Live data from Hacker News

“NASDAQ is owned.” Five men charged in largest financial hack ever

arstechnica.com

41–50 of 143 posts

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#41
Is anyone aware of a) whether other security auditors or services could have identified these vulnerabilities and b) what it takes to sell to these exploited firms?

My understanding of security is fairly small, but it seems to me that there's a market to be had here ... If the expertise exists to dramatically reduce exposure, it's a question of sales or ease of use. If the expertise doesn't exist yet, someone smart might make a lot of money.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#42

Doesn't NASDAQ have some responsibility for this hack? Doesn't NASDAQ have serious security reputation issues now?

Blaming the victim? Nice.

If indeed it was a basic SQLi attack and NASDAQ failed to prevent it, then to some degree, yes, they're responsible. As a high-value target it's incumbent on them to secure their systems.

Here on HN we often say "security through obscurity is no security." Relying on the fact that it is "illegal" for someone to hack your system to prevent them from doing so is similarly flawed logic.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#43

Is anyone aware of a) whether other security auditors or services could have identified these vulnerabilities and b) what it takes to sell to these exploited firms? My understanding of security is fairly small, but it seems to me that there's a market to be had here ... If the expertise exists to dramatically reduce exposure, it's a question of sales or ease of use. If the expertise doesn't exist yet, someone smart m…

There is a market here.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#45
post #22

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

In Israel, military service is compulsory for all men when they are 18 years old. The best hackers in the country are detected and lured into cyberwarfare positions where they need to be the best cyber attackers in the world for 3 years. You bet that these guys are among the best in the world.

Interesting, I remember reading that the hacker (jsz) who helped Kevin Mitnick back in the day with the IP spoofing attack against Shimomura's computer was from Israel as well.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#46
post #22

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

In Israel, military service is compulsory for all men when they are 18 years old. The best hackers in the country are detected and lured into cyberwarfare positions where they need to be the best cyber attackers in the world for 3 years. You bet that these guys are among the best in the world.

[deleted]

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#47

How would one even go about doing this? Do you just keep trying difference ssh key values? I never understood how people can just magically "gain access" to servers.

in this case it was supposedly done using SQL injections: http://en.wikipedia.org/wiki/SQL_injection#Incorrectly_filte...

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#48
post #2

I've seen this story (NASDAQ being hacked) reported in a couple of places, but it isn't clear to me what damage was done. It's not really possible for them to have messed with the actual trading without anyone noticing. Everyone connecting to an exchange is reconciling the orders they send in against the trade confirmations they receive. You basically design your technology assuming the exchange is going to fuck some…

The matching engine and the ring of servers around it are not accessible via internet. You can only connect to them if you have a server collocated in Carteret, and even then the NASDAQ machines only expose the ports relevant to order entry and feed data. They could have hacked a customer (say, citigroup) and entered that way, but all they really could do is incur losses for the customer.

> but all they really could do is incur losses for the customer.

If they could inject "incorrect" trades, could they put themselves on the other side of those trades via normal means and so benefit from such losses?

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#50
post #17

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

They can't easily get jobs that pay them well, the way most programmers in the West can. People really good at security in the US just get a job making a great salary.

Its also more dangerous in the US. Since the majority of major web apps are hosted in the US, if you're in the US it is easy for the app's owners to go after you legally. It gets much more complicated if you're in another country. For example, if weev had been in eastern Europe, it would make it much more difficult for ATT to go after him.
Post reply on HN