Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

201–210 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#201
More and more companies get compromised by a "highly sophisticated" actors.

And somehow, these companies immediately "know" that it was a nation-state actor. Same case here. There are only claims, but no facts, no evidence.

And lately, it's always "the russians" :) I'm just noticing the pattern.

Lastly, what I really can't understand is - how in the world these "highly sophisticated attackers" are so bad at covering their tracks. :)

Re: FireEye Shares Details of Recent Cyber Attack

#202
post #189

Earlier quoted context omitted.

The invoice will be PDF with an embedded XML blob containing the machine-readable data part, signed with a PDF signature: https://www.pdf-tools.com/pdf20/en/zugferd/ pdf.js lacks capabilities to extract the XML or verify signatures, so the usual way will be to use Acrobat Reader or the usual bunch of "industry-standard" invoice-processing crap that now suddenly has to deal with malicious input. The idea to do it diff…

Having implemented rudimentary ZUGFeRD support at $dayjob a few years ago (our main product is sending, receiving and validating invoices for energy companies in Germany), I don't see ZUGFeRD becoming relevant anytime soon. At least for b2b invoices, nothing has changed since the release of ZUGFeRD. They prefer sticking to EDI formats (many with some custom edge cases for their SAP monstrosities, e.g. putting the `-`…

Quite possible, yes. But the alternatives to zugferd look quite similar, due to requirements from the relevant laws: https://de.wikipedia.org/wiki/Elektronische_Rechnung translated excerpt: an electronic invoice must be [...] 3. human readable 4. origin of the invoice must be guaranteed (digital signature or internal controls) 5. integrity of the invoice must be guaranteed [...]

This means that while you might be able to use something other than PDF for the human-readable part, I don't think anything other than PDF will be used. All the other stuff (XML with embedded SVG or PNG, Word, plaintext) will have acceptance problems in one form or the other.

EDI is big business to big business, as evidenced by you mentioning SAP. There, you may be completely right, I don't know.

Re: FireEye Shares Details of Recent Cyber Attack

#203
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

The Mathew in accounting is why you have to fill out expense reports. Accounting used to not require them until they started getting fake invoices in the mail. This attack predates the internet.

Re: FireEye Shares Details of Recent Cyber Attack

#204

Earlier quoted context omitted.

Does Matthew in accounting need access to the same network as the engineering staff?

I can think of a few... - The CFO doesn't understand why we need separate server infrastructure (and the associated licensing and maintenance costs) for accounting and engineering. - Software vendors can't answer the most basic questions about how their software communicates to allow network ops to build reasonable access control lists for network segmentation. - The network gear doesn't have sufficient horsepower to…

The network gear doesn't have sufficient horsepower to do wire-speed stateful packet filtering because, apparently, that's still an exciting new idea in 2020, and we can't slow everybody's access down.

The problem with any defence based on filtering is that first you have to decide what to filter. In an enterprise-scale network, this is not an easy problem, despite the number of shiny and expensive tools available that are selling the hope that it is.

Individual departments have end-run IT by using "cloud" offerings that effectively bridge different segments of the network together at layer 7.

This might be the most challenging problem for modern IT security, perhaps along with BYOD. The software and equipment accessible by staff might no longer be fully controlled by the organisation. That changes the emphasis for IT security from "just" securing your own software and systems to also somehow securing your data against unauthorised transfer to other systems. And this is a hugely complicated problem with (at least) technical, legal and management dimensions.

Re: FireEye Shares Details of Recent Cyber Attack

#205

Earlier quoted context omitted.

We (as in the IT Sec industry including me) prefer to blame Matthew. Or my 80 year old mother for not installing the latest Adobe patches in real time. With 30 years of daily experience in this field, I am ashamed about how we fail Matthew & my mother in the sense that they can still not just enjoy the internet and open random emails without one of us blaming them for how stupid they are.

Do we somehow fail the dumb accountant or 80 year gma with cars because they can't just get in and drive without learning how to drive?

That analogy doesn't work in my opinion, because to even be allowed to drive, an extensive amount of training is required.

I think we need to start very early. There should be more mandatory comouter science and information security classes at schools because we are all confronted with these topics everyday.

Most people can work systems such as washing machines, vacuum cleaners and so on, the problems arise when the internet (or other forms of connectability) comes into the picture. But the reality is that most such systems will probably soon be connected in some way, so the challenge grows.

So I think it is very important that we push for more information/education instead of going into the direction of more locked down, closed off and proprietary systems because these can easily "not respect" the end user.

Re: FireEye Shares Details of Recent Cyber Attack

#206

Earlier quoted context omitted.

> Matthew in accounting that will open that invoice attachment so he can pay it. This is painfully accurate. A chain is really only as strong as its weakest link :/

We (as in the IT Sec industry including me) prefer to blame Matthew. Or my 80 year old mother for not installing the latest Adobe patches in real time. With 30 years of daily experience in this field, I am ashamed about how we fail Matthew & my mother in the sense that they can still not just enjoy the internet and open random emails without one of us blaming them for how stupid they are.

[deleted]

Re: FireEye Shares Details of Recent Cyber Attack

#207
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

Interesting that they don't even name the adversary.

Re: FireEye Shares Details of Recent Cyber Attack

#208
post #119

Earlier quoted context omitted.

...and a binary at all should not be able to be downloaded from the internet or pass through and email server. Additionally the only binary files running on any system should be known binaries. Least Privileged systems with tight change control don’t get hacked.

Senior leadership would take an incredibly dim view when this inevitably shuts down accounting and purchasing after they can't use their PDFs and other executable-code documents anymore.

I was the CISO for a major bank for 16 years...year two of my tenure we completed the Least Privilege model and ran without a hitch...to this day.

Re: FireEye Shares Details of Recent Cyber Attack

#209

Earlier quoted context omitted.

Do we somehow fail the dumb accountant or 80 year gma with cars because they can't just get in and drive without learning how to drive?

That analogy doesn't work in my opinion, because to even be allowed to drive, an extensive amount of training is required. I think we need to start very early. There should be more mandatory comouter science and information security classes at schools because we are all confronted with these topics everyday. Most people can work systems such as washing machines, vacuum cleaners and so on, the problems arise when the…

I disagree. Anyone with minor observation can get behind a wheel and drive. Will they do it well? No (same with a computer) Is it legal? No, but thats because we all decided that as a group. The danger is different, but I think it's still an interesting analogy.

I think we need to all realize that most people aren't cut out for computer science, per se, but most people are cut out to learn to responsibly use a computer.

Re: FireEye Shares Details of Recent Cyber Attack

#210
post #41

This demonstrates two major points that many people not familiar with security may not understand: The first is that anyone -- really, anyone -- can get hacked. I often joke with our CIO that security would be a lot easier if he just powered down our production infrastructure. Security is a game played in layers (often called "defense in depth"), but at the end of the day, it's almost impossible to prevent a breach w…

You missed the third major point that most people do not know which is that these attacks are not just possible, they are easy. Every single one of these articles always mentions "nation-state actors" to imply that only a nation-state with billions of dollars and thousands of people can pull off such a "sophisticated" "novel" attack. That is unequivocal garbage. I have never had a CISO (or any other high-level securi…

1M is a rounding error to almost any nation state regardless of size that would want to hack into systems. The internet has democratized everything, even hacking and disinformation. For a couple hundred million, an industrious nation state can sow discord in its largest and most powerful competitors while at the same time stealing all their IP. It's the Innovators Dilemma at the nation state level.
Post reply on HN