Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

221–230 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#221

Earlier quoted context omitted.

That analogy doesn't work in my opinion, because to even be allowed to drive, an extensive amount of training is required. I think we need to start very early. There should be more mandatory comouter science and information security classes at schools because we are all confronted with these topics everyday. Most people can work systems such as washing machines, vacuum cleaners and so on, the problems arise when the…

I disagree. Anyone with minor observation can get behind a wheel and drive. Will they do it well? No (same with a computer) Is it legal? No, but thats because we all decided that as a group. The danger is different, but I think it's still an interesting analogy. I think we need to all realize that most people aren't cut out for computer science, per se, but most people are cut out to learn to responsibly use a comput…

Well, put it this way. Let's say that most people is cut out to learn to responsibly use a computer; I don't disagree with this fact.

As a matter of fact though, the same people do _not_ use computers responsibly. What do you do, then? Metaphorically jail them?

There are lots of areas where as humans, it's easy to reach a "sufficient" level, _and_ the dangers of an insufficiency are well known. Punishments or strict measures just don't work.

Everybody knows that they can be sufficiently and with little effort fit, but especially, that unsufficient fitness leads to sicknesses and earlier death. In this sense, which punishment can be worse? Yet, this doesn't work.

Re: FireEye Shares Details of Recent Cyber Attack

#222
post #109

Earlier quoted context omitted.

> Matthew in accounting that will open that invoice attachment so he can pay it. Matthew in accounting shouldn't have permission to run an untrusted binary.

presumably he opened a pdf with a zero-day from an untrusted source

Presumably he opened an Office document containing macros. Macros are able to execute system commands and load malicious PowerShell code.

Executable files are blocked by pretty much all corporate e-mails systems. Zero-days for PDF viewers are rare. After all, most hacking attacks are things like ransomware campaigns, where everyone is a potential victim and phishing mails are sprayed all over the internet. A zero-day would be burnt pretty quickly.

However, many users legitimately need office macros and also need to open office documents to collaborate with contractors or customers. Many times, the phishing mail comes from a legitimate address because the other company has been compromised already.

The solution would be to only allow signed macros, but depending on the size of the organization, that can be costly.

Re: FireEye Shares Details of Recent Cyber Attack

#223

Earlier quoted context omitted.

Air gap is not the final word in security. Stuxnet got into the Iranian centrifuges despite an air gap.

But only because someone plugged a USB drive into the centrifuge computers. If the networks were air gapped, it wouldn't be Matthew's fault. Someone who had access to the engineering network would need to screw up. Which is of course perfectly possible—engineers make mistakes too. (Furthermore, if they were hacked by a nation state... for all we know it really could have been done without any user action at all.)

> But only because someone plugged a USB drive into the centrifuge computers.

Either that or one of the Siemens engineers who showed up at the plant's laptop was infected in anticipation of them showing up there to fix stuff.

Re: FireEye Shares Details of Recent Cyber Attack

#224

Earlier quoted context omitted.

presumably he opened a pdf with a zero-day from an untrusted source

and that untrusted source could look a lot like his superior's email (boss@c0mpany.com vs boss@company.com) And depending on the resources of the hacker, the email could be stylised just for him, talking about something important that's (perhaps something bad) happening now and the notBoss is telling him to check this months info, and kindly providing him with a pdf that Mathew hastily opens with his latest version o…

Yeah agreed, combining social engineering with technical exploits and you can get really good results. I almost fell into one trap myself one day: Basically I was having an argument with a service provider, and somehow I received an email talking about the same type of issue (just high level, without the minute details) with a link attached. I had to check it many times to make sure that it was a fraud email...

Re: FireEye Shares Details of Recent Cyber Attack

#225
post #105

Earlier quoted context omitted.

If I understand your comment correctly - even though the fingerprints are published, the attacker can still reverse eng the implementation from the tools and bypass antivirus systems at least in the near future?

Sure, but they could already reverse mimikatz; having another implementation from FireEye doesn't really help.

You don't need to reverse minikatz, it's open source.

Re: FireEye Shares Details of Recent Cyber Attack

#226

Earlier quoted context omitted.

Air gap is not the final word in security. Stuxnet got into the Iranian centrifuges despite an air gap.

If we only have a single example of their defeat in the last more than a decade , I'd say that's evidence they're a pretty good word. What other security features claim that performance?

I'd argue that many/most instances of the "dropped USB stick in parking lot" infiltration technique are also failings of airgapping as a total security measure.

Re: FireEye Shares Details of Recent Cyber Attack

#227

Earlier quoted context omitted.

That analogy doesn't work in my opinion, because to even be allowed to drive, an extensive amount of training is required. I think we need to start very early. There should be more mandatory comouter science and information security classes at schools because we are all confronted with these topics everyday. Most people can work systems such as washing machines, vacuum cleaners and so on, the problems arise when the…

I blame the way we design our computer systems. For some reason, every program a user runs on a desktop computer has full access to every file saved by every other program. And full network access, and a slew of other permissions. In seconds a single malicious program can make a right mess of things, or exfiltrate sensitive data. A ransomware attack hit a large aged care provider in Australia recently and encrypted t…

I'm sad to agree. Having watched my own family, and my older parents, it would absolutely be better for them if everything worked that way.

They don't understand the concept of files as separate from applications. They just don't. They understand the concept of sharing -- that seems to be intuitive enough -- but not of files as objects in themselves.

A system which works this way would, of course, be completely rage-inducing to myself.

Re: FireEye Shares Details of Recent Cyber Attack

#228
post #91

As a red teamer I want to clear up why we build "hacking tools" and why FireEye did nothing wrong here. For example take the tool mimikatz [1], which is publicly available and well known. It can dump stored passwords out of Windows memory. But if you download mimikatz and try to run it every single antivirus/endpoint protection solution will light up like a christmas tree. However, the underlying technique isn't bein…

Or on John Podesta?

Re: FireEye Shares Details of Recent Cyber Attack

#229
post #107

Earlier quoted context omitted.

If I understand your comment correctly - even though the fingerprints are published, the attacker can still reverse eng the implementation from the tools and bypass antivirus systems at least in the near future?

Also fingerprints will only stop the lowest level of attackers. You can easily change binaries in a way the fingerprint is changed but the functionality remains the same. Reorder functions, add some garbage data, etc.

Fingerprints are definitely not the only way to know if a binary has been tampered with.

Re: FireEye Shares Details of Recent Cyber Attack

#230
post #163

Earlier quoted context omitted.

Matthew in accounting should be given an ipad pro instead of a laptop or pc, with a glued in lightning cable that can only do power. ^ This is the solution I have been mulling if and when I am responsible for an org where security is kinda important. Sure, iOS is still hackable, but hopefully we put more hindrance steps between the attacker and the org, and move the exposure more to the cloud services (like box). Cur…

Matthew wouldn't want to work at your shit company then.

Who's this fucking Matthew and why is everyone talking about him? He must be the best heckin Accountanant ever
Post reply on HN