Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

31–40 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#31
post #29

Huge target on their back no matter what. Like those movies where the tough guy is tested when he gets to prison. This is where it does not pay to be a public company. If they weren't a public company they wouldn't have to disclose this or acknowledge it and there most likely would not be a credibility damaging story which is easy to find. Sure the story could have gotten out but it would not be easy findable and wou…

> Why say that? Why not just say you were attacked and going to try and determine why and make any changes

Because they would be out of business tomorrow if they say they think it was a 13 year old from Ohio just fooling around on a Sunday.

This is FireEye marketing itself for the F500 by selling fear of an invisible adversary with unlimited resources that already deliver innovative black hat capabilities.

Re: FireEye Shares Details of Recent Cyber Attack

#32
post #4

This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…

The reporter meant 'used'. I have never heard the use of 'created' and if there is a meaning to that that I don't know about it's not widely used and should not have been used by the writer.

The 'many inside the US' is kind of laughable. I mean what would you do to pull this off use IP addresses in China or Russia just to draw attention?

I mean if you want to pull off a burglary in a residential neighborhood you don't drive in with an auto that draws attention you go with an auto that looks like many others that have been seen before and isn't noticed.

Re: FireEye Shares Details of Recent Cyber Attack

#33

what does "None of the tools contain zero-day exploits" exactly mean? Does the tools contain knows zero-days but not non public zero days?

Doesn't being known preclude them from being zero days by definition?

In the 'zero-day' and related terminology the days start counting from the time when a fix is available. It refers to how much time a defender has had to fix their systems, a zero-day implying that even the most prudent defender could not have prevented the attack; and a day-1 (or day-x) attack implying that the defender might have closed the vulnerability if they had been sufficiently fast in monitoring for the existence of the problem and fixing their systems.

So there certainly could be zero-day exploits for vulnerabilities that are known but not yet fixable, perhaps because the vulnerability did not seem easily exploitable and thus not urgent to the vendor.

Re: FireEye Shares Details of Recent Cyber Attack

#34
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

Seems like they are seeking attention more than anything.

Re: FireEye Shares Details of Recent Cyber Attack

#35
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

I mean, FireEye has a pretty good reputation for attribution and investigation of nation state intrusions. This doesn't seem like the type of thing they would just make up. Bot saying we should take them 100% at their word, but investigating intrusions is their entire reason for existence

Re: FireEye Shares Details of Recent Cyber Attack

#36
post #34
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

Seems like they are seeking attention more than anything.

They are seeking attention by saying they got hacked, when their entire reason for existence is to defend networks?

Re: FireEye Shares Details of Recent Cyber Attack

#38
post #36
post #34

Earlier quoted context omitted.

Seems like they are seeking attention more than anything.

They are seeking attention by saying they got hacked, when their entire reason for existence is to defend networks?

It reads like a brochure written by a marketing department, "top-tier offensive capabilities... world-class... operated clandestinely... They used a novel combination of techniques not witnessed by us or our partners in the past... nation-state cyber-espionage".

It's way over-the-top.

Re: FireEye Shares Details of Recent Cyber Attack

#39
post #30
post #20

I wonder if the attackers could use what they stole to impersonate FireEye. As in, some org thinks they're contracted/working with FireEye, but they're actually working with this nation state doing intelligence against the org.

Why impersonate Fireeye even? Just start a legitimate company, gain customers and then use that as a basis to gather what you need. The employees wouldn't know this they'd think they are working for a legitimate company. The bad actors who set it up would just have access to whatever they needed to do what they needed to do. This would take years of work to pull off but could be done.

An APT group was doing this up until ~2016 under the name 'Combi Security'

https://nakedsecurity.sophos.com/2019/09/13/fin7-sysadmin-pl...

Post reply on HN