf]

#213

Earlier quoted context omitted.

You can read about the backdoors they used here: https://www.crowdstrike.com/blog/bears-midst-intrusion-democ... The summary: One used Powershell modules and Windows Scheduler to run scripts. Another used a combination of Twitter and public sites like Github/Dropbox for command and control. In my opinion, neither is impressively sophisticated, and a skilled application developer could whip up something similar in a w…

I have personally written that exact tool while learning Python. A RAT using Twitter for C & C. Uses PGP for encryption and verification. The twitter handles for the C & C change based on a hash of Googles lastest Doodle so you can access it without fear of account deletion. TIL I'm as good as a state level intelligence team. Hey CIA/NSA we know you are reading this, my contact info is in my profile. Hire me.

Tomorrow: "Cyberhacker admits to Russian hacker tools"

> Yesterday, an Internet cyber hacker using the alias "cmdrfred" claimed on "HackerNews", an elite underground hacker site, that he or she personally built the hacking tools used by Russia to breach the DNC email servers and change the outcome of the recent election.

> "I have personally written that exact tool [it] uses ... encryption ... so you can access [the DNC] without fear."

> "I'm as good as a state level intelligence team."

> cmdrfred went on to taunt American intelligence agencies while admitting that he was aware that elite anti-cyberhacking teams from the NSA and CIA were monitoring his operations.

> The owner of HackerNews Paul Graham -- venture capitalist, flamboyant playboy, and known Russian sympathizer -- could not be reached for comment.

Re: Technical report on DNC hack [pdf]

#214

Jeez people, read the report, it isn't any kind of justification of anything, its just a fairly generic don't do this, like I see 100 times a week at work. The real details were likely shown to congress and the senate (or at least a portion of it). Those are the only people who can say if the actual attack was real or imagined. Do you think the British and Americans were going to publish stories about Enigma back in…

> Do you think the British and Americans were going to publish stories about Enigma back in WW2 in the Times during the war? There were like a handful of people in the world who knew the details.

Well they plan on releasing the malware samples and evidence of the hack, so I'm not sure what you mean here...

This isn't the enigma in war time. It's not even a denied operation like Stuxnet (which was also had malware samples found in the wild and plenty of details on how it was spread and worked). It's standard nation state malware from a foreign adversary and the phishing email was already released from the Podesta hack via Wikileaks.

The only question is how they connected the public leaks to Russia. Which most people doubt they even have. But that detail won't stop the press from believing it was one and the same. Even though any number of people could have accessed it.

But otherwise simply connecting the hack to Russia and the hack itself is hardly a mystery or interesting in itself. You're very much overselling that which I'll just attribute to not knowing much about infosec.

From NYTimes:

>> The samples of malware were in what the Obama administration called a “joint analytic report” from the F.B.I. and the Department of Homeland Security that was based in part on intelligence gathered by the National Security Agency. A more detailed report on the intelligence, ordered by President Obama, will be published in the next three weeks, though much of the detail — especially evidence collected from “implants” in Russian computer systems, tapped conversations and spies — is expected to remain classified.

http://mobile.nytimes.com/2016/12/29/us/politics/russia-elec...

Obviously they won't release every detail, especially regarding implants in Russia, but they'll release more than just 'trust us'. They always do.

Re: Technical report on DNC hack [pdf]

#215

Is this more or less reputable than the clear and unambiguous claims of Craig Murray regarding the DNC leak, which he has stated clearly were the result of him personally traveling to DC, acquiring the data dump face to face from a non-Russian DNC insider, and then returning to the UK to give them to Assange himself. If the us-cert.gov report is to be believed, then both Assange and Murray are liars. Both can not be…

Craig Murray said he got the document drop in September, right? Didn't Wikileaks start publishing emails earlier than that? (Sincere question, I don't understand the timeline here.)

Thank you BryantD, that is a relevant and useful contribution.

