Live data from Hacker News

How hackers abused satellites to stay under the radar (2015)

arstechnica.com

51–60 of 69 posts

Re: How hackers abused satellites to stay under the radar (2015)

#51

Earlier quoted context omitted.

Not necessarily. I briefly pretended to be a criminal, mostly for fun. (Most readers will go "Uh huh" at this, but it was just a game.) Say you're developing the next Silk Road. Say you have perfect opsec, and you never reveal any personal info. What are your risks? The #1 risk is discovery of your physical location. Before every action, you must ask yourself: Will the next keystroke get me caught? It takes immense d…

- did you have a cellphone in your pocket? - where did you get the cash? - by talking about it you negated all the advantages you built up - if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store - you may have left fingerprints in the store - the cabdriver has seen your face and knows your home address, you should have walked to the s…

Just woke up. Here you go:

> did you have a cellphone in your pocket?

Of course not.

> where did you get the cash?

I withdrew $500 from an ATM, then spent several days breaking them into $20's at various tiny Mexican restaurants. No, I didn't have a phone while doing this either.

Important note: I planned on waiting a year after the operation before touching the funds to further reduce the risks.

> by talking about it you negated all the advantages you built up

There were no advantages left. I ended up so broke I had to use the $400 to pay bills. It was a sad day, but that's how things go sometimes.

Hopefully someone else here can use this info to carry the torch.

> if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store

That's why I waited until the middle of winter, when it was so cold it wasn't uncommon to be wearing a facemask.

> you may have left fingerprints in the store

I was careful to wear gloves, also bought from goodwill. Winter made this not-unusual.

> the cabdriver has seen your face and knows your home address, you should have walked to the spot where you changed your clothes

This was three years ago, and I got an important detail wrong in my comment: I did walk to the spot where I changed my clothes, then walked several more miles and hailed a cab. Not the other way around, like I originally said.

> the clothes bought at the goodwill, did you pay cash for those too?

Yes.

> what happened to the clothes afterwards?

The clothes, receipts, and everything else stayed in the trash bag, buried in the back of my closet. I never used the clothes again. Still have them, actually.

> how did you summon the cab to your change location?

After I was several miles away from home base, I walked until spotting one.

> you're lucky that neither of the houses you changed next to had a dog

The changing clothes part was easily the riskiest part of the operation. I brought a dim blue flashlight just to see. If anyone spotted me there, I would've pretended to be changing my shoes and called the whole thing off.

If you have a list of questions 10 times as long, better ask them so that someone else doesn't make any mistakes either.

Re: How hackers abused satellites to stay under the radar (2015)

#52

Earlier quoted context omitted.

- did you have a cellphone in your pocket? - where did you get the cash? - by talking about it you negated all the advantages you built up - if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store - you may have left fingerprints in the store - the cabdriver has seen your face and knows your home address, you should have walked to the s…

One person entered a dark alley, and then a few minutes later one person with the same build wearing different clothes left...

Once you're wearing goodwill clothes on top of your regular clothes with a coat in winter, you end up looking quite different.

Re: How hackers abused satellites to stay under the radar (2015)

#53
post #47

Earlier quoted context omitted.

Infected system sends packets to a decoy what? Satellite? And then the satellite forwards it.

Lets say John lives near (200 miles away) the C&C server and that John's IP is 192.168.7.2. John is the decoy, so the malware sends requests to John's IP. John doesn't get the requests, due to his firewall blocking them, leaving these lingering open tcp connections. So the C&C server is free to finish the TCP handshake spoofing their IP to be 192.168.7.2 As far as anyone can tell they are John, but when you go to Joh…

1) How does the satellite come into this.

2) How does the C&C server complete the request. Are the hanging ports on the victim's side?

3) If the C&C server completes the connection, how do they carry on talking? Just like spoofing IPs, you can't ever get a reply. Or do they do the John decoy thing for every packet?

Re: How hackers abused satellites to stay under the radar (2015)

#54
post #14

Are these satellites in geosynchronous orbit? If not, and you've got a copy of the malware, you ought to be able to narrow the location of the C&C server using its orbit and a correlation analysis of when the malware receives comms from the C&C. Depending on the orbit, I'll bet you could bracket it to a few degrees. Since the attackers can't stop answering C&C calls or their network collapses, merely publishing that…

$DAYJOB is about deploying satellite equipment. > Are these satellites in geosynchronous orbit? Yes. Satellites in other orbits require tracking antennas. A typical one has a four-figure cost at the very least. And if you need uninterrupted connection, you need to have at least two of them, one for tracking the one that sets, and another for tracking the one that rises. > I'm willing to bet that satellite downlink pe…

Any comments about three upcoming massive constellations from SpaceX, oneweb, etc. and their pizza box antennas?

Re: How hackers abused satellites to stay under the radar (2015)

#55
post #47

Earlier quoted context omitted.

Lets say John lives near (200 miles away) the C&C server and that John's IP is 192.168.7.2. John is the decoy, so the malware sends requests to John's IP. John doesn't get the requests, due to his firewall blocking them, leaving these lingering open tcp connections. So the C&C server is free to finish the TCP handshake spoofing their IP to be 192.168.7.2 As far as anyone can tell they are John, but when you go to Joh…

1) How does the satellite come into this. 2) How does the C&C server complete the request. Are the hanging ports on the victim's side? 3) If the C&C server completes the connection, how do they carry on talking? Just like spoofing IPs, you can't ever get a reply. Or do they do the John decoy thing for every packet?

