I am pretty sure I was hit with this. I had some REALLY weird redirects coming from text msgs. NOT from Egypt. Maybe paranoid. Offline / on new Linux devices for now.
0-days exploited by commercial surveillance vendor in Egypt
161–170 of 254 posts
Re: 0-days exploited by commercial surveillance vendor in Egypt
#162Earlier quoted context omitted.
Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me
I'm interested at your suggestion that Digicert et al are doing some sort of "keeping the streets safe" checking. I have zero experience of using them but I thought all they were doing was confirming the applicant represented some entity that matched the domain name. If I manage to get a company registered called G00gle, buy a corresponding domain and then send them my $500 are you suggesting they're going to refuse…
Source: Have to be that human from time to time
Re: 0-days exploited by commercial surveillance vendor in Egypt
#163It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…
Re: 0-days exploited by commercial surveillance vendor in Egypt
#164Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.
Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me
OTOH, Certificate Transparency Logs will give the game away, so there's that.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#165It's good to get some more info, but it is a little disconcerting that they only mention patching Chrome. What was the sandbox escape on Android? Even if you had code execution inside the Chrome process on Android, that shouldn't be enough to enable persistence, so clearly there's another vulnerability. Also in this case the attack vector was MITM of http and one time links as it was a targeted campaign, but it feels…
There are millions of android devices out there that have been abandoned by their manufacturers, so they might be omitting those details because the flaw hasn't yet been patched (and likely never will be.)
Re: 0-days exploited by commercial surveillance vendor in Egypt
#166Earlier quoted context omitted.
Yes, that doesn't happen. If a legislator agrees with you, you want to keep them in the legislature, not retiring into industry. Also, campaign donations are capped at like $5000 and most of what people think is corruption is them recklessly misreading the donation reports. Similarly, it's Bernie and similar people who get the most donations these days because of ActBlue, and it doesn't help them win elections, becau…
> Yes, that doesn't happen. I invested 15 seconds into a search query. Former Members Dick Armey. Tom Daschle. Tom Foley. Trent Lott. Once, these politicos ranked among Congress' most powerful members. Today, they share another distinction: They're lobbyists (or "senior advisors" performing very similar work). And they're hardly alone. Dozens of former members of Congress now receive handsome compensation from corpor…
Those people are a combination of 1. really old and 2. lost an election. You can't keep people around forever, even if you might want to. (It also implies they're effective as lobbyists, which I don't think is necessarily true.)
> This falsely implies no donor can get more than $5k into any one campaign fund.
Those other things aren't the campaign fund, they're largely separate funds running separate campaigns and not controlled by the candidate. So they can't be used to directly pay the candidate.
Also, as I said, 1. money doesn't actually win elections and 2. if it did, it's Bernie and fellow non-corporate-Dem candidates who'd actually be winning, because small donor fundraising is more effective than this stuff is.
There are some straight up bribery scandals, but I think Bob Menendez is an exception that proves the rule and is going to lose his office based on his literal piles of gold bars bribery.
It is, however, actually the case with SCOTUS judges that they straight up take bribes and nobody can stop them.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#167Earlier quoted context omitted.
You probably can't forge a certificate like that without all the browsers noticing and dropping your CA; there's protections against it.
If you're a nation you can just force the CAs that are in your jurisdiction to do whatever you want, or sneak in in various ways so they won't know. If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#168Earlier quoted context omitted.
You probably can't forge a certificate like that without all the browsers noticing and dropping your CA; there's protections against it.
If you're a nation you can just force the CAs that are in your jurisdiction to do whatever you want, or sneak in in various ways so they won't know. If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#169Earlier quoted context omitted.
If you're a nation you can just force the CAs that are in your jurisdiction to do whatever you want, or sneak in in various ways so they won't know. If you use the MITM judiciously, it's very likely that nobody will notice, or that those that notice can be compelled not to say anything.
The browser will notice that it's being given a cert that isn't in the CA transparency log + other hardcoded known certs for top sites and will phone home about it.
Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log, though that's almost certainly harder for most nations and CAs.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#170Earlier quoted context omitted.
I'm interested at your suggestion that Digicert et al are doing some sort of "keeping the streets safe" checking. I have zero experience of using them but I thought all they were doing was confirming the applicant represented some entity that matched the domain name. If I manage to get a company registered called G00gle, buy a corresponding domain and then send them my $500 are you suggesting they're going to refuse…
As far as I can tell, the verification that DigiCert performs is 1. the company exists in various Business listings 2. the phone number listed in whois has a human behind it and the human confirms the phone number belogs to the company. Source: Have to be that human from time to time
If you get the normal DV cert they don't provide any more verification than Letsencrypt.
And since browsers have moved away from indicating OV/EV certs to end users, not many organizations are paying for those anymore.