As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…
Does Matthew in accounting need access to the same network as the engineering staff?
FireEye Shares Details of Recent Cyber Attack
141–150 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#142Why build hacking tools when you can steal them? Or at least get an idea of what tools your target company was red teamed with.
Why spy on your own citizens when that makes them blackmail-able by foreign nation states? Seriously, the quickest, cheapest, easiest way to spy on someone (edit= everyone) in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part.
Re: FireEye Shares Details of Recent Cyber Attack
#143Is FireEye the kind of company that has a cache of 0days?
This is something I doubt. Zero-day exploits are the kind that software vendors have no awareness of and therefore have no fixes in place (think mimikatz). FireEye is the sort of company who, upon discovering one in the wild, would disclose it to the software vendor to protect their clients. NSA on the other hand has been proven to hoard zero-days--even from US companies.
Re: FireEye Shares Details of Recent Cyber Attack
#144This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…
Also how do you validate an address has never been used in an attack?
Re: FireEye Shares Details of Recent Cyber Attack
#145Earlier quoted context omitted.
Also fingerprints will only stop the lowest level of attackers. You can easily change binaries in a way the fingerprint is changed but the functionality remains the same. Reorder functions, add some garbage data, etc.
That makes sense. So given that the attacker is technically sophisticated in this case, what are the tangible benefits of publishing the fingerprints? I guess one benefit might be to push the development of new detection techniques to detect the underlying implementation of these tools.
Re: FireEye Shares Details of Recent Cyber Attack
#146Earlier quoted context omitted.
This is a very peculiar thought experiment.
Indeed. It would, however, provide very strong evidence for most such claims. The primary problem with actually implementing it in general is the risk of getting unlucky if you have a very large payout. Say you claim $100,000,000,000. Even if it is an accurate assessment, somebody could randomly luck into a vulnerability that would normally actually take $100,000,000,000 to find and suddenly you are dead since it is…
No it wouldn't, because--
> the risk of getting unlucky
-- oh, you do understand. Why are you proposing this again?
Re: FireEye Shares Details of Recent Cyber Attack
#147From their official blog post: > Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities. I wonder what nations possess “top-tier offensive capabilities” today. USA, China, Russia, Israel come to mind. Who else? Is there a list or metric to measure a nation’s cyber attack capabilities?
Re: FireEye Shares Details of Recent Cyber Attack
#148Earlier quoted context omitted.
> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.
presumably he opened a pdf with a zero-day from an untrusted source
And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version of Adobe Acrobat with a zero day vulnerability that hasn't been discovered yet.
It could also be literally anything.
Re: FireEye Shares Details of Recent Cyber Attack
#149Earlier quoted context omitted.
But only because someone plugged a USB drive into the centrifuge computers. If the networks were air gapped, it wouldn't be Matthew's fault. Someone who had access to the engineering network would need to screw up. Which is of course perfectly possible—engineers make mistakes too. (Furthermore, if they were hacked by a nation state... for all we know it really could have been done without any user action at all.)
Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.
Re: FireEye Shares Details of Recent Cyber Attack
#150Earlier quoted context omitted.
> Seriously, the quickest, cheapest, easiest way to spy on someone in the US (or any 5 eyes) is through our own "security" agencies, but I'm going to go with stupidity rather than malice on the NSA's part. No. The quickest and easiest way is probably to send them a phishing message, the next easiest is probably figuring some of their password recovery answers using dossiers compiled by data brokers, maybe after that…
Intercepting an sms message for 2FA is also easy nowadays via sim cloning.
Not fun.