Live data from Hacker News

Wikileaks releases CIA's Marble: Malware obfuscation tools

wikileaks.org

261–270 of 284 posts

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#261
post #90

Earlier quoted context omitted.

It's entirely irrelevant to this release. The attribution to Russia has nothing to do with the language of strings embedded in the malware. It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests. Successfully hacking, over the course of about a decade,…

> It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests. Is there an official source that actually breaks down the similarities to which attacks? I have my doubts about the attribution of the DNC hack to _state_ agents. The only specific I've read was…

https://motherboard.vice.com/en_us/article/all-signs-point-t...

https://medium.com/@thegrugq/evidence-guccifer-2-0-is-russia...

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#262
post #50

Earlier quoted context omitted.

There is simply no evidence of that.

You are saying that Wikileaks has a ton of other documents but won't publish them? Based on what exactly?

I'm not saying that, I'm saying there is no evidence either way.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#263
post #198

Earlier quoted context omitted.

Edit: part of my comment is corrected by comment below - Thanks openasocket! Another comment about the content of this article: Three quarters down the wiki page there is code for "adding foreign language" to the code. The options are are to add code comments in Arabic/Chinese/Russian/Korean/Farsi. My gut reaction is the purpose of this added language is to obfuscate the true source of the code - i.e. the code has Ch…

This is for obfuscating string constants, the foreign languages included is a red herring. The reason for this is that nontrivial code often has string constants in it, and the string contents are stored in the ELF/PE file in a manner that makes it trivial to extract. Since these strings often reveal a lot about the malware (e.g. a string constant "Your computer has been infected with randomware. Please deposit %d bi…

Analysts might not, but it could be used as "proof" for the less knowledgeable (e.g. politicians).

The fact that this paragraph[0] exists on the Stuxnet wiki is telling:

> Some have also referred to several clues in the code such as a concealed reference to the word "MYRTUS", believed to refer to the Myrtle tree, or Hadassah in Hebrew. Hadassah was the birth name of the former Jewish queen of Persia, Queen Esther. [...] Also, the number 19790509 appears once in the code and might refer to the date "1979 May 09", the day Habib Elghanian, a Persian Jew, was executed in Tehran. Another date that appears in the code is "24 September 2007", the day that Iran's president Mahmoud Ahmadinejad spoke at Columbia University and made comments questioning the validity of the Holocaust. Such data is not conclusive, since, as written by Symantec, "Attackers would have the natural desire to implicate another party" with a false flag.

[0] https://en.wikipedia.org/wiki/Stuxnet#Israel

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#264

Earlier quoted context omitted.

>Telling Chinese people that their government is systematically harvesting organs of Tibetian people has no new information or benefit. This is hilarious. Whatever you have been smoking, it needs to stop.

You are the one apparently smoking something. It is common knowledge that China uses prisoners as a way to mass harvest organs. http://www.cnn.com/2016/06/23/asia/china-organ-harvesting/

I am not going to contest that, but nothing has came out to support the claim of "systematic organ harvesting in tibet". I work with surgeons who specialise in liver transplant and you usually want to position donors as close to recipients as you could to minimise transport delay, and Tibet is just too far away from where the.demand is.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#266
post #148

It's unethical for anyone who calls themselves an engineer to do this kind of work.

It's unethical to write a script that will xor strings?

>"It's unethical to shoot somebody"

It's unethical to pull on a little piece of metal?

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#267
post #227
post #206

Earlier quoted context omitted.

The problem with holding Wikileaks as "selective" is that you would have to establish that there are true leaks which they have withheld from us. There's this popular misconception that Wikileaks actually hacks to obtain the data, but this is false and no one has ever so much as attempted to prove otherwise. So given that they can't select the sources, the claims of them being "selective" just sound ignorant to anyon…

How would we tell the difference between a selective Wikileaks and a publish-everything Wikileaks?

If true leaks came out by other means with proof they were rejected by Wikileaks after being offered with validation.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#268
post #206

Earlier quoted context omitted.

The problem with holding Wikileaks as "selective" is that you would have to establish that there are true leaks which they have withheld from us. There's this popular misconception that Wikileaks actually hacks to obtain the data, but this is false and no one has ever so much as attempted to prove otherwise. So given that they can't select the sources, the claims of them being "selective" just sound ignorant to anyon…

First of all, if you know how Wikileaks operates, you know that as well as the leaks they generate content and opinions. They are not merely a funnel. Second, if they were trying to be just a funnel but realised that they were only getting information from limited sources with a known agenda, then they would also know that they are facilitating a political agenda. They could be open about this. But they are not. They…

> First of all, if you know how Wikileaks operates, you know that as well as the leaks they generate content and opinions. They are not merely a funnel.

Yes, but that opinion is that powerful, unaccountable organizations shouldn't be able to keep deep secrets from the general public when they do things like manufacturing consent for war.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#269
post #39

Earlier quoted context omitted.

There should be secrets. there should not be secret attacks on every computer on the planet.

I dont think there are, but who can say. But you realize the US isn't the only one hacking systems, right?

Once people find out their beloved Sweeden and Norway are also doing it, they will start scratching their heads.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#270
post #236

Earlier quoted context omitted.

http://thehill.com/blogs/ballot-box/presidential-races/29345...

I was expecting something more damning. But I guess they could have published the info, and the reason they didn't is not very convincing. It suggests they are more after the publicity than after a reputation of publishing anything and everything.

From the description, it sounds like they got that opposition research doc that every other media organization had and which most of them said they didn't publish because they weren't able to validate it.
Post reply on HN