Live data from Hacker News

Hacker confirms access through infostealer infection [withdrawn]

hudsonrock.com

161–170 of 235 posts

Re: Hacker confirms access through infostealer infection [withdrawn]

#162

Earlier quoted context omitted.

I don't quite understand how Snowflake works. My understanding was that you had to grant storage access (e.g. S3) and compute access (e.g. EC2) from your account to Snowflake, which would then use said resources to perform queries that you issue from their hosted web UI. In that case it would mean stealing the Snowflake demo account of a SE should not expose your data unless you forgot to revoke their access to your…

No, Snowflake runs it's own storage and compute (on either AWS, GCP, or Azure depending on what you pick).

This was the case in ~2019 but are you sure this is still true? I think you can “bring your own account” with Snowflake, but I’m honestly not certain because their docs aren’t exactly clear about it…

Re: Hacker confirms access through infostealer infection [withdrawn]

#163
post #160

I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…

This is the description of one of Hudson Rock's main products, "Bayonet". "Imagine getting access to a lead-generation platform featuring hundreds of thousands of compromised companies around the world with active vulnerabilities that you can convert into customers." I've seen and dealt with a couple of these types of companies. It's a pretty sleazy tactic, and it's low skill/effort from a technical point of view as…

Doing some more digging, this is where the data is sourced

"Hudson Rock acquires and purchases compromised data directly from top-tier threat actors operating in closed circle hacking groups. What sets our data apart is its quality in providing high accessibility to hacker groups looking for potential targets, and the speed in which we make it available to clients compared to other threat intelligence companies. Our operational knowhow, and our boots-on-the-ground approach to cybercrime originates from the IDF's 8200 Cybercrime division, and its efforts to thwart nation-state adversaries and professional threat actors."

https://cavalier.hudsonrock.com/docs

This would imply that they are financially engaging with and supporting cyber criminals.

Re: Hacker confirms access through infostealer infection [withdrawn]

#164
post #161

In response to this incident, I just put together a Python CLI to help you monitor and take action against suspicious sessions in your account. https://github.com/Titan-Systems/titan-security-tools

Where are the blocked ip’s from? Also rapeflake? Hesitant to google that

Re: Hacker confirms access through infostealer infection [withdrawn]

#165
post #164
post #161

In response to this incident, I just put together a Python CLI to help you monitor and take action against suspicious sessions in your account. https://github.com/Titan-Systems/titan-security-tools

Where are the blocked ip’s from? Also rapeflake? Hesitant to google that

Snowflake published these rules earlier today - https://community.snowflake.com/s/article/Communication-ID-0...

Re: Hacker confirms access through infostealer infection [withdrawn]

#166

Earlier quoted context omitted.

I don't quite understand how Snowflake works. My understanding was that you had to grant storage access (e.g. S3) and compute access (e.g. EC2) from your account to Snowflake, which would then use said resources to perform queries that you issue from their hosted web UI. In that case it would mean stealing the Snowflake demo account of a SE should not expose your data unless you forgot to revoke their access to your…

No, Snowflake runs it's own storage and compute (on either AWS, GCP, or Azure depending on what you pick).

You can definitely bring your own storage (e.g. store your data in your own s3 buckets and integrate it with snowflake) using storage integrations and external tables.

See https://docs.snowflake.com/en/user-guide/data-load-s3-config...

Personally believe this is the right approach as the data resides in a location fully under the company's control. You could ditch snowflake and the data still resides in your s3 buckets for reuse with a another platform (just remove the iam permissions for snowflake).

Re: Hacker confirms access through infostealer infection [withdrawn]

#167
post #160

I don't work for Snowflake but I spend a lot of time working with them and their SE organisation. When working and building demos with clients, SEs create demonstration environments on the same $400 Snowflake demo accounts anyone can. To build demos the client would grant access to that SE. The SE would take some of the data to the demo environment and then work on it. This is further confirmed by the name of the env…

This is the description of one of Hudson Rock's main products, "Bayonet". "Imagine getting access to a lead-generation platform featuring hundreds of thousands of compromised companies around the world with active vulnerabilities that you can convert into customers." I've seen and dealt with a couple of these types of companies. It's a pretty sleazy tactic, and it's low skill/effort from a technical point of view as…

That screenshot where the attacker agrees that buying their services would help makes me have a very strong suspicion this attack is either faked, sponsored by or in some way Hudson Rock is in cahoots with the attackers. That screenshot is a pure 100% advertisement manufactured by Hudson Rock one way or another.

As they usually say.. I'd check whoever is running Hudson Rock's hard drive.

Re: Hacker confirms access through infostealer infection [withdrawn]

#168
post #167
post #160

Earlier quoted context omitted.

This is the description of one of Hudson Rock's main products, "Bayonet". "Imagine getting access to a lead-generation platform featuring hundreds of thousands of compromised companies around the world with active vulnerabilities that you can convert into customers." I've seen and dealt with a couple of these types of companies. It's a pretty sleazy tactic, and it's low skill/effort from a technical point of view as…

That screenshot where the attacker agrees that buying their services would help makes me have a very strong suspicion this attack is either faked, sponsored by or in some way Hudson Rock is in cahoots with the attackers. That screenshot is a pure 100% advertisement manufactured by Hudson Rock one way or another. As they usually say.. I'd check whoever is running Hudson Rock's hard drive.

[deleted]

Re: Hacker confirms access through infostealer infection [withdrawn]

#170
The practice of how Snowflake team uses customer data and builds/helps them and their access is not expired is still on Snowflake; such access should be temporary in nature, tied to an active ticket upon its closure to auto expire. The fact that Snowflake has managed to attain (and/or keep?) their FedRamp High certification despite this, is a separate story for some investigative journalists (not just for the label but also to look into what public sector data might be at risk or already compromised...)
Post reply on HN