Earlier quoted context omitted.
I mean, FireEye has a pretty good reputation for attribution and investigation of nation state intrusions. This doesn't seem like the type of thing they would just make up. Bot saying we should take them 100% at their word, but investigating intrusions is their entire reason for existence
They have a reputation for making up salacious stories based on totally inconclusive, inadequate "evidence". No wonder they turned it up to 11 when it was themselves getting breached.
FireEye Shares Details of Recent Cyber Attack
161–170 of 251 posts
Re: FireEye Shares Details of Recent Cyber Attack
#162I found an XSS on FireEye's website when I was a pentester. Good times.. It took all night, too. Was worried it'd be the first gig I wasn't able to get a medium severity on. I'm not sure anything can protect against a targeted attack from a nation-state. It's tempting to think that you can. But the warfare is asymmetric; they have all the time in the world to become certain that they can breach your outer defenses. O…
Re: FireEye Shares Details of Recent Cyber Attack
#163Earlier quoted context omitted.
> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.
Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…
Re: FireEye Shares Details of Recent Cyber Attack
#164Earlier quoted context omitted.
Likely you want to transfer data from an airgapped computer and back. So you need some way of transferring it.
It’s not obvious to me why engineering and accounting should need to transfer any data and back forth beyond basic email communications.
Re: FireEye Shares Details of Recent Cyber Attack
#165This part of the story is intriguing: > In the FireEye attack, the hackers went to extraordinary lengths to avoid being seen. They created several thousand internet protocol addresses — many inside the United States — that had never before been used in attacks. By using those addresses to stage their attack, it allowed the hackers to better conceal their whereabouts. What does it mean to "create an internet protocol…
The reporter meant 'used'. I have never heard the use of 'created' and if there is a meaning to that that I don't know about it's not widely used and should not have been used by the writer. The 'many inside the US' is kind of laughable. I mean what would you do to pull this off use IP addresses in China or Russia just to draw attention? I mean if you want to pull off a burglary in a residential neighborhood you don'…
Re: FireEye Shares Details of Recent Cyber Attack
#166Earlier quoted context omitted.
It is. It's equally likely that the direct goal of this attack was simply to harm FireEye.
I wouldn't discount a bored teenager yet. And yes, I am serious (as there is no info on how the attack took place yet).
Re: FireEye Shares Details of Recent Cyber Attack
#167Is anyone getting the sense that there are a lot of weird comments in this thread? Why are there so many comments doubting the idea that FireEye could have been hacked by a nation state actor? It's just really weird that so many people are saying similar things without directly contributing. Not to be paranoid, bit it's the type of behaviour I would expect from a nation state trying to place doubt in the narrative th…
Re: FireEye Shares Details of Recent Cyber Attack
#168Earlier quoted context omitted.
I wouldn't discount a bored teenager yet. And yes, I am serious (as there is no info on how the attack took place yet).
Yeah, no. People say this every time an attack is attributed to a state-level adversary, and while attribution is imperfect, it's not based on the idea that you have to be GRU to write an exploit. There's much more that goes into it; attribution specialists collect and catalog indicators of compromise, like the C&C servers and protocols people are using, many of which are not widely known.
Besides that, I care little about "attribution specialists" and what they say (sorry if anybody is in the audience :p). Evidence can be faked, it's all bits and bytes in the end (and some server locations, usually rented boxes) and things have been misattributed constantly in the past and will be in the future. I think the most you can infer is the general sophistication of the attackers and their resources, but that doesn't require an "attribution specialist". Attributing it to some specific nation state is guess work at best based on mistakes they made in their camouflage (if those mistakes aren't a deliberate or accidental red herring; e.g. [1]). And such "It was China/Russia/North Korea/underpants gnomes" claims are made by people claiming to be "attribution specialists" all the time. It's extremely rare that there is compelling evidence to supporting such attributions.
So if FireEye provided evidence or at least a reasonably detailed post mortem backing their claim of a sophisticated attack, then I'd probably believe them on that. If they made claims about a particular nation state (and so far they did not, as far as I can tell) then I would find that a dubious claim to make.
[1] https://theintercept.com/2017/03/08/wikileaks-files-show-the...
Re: FireEye Shares Details of Recent Cyber Attack
#169Earlier quoted context omitted.
> Matthew in accounting that will open that invoice attachment so he can pay it. This is painfully accurate. A chain is really only as strong as its weakest link :/
The invoice should be a PDF interpreted by pdf.js inside a sandboxed browser. Even better is that the company should have its own internal ordering system.
This always becomes a war where the seller wants you to send orders 1 way, and the buyer wants to send all orders another way.
Re: FireEye Shares Details of Recent Cyber Attack
#170Earlier quoted context omitted.
Yeah, no. People say this every time an attack is attributed to a state-level adversary, and while attribution is imperfect, it's not based on the idea that you have to be GRU to write an exploit. There's much more that goes into it; attribution specialists collect and catalog indicators of compromise, like the C&C servers and protocols people are using, many of which are not widely known.
But nothing is known, we have to believe a company trying to master a PR shitshow right now, saying that the attackers were extremely sophisticated. Maybe it was, maybe they are "inflating" the sophistication of the attack to avoid looking bad. Besides that, I care little about "attribution specialists" and what they say (sorry if anybody is in the audience :p). Evidence can be faked, it's all bits and bytes in the e…
You're probably never going to get evidence that will satisfy a message board.
The Wikileaks post you cited repeats the fallacy I mentioned earlier --- the idea that analysts are simply attributing exploit code. I think if you stop and think about it, you can probably rattle off a number of things besides exploits that a single attacker group will share in common across its attacks.
To fake the evidence we're discussing, you have to know what it looks like. A bored teenager doesn't.
I think it's unlikely that you can derive the entire practice of attribution axiomatically from your own intuitions about how attacks work, unless you've had some real exposure to IR and forensics as a practitioner.