1) The satellite system system broadcasts to everyone (apparently poorly/not encrypted) in the area, so it isn't necessary to take over any upstream routing in order to get a hold of the incoming packets. They just arrive at your doorstep, and since you configured them to be rejected by normal clients you know you won't have to compete for the response.

2) The C&C just responds over regular land-line. (Since the satellite service is download-only, this isn't any different from the service's normal clients.)

3) The reply keeps coming back over satellite and they keep grabbing it?

Re: How hackers abused satellites to stay under the radar (2015)

#56

Earlier quoted context omitted.

I'm not even GP but I think I can answer a lot of these. Are you maybe trying a little too hard to play devil's advocate? - did you have a cellphone in your pocket? After going through all of this, do you honestly think he forgot that detail? - where did you get the cash? That's a good question. Hopefully he withdrew a different amount of cash on a completely separate date, otherwise bank account and transactions sur…

> I'm not even GP but I think I can answer a lot of these If you can, then he's failed even more. So no, I don't think that you can answer any of them. The point I'm trying to make is that the best made plans of men and mice fail due to overlooking some small detail. I could easily make that list 10 times as long. One or more slip ups could allow someone to tie 1-and-1 together to make 3 and it is game over. The funn…

Wait. I thought the Unabomber got caught after he made people publish his manifesto online/on TV. From what I remember from reading on the internet, his relatives identified certain key points in the manifesto and immediately tipped the FBI telling them about him and his similar ideologies.

Re: How hackers abused satellites to stay under the radar (2015)

#57
post #14

Are these satellites in geosynchronous orbit? If not, and you've got a copy of the malware, you ought to be able to narrow the location of the C&C server using its orbit and a correlation analysis of when the malware receives comms from the C&C. Depending on the orbit, I'll bet you could bracket it to a few degrees. Since the attackers can't stop answering C&C calls or their network collapses, merely publishing that…

$DAYJOB is about deploying satellite equipment. > Are these satellites in geosynchronous orbit? Yes. Satellites in other orbits require tracking antennas. A typical one has a four-figure cost at the very least. And if you need uninterrupted connection, you need to have at least two of them, one for tracking the one that sets, and another for tracking the one that rises. > I'm willing to bet that satellite downlink pe…

>If ever you lost satellite tv during bad weather, that's due to your antenna shaking because of the wind, not rainfade.

I wonder if thats why at my old job I was required to go onto the roof of a four story building to check the dish. The dish sat on old railway ties on a wavy roof.

I had to jump from one roof to another it was an L-shaped part of the roof where two buildings joined. I jumped onto a slanted icy roof in winter with a 50 foot drop to a parking lot.

Re: How hackers abused satellites to stay under the radar (2015)

#58

Earlier quoted context omitted.

> I'm not even GP but I think I can answer a lot of these If you can, then he's failed even more. So no, I don't think that you can answer any of them. The point I'm trying to make is that the best made plans of men and mice fail due to overlooking some small detail. I could easily make that list 10 times as long. One or more slip ups could allow someone to tie 1-and-1 together to make 3 and it is game over. The funn…

Wait. I thought the Unabomber got caught after he made people publish his manifesto online/on TV. From what I remember from reading on the internet, his relatives identified certain key points in the manifesto and immediately tipped the FBI telling them about him and his similar ideologies.

Yes, exactly that is my point.

So after all that careful work he still managed to blow it by not thinking of one obvious thing and he's been rotting in jail, ironically after he swore he would stop his bombing spree if they published his writing. He could not have been more right about that, his writings definitely made an end to his life as a domestic terrorist.

Staying alive and free while you are making powerful enemies is hard. The Unabomber was one of the smartest terrorists ever (IQ 160+), had a really long time to prepare what he did, was a lone wolf (which is a huge advantage compared to a larger number of people) and in the end blew it completely.

Re: How hackers abused satellites to stay under the radar (2015)

#59

Earlier quoted context omitted.

I'm not even GP but I think I can answer a lot of these. Are you maybe trying a little too hard to play devil's advocate? - did you have a cellphone in your pocket? After going through all of this, do you honestly think he forgot that detail? - where did you get the cash? That's a good question. Hopefully he withdrew a different amount of cash on a completely separate date, otherwise bank account and transactions sur…

> I'm not even GP but I think I can answer a lot of these If you can, then he's failed even more. So no, I don't think that you can answer any of them. The point I'm trying to make is that the best made plans of men and mice fail due to overlooking some small detail. I could easily make that list 10 times as long. One or more slip ups could allow someone to tie 1-and-1 together to make 3 and it is game over. The funn…

I'm glad you raised these points, because it dissuades other people from trying this flippantly.

But for what it's worth, I carefully considered each of those points from the outset. I hatched the plan and spent several months preparing for it daily.

I left a lot of details out (I didn't anticipate much interest...) such as the practice operation I did prior to this. I'm glad I ran a fake one, since it revealed a lot of mistakes I would've made which would've scrubbed the operation.

Before you start on a job like that you begin with laying the groundwork over the course of several years, any step along the way that can give away the game will endanger you and those around you. This is not something you cook up one find winter evening and put in motion without some extremely careful planning and creating multiple levels of cut-outs for any kind of activity that might point at your real identity.

Anyone who's considering doing anything like this should take these words to heart.

If anyone is going to fight these people and win, it has to be one of us. That means you have to try. It's doable, but you have to be absolutely meticulous.

P.S. Still mildly hopeful you have a list of questions 10x as long.

Post reply on HN