Per wikileaks:

> "Starting on Friday 22 July 2016 at 10:30am EDT, WikiLeaks released over 2 publications 44,053 emails and 17,761 attachments from the top of the US Democratic National Committee -- part one of our new Hillary Leaks series. The leaks come from the accounts of seven key figures in the DNC: Communications Director Luis Miranda (10520 emails), National Finance Director Jordon Kaplan (3799 emails), Finance Chief of Staff Scott Comer (3095 emails), Finanace Director of Data & Strategic Initiatives Daniel Parrish (1742 emails), Finance Director Allen Zachary (1611 emails), Senior Advisor Andrew Wright (938 emails) and Northern California Finance Director Robert (Erik) Stowe (751 emails)."

Per Craig Murray:

"Craig Murray, former British ambassador to Uzbekistan and a close associate of Wikileaks founder Julian Assange, told Dailymail.com that he flew to Washington, D.C. for a clandestine hand-off with one of the email sources in September."

http://www.dailymail.co.uk/news/article-4034038/Ex-British-a...

Perhaps Craig Murray meant September 2015, or perhaps the Daily Mail wrote the wrong thing down. If neither of these is true, there's a serious discrepancy in these claims. Lacking such an explanation, the reasonable conclusion here given the date discrepancy would be that either Ambassador Murray or the Daily Mail is lying about the dates.

Re: Technical report on DNC hack [pdf]

#216
post #98

Earlier quoted context omitted.

This stopped being about Hilary Clinton over a month ago. This is extremely important regardless of who is President.

is it though? we have been spying and counterspying on russia for decades. this is literally not news at all. the real news is the distraction campaign drummed up by HRC & Co to cover up their shady dealings during the democratic campaign.

your counterpoint is that you don't care?

Re: Technical report on DNC hack [pdf]

#217

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

The actual evidence is probably closer to 'we have moles in the kremlin and taps on their phones' but they're not exactly going to publish that are they.

Re: Technical report on DNC hack [pdf]

#218
post #116

Earlier quoted context omitted.

The basic flaws I'd mention are: - Multiple state actors (or well-funded non-state actors) likely compromised the emails. - A state actor could also have faked the "trail" that points to Russia. - The rest of the evidence is circumstantial. Sure, if we pretend we live in a pre-stuxnet, script kiddie sort of world, this was likely a high level state sponsored attack, but it seems preposterous that a state actor would…

Exactly, it could just as easily be China making it look like Russia did it...

Yea, This made me think of chinese black pr groups too.

Hillary was not liked in china or korea.

Re: Technical report on DNC hack [pdf]

#219
post #35

As an aside, for those looking to understand YARA rules, [1] provides a brief introduction and [2] introduces how to write them. I needed to look it up myself, but seems relatively straightforward if you have a programming background. tl;dr: YARA rules are a method of categorizing malware based on their characteristics. So the PDF here released a YARA rule to determine a specific piece of malware used in the hack (it…

I have found some code that matches that ruleset perfectly (see my other comment: [1]). It was surprisingly easy to find, a github search for .substr(md5(strrev( is all it takes to find this top-secret payload.

Note how the base64decode regex doesn't actually match base64_decode, but it matches

    $l___l_='base'.(32*2).'_de'.'code';
which is the first statement in the github code I found.

1: https://news.ycombinator.com/item?id=13281008

Re: Technical report on DNC hack [pdf]

#220

Earlier quoted context omitted.

> which would be enforced in any corporation with more than a couple dozen employees No they wouldn't, and you are one of the people here who I would say should very well know it. :p The DNC screwed up, but the overwhelming majority of everybody else screws up to this level or worse on the regular.

Yeah, you are completely right, and I completely agree, as I imply later in the post. Such mistakes are extremely common across the spectrum, at companies large and small alike (remember when American Express accidentally exposed an internal debugging application? [0] :O). Cybersecurity is still very difficult for everyone, and I don't mean to imply any differently. My quip was meant to emphasize that the security br…

What it really requires is the blind eye (or knowing nod) of a nation state, since with the level of unuttered evidence (and the private orgs named which no one seems to be mentioning here) the idea that "we won't prosecute you if you do this" is the nation-state sophistication here. In the US you'd normally face justice for this, regardless of the locale or the ease of the break-in.
Post reply on HN