Earlier quoted context omitted.
It's entirely irrelevant to this release. The attribution to Russia has nothing to do with the language of strings embedded in the malware. It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests. Successfully hacking, over the course of about a decade,…
> It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests. Is there an official source that actually breaks down the similarities to which attacks? I have my doubts about the attribution of the DNC hack to _state_ agents. The only specific I've read was…
Wikileaks releases CIA's Marble: Malware obfuscation tools
261–270 of 284 posts
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#262Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#263Earlier quoted context omitted.
Edit: part of my comment is corrected by comment below - Thanks openasocket! Another comment about the content of this article: Three quarters down the wiki page there is code for "adding foreign language" to the code. The options are are to add code comments in Arabic/Chinese/Russian/Korean/Farsi. My gut reaction is the purpose of this added language is to obfuscate the true source of the code - i.e. the code has Ch…
This is for obfuscating string constants, the foreign languages included is a red herring. The reason for this is that nontrivial code often has string constants in it, and the string contents are stored in the ELF/PE file in a manner that makes it trivial to extract. Since these strings often reveal a lot about the malware (e.g. a string constant "Your computer has been infected with randomware. Please deposit %d bi…
The fact that this paragraph[0] exists on the Stuxnet wiki is telling:
> Some have also referred to several clues in the code such as a concealed reference to the word "MYRTUS", believed to refer to the Myrtle tree, or Hadassah in Hebrew. Hadassah was the birth name of the former Jewish queen of Persia, Queen Esther. [...] Also, the number 19790509 appears once in the code and might refer to the date "1979 May 09", the day Habib Elghanian, a Persian Jew, was executed in Tehran. Another date that appears in the code is "24 September 2007", the day that Iran's president Mahmoud Ahmadinejad spoke at Columbia University and made comments questioning the validity of the Holocaust. Such data is not conclusive, since, as written by Symantec, "Attackers would have the natural desire to implicate another party" with a false flag.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#264Earlier quoted context omitted.
>Telling Chinese people that their government is systematically harvesting organs of Tibetian people has no new information or benefit. This is hilarious. Whatever you have been smoking, it needs to stop.
You are the one apparently smoking something. It is common knowledge that China uses prisoners as a way to mass harvest organs. http://www.cnn.com/2016/06/23/asia/china-organ-harvesting/
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#265Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#266Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#267Earlier quoted context omitted.
The problem with holding Wikileaks as "selective" is that you would have to establish that there are true leaks which they have withheld from us. There's this popular misconception that Wikileaks actually hacks to obtain the data, but this is false and no one has ever so much as attempted to prove otherwise. So given that they can't select the sources, the claims of them being "selective" just sound ignorant to anyon…
How would we tell the difference between a selective Wikileaks and a publish-everything Wikileaks?
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#268Earlier quoted context omitted.
The problem with holding Wikileaks as "selective" is that you would have to establish that there are true leaks which they have withheld from us. There's this popular misconception that Wikileaks actually hacks to obtain the data, but this is false and no one has ever so much as attempted to prove otherwise. So given that they can't select the sources, the claims of them being "selective" just sound ignorant to anyon…
First of all, if you know how Wikileaks operates, you know that as well as the leaks they generate content and opinions. They are not merely a funnel. Second, if they were trying to be just a funnel but realised that they were only getting information from limited sources with a known agenda, then they would also know that they are facilitating a political agenda. They could be open about this. But they are not. They…
Yes, but that opinion is that powerful, unaccountable organizations shouldn't be able to keep deep secrets from the general public when they do things like manufacturing consent for war.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#269Earlier quoted context omitted.
There should be secrets. there should not be secret attacks on every computer on the planet.
I dont think there are, but who can say. But you realize the US isn't the only one hacking systems, right?
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#270Earlier quoted context omitted.
http://thehill.com/blogs/ballot-box/presidential-races/29345...
I was expecting something more damning. But I guess they could have published the info, and the reason they didn't is not very convincing. It suggests they are more after the publicity than after a reputation of publishing anything and everything.