Live data from Hacker News

“NASDAQ is owned.” Five men charged in largest financial hack ever

arstechnica.com

111–120 of 143 posts

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#111

Amazing people are still ignorant of how to properly code a web application. Not to mention all the companies that likely still store passwords using a reversible algorithm and fail to separate and encrypt credit card information. What is this, 1994?

It's not that people don't know how to properly code a web application. It's that coding a web application with a strong and secure perimeter is more expensive, more effort, and difficult to QA (the perimeter) than building one without.

"Ship it."

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#112
post #58

Earlier quoted context omitted.

Speaking as bulgarian, my guess is that the eastern block countries were limited to the amount of software/hardware that could be sold in the countries due to Cocom ( http://en.wikipedia.org/wiki/CoCom ) and this possibly brought a whole generation of people that became good at reverse engineering, but most likely also at whole culture that thinks it's okay to reverse engineer almost everything... One of my friend's…

> "communism" (there was never such thing) In college I wrote a major research paper on market-style exchanges on the factory floors of Eastern Europe, with the underlying point that you can never really purge all market forces, that "capitalism" is more descriptive than normative. When I think back on it, well, I'm mostly ashamed for talking out of my ass about what other people actually experienced. It'd be great t…

Possibly you understood what it was better than me, especially since you've researched it.

From my point, it was never communism - ahem the simple - produce as much as you can, take as much as you need

There was one difference - central planning - all prices were fixed and you can't find much variety in the store (2-3 types of bread, 2-3 types of feta cheese, etc.)

Another thing was the foreign currency - read about it here - http://en.wikipedia.org/wiki/Corecom

As a kid one of the best things were getting bananas/oranges for New Year, or getting some real dollars so you can buy kinder eggs/pezz/tobleron/etc from the Corecom stores (above). Although you might afford the money, there was no easy way to exchange them.

It was a 'meh' moment for me, when democracy came, and my favourite store (selling cake, soda drinks) start also selling kinder eggs - It was impossible for me to think that I can go and buy as much as I want with ... levas (our currency).

And as such they were no longer interesting :)

I had a happy childhood, maybe because I did not know anyone too rich, or too poor, and the choice was limited... okay maybe that was not the case... But looking at all old bulgarian kid movies, one can see kids roaming the streets without any danger (and it was so - It was normal for me to stroll around while I was 5 or 6 years old). This gets old, a a bit reddit-ish, and it's purely my experience and surely for other people it could've been totally different story.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#113
post #104

I'll get downvoted for this, but I think SQL admins should in some way be held accountable for successful injection attacks. Falling victim to this type of exploit which is as old as the hills should be inexcusable. How difficult is it to learn how a UNIX shell works, inside and out? For what these guys get paid and what they are tasked with securing, they should be experts on escaping and quoting and every possible…

Generally, the DBAs have very little role in knowing whether any part of their application is vulnerable to SQL injection, and on top of that they can't mitigate very well against it. They can do the basic things: don't use the root MySQL user, restrict privileges on each MySQL user, use AppArmor or SELinux to isolate the mysqld process, etc. This does prevent an attacker, in most cases, from instantly uploading a sh…

Question: Can/do they do "fuzzing" on their database applications? Has anyone built a fuzzer for this purpose that tries an assortment of possible vectors as well as random strings? I still do not understand why the injection vectors cannot be preempted to begin with. It seems to me as if the folks securing the database are unable to predict possible ways someone could exploit what their application considers "valid" queries. If so, why?

Also, I don't follow reddit, so I didn't know they say that.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#115
post #111

Amazing people are still ignorant of how to properly code a web application. Not to mention all the companies that likely still store passwords using a reversible algorithm and fail to separate and encrypt credit card information. What is this, 1994?

It's not that people don't know how to properly code a web application. It's that coding a web application with a strong and secure perimeter is more expensive, more effort, and difficult to QA (the perimeter) than building one without. "Ship it."

I love the "ship it" here. Deadlines kill security. When you're under the gun to finish something as a dev, the first thing to go is the security mindset. The next thing to go is the "beautiful code" mindset, which leads to even more security issues. The problem is that by definition projects that have a critical deadline will usually be used by thousands of people or handle very important information.

It's a weird issue of "I need it now because it's important" and "I need it working well because it's important". Good, fast, cheap. Pick two.

Thanks for supporting my confirmation bias.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#116
post #43

Is anyone aware of a) whether other security auditors or services could have identified these vulnerabilities and b) what it takes to sell to these exploited firms? My understanding of security is fairly small, but it seems to me that there's a market to be had here ... If the expertise exists to dramatically reduce exposure, it's a question of sales or ease of use. If the expertise doesn't exist yet, someone smart m…

There is a market here.

[deleted]

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#117
post #90
post #72

Earlier quoted context omitted.

Someone who does security work for me on the side (for about 12 years works now) manages a team that does this at a large consulting company. I can't remember exactly, but he told me what they bill him out for and it sounded like NY senior attorney level rates. He travels overseas regularly on longer term assignments. I told him he should go out on his own but he's not entrepreneurial. He also said that a few of the…

I think starting a security consultancy is a business idea that just might work.

I admit by the time I made it through this comment thread, I wasn't quite laughing out loud, but I was having a good chuckle.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#118
post #71
post #48

Earlier quoted context omitted.

> but all they really could do is incur losses for the customer. If they could inject "incorrect" trades, could they put themselves on the other side of those trades via normal means and so benefit from such losses?

Surely.

But how would this be noticeable from the regular fraud that occurs?

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#119
post #22

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

In Israel, military service is compulsory for all men when they are 18 years old. The best hackers in the country are detected and lured into cyberwarfare positions where they need to be the best cyber attackers in the world for 3 years. You bet that these guys are among the best in the world.

> for 3 years

Not exactly true. There are a few different computer groups, one of which requires only three years and it is nowhere near the level of sophistication of an average programmer (they are mostly responsible for the technological infrastructure of the army). The other programs require a degree beforehand (so they only go into the army at about 22) and then require 5 years of service. These are the people who create cool things. But let me say: even the things that they do are closer to things you can think about than what you would find in a sci-fi novel.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#120
post #113

Earlier quoted context omitted.

Generally, the DBAs have very little role in knowing whether any part of their application is vulnerable to SQL injection, and on top of that they can't mitigate very well against it. They can do the basic things: don't use the root MySQL user, restrict privileges on each MySQL user, use AppArmor or SELinux to isolate the mysqld process, etc. This does prevent an attacker, in most cases, from instantly uploading a sh…

Question: Can/do they do "fuzzing" on their database applications? Has anyone built a fuzzer for this purpose that tries an assortment of possible vectors as well as random strings? I still do not understand why the injection vectors cannot be preempted to begin with. It seems to me as if the folks securing the database are unable to predict possible ways someone could exploit what their application considers "valid"…

Yes, database fuzzers exist. (http://sqlmap.org)

To answer your second question, Standard Query Language is very, very complicated, and you would have to be a genius to make a proper input scrubber. That's why you are supposed to use things like parameterized queries and bypass the danger of sql injection entirely. However, security mistakes still happen, and you should code in such a way that database leaks are not catastrophic.

Post reply on HN