Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

141–150 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#141
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

Does Matthew in accounting need access to the same network as the engineering staff?

Pretty irrelevant. They can get money from Matthew over the phone or even snail mail without ever using a computer.

Re: FireEye Shares Details of Recent Cyber Attack

#142
post #74
post #69

Why build hacking tools when you can steal them? Or at least get an idea of what tools your target company was red teamed with.

Why spy on your own citizens when that makes them blackmail-able by foreign nation states? Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.

The cheapest, easiest way to spy on everyone is through always-on, always sensing, always transmitting devices they'll crawl over their own grandmothers to own, social networking services self-supporting via $bilion$ in advertising, and a payments system with item-level detail captured to the penny dating back decades.

Re: FireEye Shares Details of Recent Cyber Attack

#143
post #103

Is FireEye the kind of company that has a cache of 0days?

This is something I doubt. Zero-day exploits are the kind that software vendors have no awareness of and therefore have no fixes in place (think mimikatz). FireEye is the sort of company who, upon discovering one in the wild, would disclose it to the software vendor to protect their clients. NSA on the other hand has been proven to hoard zero-days--even from US companies.

I didn't realize mimikatz ever used an 0-day. I'd be interested to learn more about the vuln

Re: FireEye Shares Details of Recent Cyber Attack

#144
post #4

This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…

Also how do you validate an address has never been used in an attack?

Probably just a journalist's summary of "not on existing IOC lists".

Re: FireEye Shares Details of Recent Cyber Attack

#145
post #107

Earlier quoted context omitted.

Also fingerprints will only stop the lowest level of attackers. You can easily change binaries in a way the fingerprint is changed but the functionality remains the same. Reorder functions, add some garbage data, etc.

That makes sense. So given that the attacker is technically sophisticated in this case, what are the tangible benefits of publishing the fingerprints? I guess one benefit might be to push the development of new detection techniques to detect the underlying implementation of these tools.

Some of the fingerprints are easily gotten around by fudging the binaries a bit. Others, like snort rules, look at things like network traffic that might not always be so easily disguised.

Re: FireEye Shares Details of Recent Cyber Attack

#146
post #92

Earlier quoted context omitted.

This is a very peculiar thought experiment.

Indeed. It would, however, provide very strong evidence for most such claims. The primary problem with actually implementing it in general is the risk of getting unlucky if you have a very large payout. Say you claim $100,000,000,000. Even if it is an accurate assessment, somebody could randomly luck into a vulnerability that would normally actually take $100,000,000,000 to find and suddenly you are dead since it is…

> It would, however, provide very strong evidence

No it wouldn't, because--

> the risk of getting unlucky

-- oh, you do understand. Why are you proposing this again?

Re: FireEye Shares Details of Recent Cyber Attack

#147

From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?

Iran is pretty good, maybe North Korea too. Countries like Netherlands, Germany, France, UK and similar must have programs in place too.

Re: FireEye Shares Details of Recent Cyber Attack

#148
post #109

Earlier quoted context omitted.

> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.

presumably he opened a pdf with a zero-day from an untrusted source

and that untrusted source could look a lot like his superior's email (boss@c0mpany.com vs boss@company.com)

And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version of Adobe Acrobat with a zero day vulnerability that hasn't been discovered yet.

It could also be literally anything.

Re: FireEye Shares Details of Recent Cyber Attack

#149
post #136

Earlier quoted context omitted.

But only because someone plugged a USB drive into the centrifuge computers. If the networks were air gapped, it wouldn't be Matthew's fault. Someone who had access to the engineering network would need to screw up. Which is of course perfectly possible—engineers make mistakes too. (Furthermore, if they were hacked by a nation state... for all we know it really could have been done without any user action at all.)

Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.

It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.

Re: FireEye Shares Details of Recent Cyber Attack

#150
post #81

Earlier quoted context omitted.

> Seriously, the quickest, cheapest, easiest way to spy on someone in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part. No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that…

Intercepting an sms message for 2FA is also easy nowadays via sim cloning.

Had a customer with an ex who did this.

Not fun.

Post reply on HN