Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

101–110 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#101
post #86

>There is no evidence that FireEye’s hacking tools have been used or that client data was stolen Later in same article... >Beyond the tool theft, the hackers also appeared to be interested in a subset of FireEye customers: government agencies. ??? Which is it?

Interest != Used or Stolen Client Data.

"no evidence" != "didn't happen", either, tho, especially if the attackers really were that capable as they claim,

Re: FireEye Shares Details of Recent Cyber Attack

#102
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

If I understand your comment correctly - even though the fingerprints are published, the attacker can still reverse eng the implementation from the tools and bypass antivirus systems at least in the near future?

Re: FireEye Shares Details of Recent Cyber Attack

#104
post #53

Earlier quoted context omitted.

>I'm not sure anything can protect against a targeted attack from a nation-state. hardware airgap can go a long way

Honestly, system user education/awareness goes even further. Iran nuclear facilities used an airgap but it was social engineering that was the weakest attack vector for Stuxnet to exploit. Same with the South Korean Winter Olympics; a phishing email with a macro embedded Word doc got them in there. A great book on Russian, state-backed hacking group was by a senior Wired writer, Andy Greenberg, called "Sandworm" [0]…

[deleted]

Re: FireEye Shares Details of Recent Cyber Attack

#105
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

If I understand your comment correctly - even though the fingerprints are published, the attacker can still reverse eng the implementation from the tools and bypass antivirus systems at least in the near future?

Sure, but they could already reverse mimikatz; having another implementation from FireEye doesn't really help.

Re: FireEye Shares Details of Recent Cyber Attack

#106
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

Whats your opinion of open source tools and distributions of them (like Kali) in this space and the tradeoff between open sourcing your red team tools vs reimplementing tools that are already out there.

Re: FireEye Shares Details of Recent Cyber Attack

#107
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

If I understand your comment correctly - even though the fingerprints are published, the attacker can still reverse eng the implementation from the tools and bypass antivirus systems at least in the near future?

Also fingerprints will only stop the lowest level of attackers. You can easily change binaries in a way the fingerprint is changed but the functionality remains the same. Reorder functions, add some garbage data, etc.

Re: FireEye Shares Details of Recent Cyber Attack

#108

From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?

Very few companies will publicly attribute attacks to a specific government - both because it is hard and because of potential political blowback.

I would confidently say that the top 50 countries by GDP have a solid offensive capability. Some, like Japan, have very specific interests that don't align with what makes the news.

At some point you start getting in to the territory of Hacking Team, NSO Group, Gamma, VASTech, etc. Effectively combining the resources of many smaller governments in to a for-hire enterprise that can provide near-nation-state capabilities.

Here is a list of well known attributions of groups to get you started: https://docs.google.com/spreadsheets/u/1/d/1H9_xaxQHpWaa4O_S...

Re: FireEye Shares Details of Recent Cyber Attack

#109
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

> Matthew in accounting that will open that invoice attachment so he can pay it.

Matthew in accounting shouldn't have permission to run an untrusted binary.

Re: FireEye Shares Details of Recent Cyber Attack

#110
post #81
post #74

Earlier quoted context omitted.

Why spy on your own citizens when that makes them blackmail-able by foreign nation states? Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.

> Seriously, the quickest, cheapest, easiest way to spy on someone in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part. No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that…

You can get a database of everyone's metadata communications by sending them a phishing message? Certainly, I don't keep even all my information on my computer, or even a single phone, and I think phishing _everyone_ is harder than you're making out. On the other hand it's all sitting right there at the NSA et al. Your other attacks are similarly focused on individuals, although the credit and health agencies are prime surfaces for data mining, you're not going to get the metadata/connectivity needed.

I'm interested to know what you're proposing, but I suspect you simply misunderstood what I meant, and perhaps what your (and everyone else's) file at the TLAs looks like. It's a mighty plump target, and not comparably secure.

Post reply on HN