Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

91–100 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#91
As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here.

For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't being blocked - just the specific implementation. This is why we build our own tools: to demonstrate to defenders that while they are blocking a specific implementation they have not addressed the underlying vulnerability.

I do want to call out FireEye for doing an amazing job recovering from this situation. They did the responsible thing and released fingerprints [2] that could be used to detect every single one of their tools. They effectively burned their entire catalog and put them in to the class of "public" tools that are easily identified. I've browsed over the list of signatures and didn't see anything that popped out as giving a malicious attacker any advantage other than saving them work of building it themselves (of course I don't have access to look at the actual tools so YMMV).

Also, everyone gets hacked. No matter how good you are or how many cyber security engineers you have on staff... there is still Matthew in accounting that will open that invoice attachment so he can pay it.

1. https://github.com/gentilkiwi/mimikatz 2. https://github.com/fireeye/red_team_tool_countermeasures/tre...

Edit: To be clear I do work on an internal red team - we hack ourselves. I don't work for FireEye or a competitor.

Edit 2: Don't pick on Matthew. :)

Re: FireEye Shares Details of Recent Cyber Attack

#92
post #66

Earlier quoted context omitted.

Well they could pretty easily demonstrate that only a state actor could pull off an attack like this in an objective manner. If it takes state-level resources to breach their systems, then they can just announce and put out an open prize for anybody who can breach their systems that pays out less than state-level resources. If it actually takes state-level resources to breach their systems, but pays out less than tha…

This is a very peculiar thought experiment.

Indeed. It would, however, provide very strong evidence for most such claims. The primary problem with actually implementing it in general is the risk of getting unlucky if you have a very large payout. Say you claim $100,000,000,000. Even if it is an accurate assessment, somebody could randomly luck into a vulnerability that would normally actually take $100,000,000,000 to find and suddenly you are dead since it is highly unlikely you are one of the few companies that can actually survive such a payout. You could alleviate that to some degree with insurance in the middle range, but it is highly unlikely that would work at the very high payouts. Luckily, in this case, a payout of $100,000,000 is actually within FireEye's reach given their revenue and market cap. In fact, they lost more in market cap on this breach news than such a payout. So, if their claims are actually true, this is an entirely feasible and useful demonstration to run.

Personally, I think if they actually announced a $100,000,000 prize they would be breached within a week on the outside. At $100,000,000 people can burn dozens to hundreds of zero-days to be the first to get the payout and still come out ahead. Even at $10,000,000 I doubt they would last more than 1 month. At $10,000,000 the prize would be the most attractive bounty in the entire industry by a factor of 3-10x and people could still burn some zero-days and still come out ahead.

Re: FireEye Shares Details of Recent Cyber Attack

#94
post #71

If FireEye, ostensibly full of competent people, can be hacked, what hope does the government have for protecting access to legally mandated backdoors in encryption? The silver lining of these events is it shows how ridiculous mandating backdoors would be. It’s begging other nations to attack us.

>...what hope does the government have for protecting access to legally mandated backdoors in encryption?

None. Both the CIA and NSA have been hacked too. The only entity that should hold private keys should be the person or organization using those keys.

Re: FireEye Shares Details of Recent Cyber Attack

#95
post #86

>There is no evidence that FireEye’s hacking tools have been used or that client data was stolen Later in same article... >Beyond the tool theft, the hackers also appeared to be interested in a subset of FireEye customers: government agencies. ??? Which is it?

They could have seen evidence in logs that the hackers were searching for files that likely were associated with the government, but they didn't find any.

Re: FireEye Shares Details of Recent Cyber Attack

#96
post #71

If FireEye, ostensibly full of competent people, can be hacked, what hope does the government have for protecting access to legally mandated backdoors in encryption? The silver lining of these events is it shows how ridiculous mandating backdoors would be. It’s begging other nations to attack us.

I genuinely hope your point is not lost on the decision makers. The steady push towards the 'ease' of accessing w/e you want as long as it is by 'good guys' ignores this argument and quickly pivots to cp, aml, and terrorism ( basically whatever currently works ). It is genuinely maddening.

Re: FireEye Shares Details of Recent Cyber Attack

#97
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

> Matthew in accounting that will open that invoice attachment so he can pay it.

This is painfully accurate. A chain is really only as strong as its weakest link :/

Re: FireEye Shares Details of Recent Cyber Attack

#98

Does a story like this negativity impact FireEye's security credibility?

Not necessarily. Realistically, you can't stop a nation state attack if they want to get in. If it turns out that the breach was caused by default credentials being used on a public server, then it's a different story.

Re: FireEye Shares Details of Recent Cyber Attack

#99
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

> The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses

This was precisely my read of it as well. Exaggerated usage of superlatives coupled with no actual explanation suggests trumping up an adversary's capabilities to excuse one's own security lapses. Like claiming a highly sophisticated burglar broke into your home, while neglecting to mention you left a window open.

Re: FireEye Shares Details of Recent Cyber Attack

#100
post #84
post #78

> FireEye CEO Mandia wrote that none of the red team tools exploited so-called “zero-day vulnerabilities,” meaning the relevant flaws should already be public. Seems like a massive amount of energy to devote to stealing tools, that by and large, probably have public equivalents sitting around on GitHub.

It is. It's equally likely that the direct goal of this attack was simply to harm FireEye.

I wouldn't discount a bored teenager yet. And yes, I am serious (as there is no info on how the attack took place yet).
Post reply on HN