Live data from Hacker News

Anonymous speaks: the inside story of the HBGary hack

arstechnica.com

21–30 of 84 posts

Re: Anonymous speaks: the inside story of the HBGary hack

#21
post #12
post #7

Earlier quoted context omitted.

They homebrewed their own password system. the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system. Can someone switch on the tptacek bat-signal? thomas' security company also got hacked a couple years ago and had sensitive information plastered all over a mailing list. rumor was that it happened via their use of wordpress for their web…

> the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system. Doesn't that make them look even more amateurish and incompetent? They chose an insecure content management system and, most importantly, they didn't isolate it enough. So penetrating that resulted in a complete penetration of their site. If they were selling hand-made baskets,…

Just means they've never had experience being attacked before. Always offense, never defense. In their minds, they never considered someone would have a reason to go after THEM.

They specialize in thinking up new ways to attack OTHERS, using OTHER peoples' tools. It's a huge problem in DC. A bunch of people telling other people what to do, without little idea or experience how to do it themselves.

Re: Anonymous speaks: the inside story of the HBGary hack

#22

Wow. Did they do anything right? I can understand a typical organization making most of these mistakes, but a security firm?

I'm not pointing any fingers, but the security industry both on- and offline has long had problems with snake oil.

Re: Anonymous speaks: the inside story of the HBGary hack

#23
SQL injection and MD5... on a "security" company? In 2011?

I'm sorry but thats just egregious. Thats like being a bodyguard and not even putting a lock on your own house.

The rest of the attacks could have happened to anyone. We all know its best practice to use many different passwords but most don't because its more convenient to only have one or a few. And if the email is coming from the email address it should you could brain fart and give up the info without thinking.

But the first two parts of the attack should NOT have been possible for them to even pretend to call themselves a computer "security" firm in 2011

Re: Anonymous speaks: the inside story of the HBGary hack

#24

  HBGary used Google Apps for its e-mail services
So, this high flying super duper high tech hardcore company actually uses an external email provider for their (I suppose) super secret emails?

The more I learn about this incident the more Mr. Barr and HBGary look like a bunch of amateurish dolts that may give good power point presentations, but I for one sure wouldn't take my security business there.

Re: Anonymous speaks: the inside story of the HBGary hack

#25

HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.

Company? Hell, government, military, it goes on and on how many vulnerable networks are out there.

Re: Anonymous speaks: the inside story of the HBGary hack

#26
post #23

SQL injection and MD5... on a "security" company? In 2011? I'm sorry but thats just egregious. Thats like being a bodyguard and not even putting a lock on your own house. The rest of the attacks could have happened to anyone. We all know its best practice to use many different passwords but most don't because its more convenient to only have one or a few. And if the email is coming from the email address it should yo…

You are completely wrong to justify people using the same passwords in multiple places because it is convenient.

Re: Anonymous speaks: the inside story of the HBGary hack

#27
Computer security is obscenely asymmetric - an attacker only has to find one flaw, once, somewhere. A defender needs to constantly monitor, test, review isolate and basically never make any mistakes.

It is easy to look at almost any intrusion and attribute it to poor defenses. If HBGary didn't have a SQL injection, they'd have had a XSS vuln. Or a employee would get spearphished. Or an attacker at a local coffee shop would compromise a mobile client. Or a backup service would get compromised and unencrypted. Or a interviewee could plant a network listening device. Or the CEO's daughter could win a pre-owned iPhone. Or a secretary gives out a VPN login. And so on and so on.

Did HBGary suck worse than usual? Possibly - but consider Google china got hit by ie6+acrobat vulns, DOD lost hundreds of thousands of classified documents from an air gapped and physically controlled system to a private, Open BSD may have included side channel backdoors, Kaspersky lost their source code, PS3/iPhone/Xbox/HTC etc. are unable to secure their platforms.

The truth is, a motivated attacker will rarely fail. Anyone reading this would be unlikely to survive 24 hours of a coordinated attack whether it's done by 16 year olds, chinese university students, russian mafia, FBI or simply nerds that know how to google vulnerabilities.

Fighting back against a group like Anonymous provides the same asymmetric warfare problems as the US military experiences in fighting terrorists, including the inability to respond with similar tactics for legal reasons.

Bottom line is, almost any organization can be subject to this kind of embarrassment without warning.

Re: Anonymous speaks: the inside story of the HBGary hack

#28
post #12
post #7

Earlier quoted context omitted.

They homebrewed their own password system. the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system. Can someone switch on the tptacek bat-signal? thomas' security company also got hacked a couple years ago and had sensitive information plastered all over a mailing list. rumor was that it happened via their use of wordpress for their web…

> the story says hbgary hired an outside company to make this cms for them, which may explain the crappy security on that particular system. Doesn't that make them look even more amateurish and incompetent? They chose an insecure content management system and, most importantly, they didn't isolate it enough. So penetrating that resulted in a complete penetration of their site. If they were selling hand-made baskets,…

Doesn't that make them look even more amateurish and incompetent? They chose an insecure content management system and, most importantly, they didn't isolate it enough.

No more than google choosing a linux kernel with a privilege escalation bug for Android, anyone using OS X in 2009 while a remote jdk bug sat open for 6 months, anyone using windows+ie in dec '10 or jan '11.

Unless you can explain how to only buy software that will never have any vulnerabilities.

Re: Anonymous speaks: the inside story of the HBGary hack

#29
post #9

HBGary isn't anywhere near the only company to have security holes like this open. It's just worse because they're a security company and they happened to piss off Anonymous. Getting employees or users not to reuse passwords is probably the hardest thing to do. Also, Ars' coverage of this story has been great.

One point in favor of requiring ssh keys for external access is that the users don't get to blow it on passwords. Though it does require sysadmin staff who are willing to walk users through the process of creating the keys --- and stubborn enough to explain that this is the procedure until following it becomes the path of least resistance.

Changing passwords is a lot easier than changing keys.

Re: Anonymous speaks: the inside story of the HBGary hack

#30
One: the root password to the machine running Greg's rootkit.com site was either "88j4bb3rw0cky88" or "88Scr3am3r88".

There must be more to it than this. If you know it's one of two passwords, why bother asking - couldn't you just try both? (In retrospect, maybe it was to give Jussi confidence that he was communicating with the real Greg? [Who else, after all, would know the root passwords?])

Post reply on HN