Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

41–50 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#41
post #26
post #15

Wonder what shenanigans the USB device is up to. A bootable drive for flashing backdoored bios/hdd firmware or keylogging? Snapshotting the HDDs? 0day'ing the kernel USB stack?

Probably just a USB stick with Second Look or a similar tool on it. Very first thing you do is dump the running memory on the system. Then you pull the drives, plug them into a write blocker, then image the drives. Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.

I'm trying to understand that too.

A Linux server (I'm guessing for no particular reason it's a Linux server) would have no reason to automount a USB stick, and its console would be at a login screen (so a HID device would gain nothing).

So my guess for the intrusion scenario would be a "cold boot" attack: plug a specially prepared USB stick, open the server case, short the reset pins in the motherboard (AFAIK, modern motherboards still have the pins for the reset button, even though modern cases don't have a reset button anymore), and tell the BIOS to boot from the USB stick. The USB stick then dumps the memory, which still has data from the previously running system (since it was an unclean shutdown), with some luck including cryptographic keys.

That scenario would also explain why he briefly saw the server back on the KVM: they might have been using the KVM to interact with the BIOS.

The defense against such a scenario would be to aggressively shut down all processes and kexec to a memory-wiping kernel as soon as any unexpected device (not only USB, but also PCI and others) is seen, or if the case is opened. Also make it send an alert message through the network with the details whenever it's triggered, to be able to diagnose why the server shut down without warning.

But there's another possible scenario: the "bureaucratic confusion" scenario. It's possible that the systems at his hosting location got confused, and thought he was no longer a client. The apparent intrusion would be a techie repurposing the servers for another client.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#42
post #12

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

Must admit I'm slightly amused that this is even being considered as a plausible theory. They're busy executing elderly with AK47s...thats very far away from physically cracking open servers in a western data center and inserting USB devices with targeted attack software.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#43
post #34

Earlier quoted context omitted.

When it hits hedge funds and private equity firms people will start caring.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

> Security is still mostly an afterthought, if that, almost everywhere you look... yes, this will require immense effort.

What I keep thinking, though, is, what would be the total dollar cost to make security a forethought, with information technology being pretty ubiquitous? I think it might actually have serious economic impact -- is it possible we literally can't afford security, as a society?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#44
post #31

Earlier quoted context omitted.

> It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. It might have been a freudian slip or some kind of intuition, but when I was describing my life plans to my family, I said something along the lines of "I don't want to manage people, I want to stay on the front lines with the code." Except I d…

I've heard opinions along the lines of "thinking too much" countless of times, at first it was kind of depressing but later I've concluded that if you just like to think and analyze things in your mind (which is not so popular thing to do when you consider general population, sadly), people who voice such (negative, I'd say) comments didn't really think about this deeply. Over-analying can be a serious problem (consi…

Yea, the repetitive analysis usually stems from using the same model of which to analyze the data by. It's insufficient. That helps me turn it off, listen to other people, go about my life, learn new ways of thinking, connecting, interacting, helping, participating, and then I continue to re-evaluate myself, existence, and my place in it. I still can't shake the depression, though. Unless the entire world existed in a state of neutrality or bliss, I don't think I could. It's just an echo of sadness, something I have to distance myself from internally and examine scientifically, which allows me to remove it's control over me, and instead direct myself in ways I can improve the world, but, /shrug. I'm not perfect and I'm never going to exist perfectly and life is never going to be perfect, if perfect even could exist.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#45

Earlier quoted context omitted.

Nederlands $ whois 77.95.229.11

WTF?! Since when do we backdoor hardware in The Netherlands without informing the owner?

I'm sure even the Netherlands has some kind of mechanism in place to allow this if a sufficiently powerful court order is in place.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#46
post #12

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

To assume the only adversary is ISIS would be extremely foolish. Any actors within a system side with particular groups and ideologies. The Tor project maintainers align to an ideology shared with many other groups, just as ISIS align with a shared ideology, NSA/FBI etc share another... More likely NSA/FBI/nation-state level, or a large hacking group, although the former has clear motive here. ISIS has little motive for this. Use your common sense.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#47

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

> It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. It might have been a freudian slip or some kind of intuition, but when I was describing my life plans to my family, I said something along the lines of "I don't want to manage people, I want to stay on the front lines with the code." Except I d…

I don't think that the scenario you're sketching here is far fetched at all. Code re-use and recycling inside technical companies is very common. If any code you wrote there turned out to be great/good at something you'd never know where it might end up. Perhaps in the processor of some killer robot in the future.

I wonder where the code that is running inside the drones today comes from. Some one who never meant to be involved in those things must have written either the compiler, specs or actual code that these things use to do their killing, I can't imagine any company (no matter how secure they might want to be) designing a completely new processor architecture and tools and compilers and all that from scratch.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#48
post #28

Earlier quoted context omitted.

Can you explain more? How do go about dumping memory?

The specific tool they were mentioning is: https://secondlookforensics.com/ Interestingly enough, look who makes it.

Spoiler/save-the-click: "© 2014 Raytheon Cyber Products. All rights reserved. Second Look® is a registered trademark of Raytheon."

> The Raytheon Company is a major American defense contractor and industrial corporation with core manufacturing concentrations in weapons and military and commercial electronics.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#49

Earlier quoted context omitted.

Sorry, I think you misunderstood me... what I meant was - what is the purpose of the TLAs continuing with their raids if everyone knew it was about happen. That's what I meant by fear mongering.

OK, they might simply seek control of those servers in preparation for some large-scale action. Or they are after some people who they know absolutely depend on Tor to operate. Just wild speculation though...

> Or they are after some people who they know absolutely depend on Tor to operate. Just wild speculation though...

Maybe this is related to the Sony hacks, the authorities could know about a forthcoming data leak or threat. Taking away a major source of anonymity could prevent the information getting out.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#50
post #38
post #26

Earlier quoted context omitted.

Probably just a USB stick with Second Look or a similar tool on it. Very first thing you do is dump the running memory on the system. Then you pull the drives, plug them into a write blocker, then image the drives. Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.

Seeing how this is a targeted attack on an exit node specifically they're not going to be interested in dumping whats on the system for evidence. Even an idiot will know that someone running a TOR exit node isn't going to be a big fan of logging traffic in detail. Has to be an attempt to keep the node running but in a compromised state...

When you are going to take control over a machine you have physical access to while it is running, you should always dump memory because it might, among other things, contain disc encryption keys.
Post reply on HN