Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

221–230 of 502 posts

Re: Technical report on DNC hack [pdf]

#221

Earlier quoted context omitted.

>I have seen similar obfusaction many times before. If you look at it carefully you'll very quickly realize that you haven't. This isn't at all like your typical base64 silliness, and it's certainly very uncommon. This actually uses a cookie to decrypt the encrypted shell before executing it. Pretty obvious, but very few things actually do it.

hasnt this tech been known for a year now. https://www.fireeye.com/blog/threat-research/2015/12/uncover... Its been taught in my security class.

I'm not sure if I'd describe encrypting and decrypting data as a "tech" :) And it's certainly been known for longer than a year, it's just very rare to see PHP shells doing it like this.

Re: Technical report on DNC hack [pdf]

#223

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

> This attacks could be easily mitigated. [...] second, we should start using physical cryptographic keys instead of passwords Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.

I think it's a generational thing. Americans of a certain vocation and certain age and older tend to have no idea about how this whole Internet thing works. No matter what their education level or achievement level. Obama held onto his Blackberry for almost 2 years after SS told him you can't use that thing.

I suspect what needs to happen is each branch of government needs to have infosec people assigned to it that sets standards and policies around this stuff. If they don't comply there have to be consequences.

Re: Technical report on DNC hack [pdf]

#224

Earlier quoted context omitted.

> By the way iOS is the only popular operating system I know that doesn't allow to execute files downloaded from web or emails. Windows 8, 8.1, and 10 don't allow it either. SmartScreen will block unsigned executables by default[0]. Enterprise customers should be using AppLocker which does a lot of what SmartScreen does, but with more flexibility and control. The issue arises when [bad] System Administrators disable…

The problem here is that the system is not secure by default, one needs to hire a qualified specialist to set everything up. By default the user can run executable attachments or files downloaded from browser and it is a wrong design decision made many years ago. Users do not understand what is an "executable file", they got used to click an icon to see the file contents. This is just poorly designed UI that helps to…

It is secure but default. Out of the box SmartScreen blocks unsigned executables like I stated above.

System admins are going out of their way to disable default protections.

Also Windows 10 has a package manager and app store.

Re: Technical report on DNC hack [pdf]

#225
post #89

Even if Wikileaks never published anything, She would have still lost. She had the greatest help, money and collusion from government, media, international community elites and her party and still lost against the most unpopular and unfit candidate of all time who got more than 300 electoral votes. That's how loser and corrupt she is. Just get over it.

That is unfortunately something we will never get to know. Trump's election is tainted by both the Russian DNC hack and the FBI letter released immediately before the election. It is impossible to know what would have happened without these two events

IMO the russian hack did not taint Trump. It tainted Hillary. That said, some people are trying very hard to make this somehow invalids trumps win, tho I actually think it reinforces it.

"He wouldn't have won if Russia didn't expose Hillary's flaws" is not exactly the best argument for why Trump shouldn't have won, IMO.

Re: Technical report on DNC hack [pdf]

#227

Earlier quoted context omitted.

"Many breach announcements this year pointed to a “sophisticated attacker” as a narrative of their issue. This usually is followed up by criticism when an initial means of their compromise is revealed. Most breaches begin with spear phishing, commodity exploits, a leaked key, or some other obvious or preventable detail. However, this is almost never the “sophisticated” aspect of a breach worth talking about. It’s eas…

Valid point, but I should clarify my original comment: I don't find either aspect of the attack--the entry or the payload--to be particularly sophisticated. Everything I've read indicates the bulk of work was done by Powershell scripts, along with a backdoor process running in the open. If you told me that the backdoor was a kernel level rootkit or something similar then I could get onboard, but as it stands I don't…

The main arguments might be not technical. The political emails are pretty boring stuff for an outsider so it should be some government or politician bothering to get them.

I also remember that some gmail accounts of people from DNC staff were hacked. Gmail probably has logged what IP addresses were used when logging in with stolen passwords and they could be used as a hint too (though most probably they point to cheap VPS bought by some anonymous person or Tor node, I doubt anyone would use a stolen password from their real IP address).

Re: Technical report on DNC hack [pdf]

#229
"This document provides technical details regarding the tools and infrastructure used by the Russian civilian and military intelligence Services (RIS) to compromise and exploit networks and endpoints associated with the U.S. election"

A great big distraction from the real issue, being the contents of the emails as leaked by Wikileaks in retaliation for framing Assange with that honeypot operation in Sweden. The technical source of the hack being Microsoft Windows. The same one they're running Homeland Security on :)

Re: Technical report on DNC hack [pdf]

#230
post #184

Earlier quoted context omitted.

That the RNC was also hacked seems to be a popular, but probably false, meme. http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...

Belief in this will likely depend on who someone trusts more, spokespersons for the RNC, or the New York Times and the Washington Post.

Being able to read a bit of Russian helps too.

Man them parties in the Kremlin these past few weeks. Truly epic.

Хотите водки?

Post reply on HN