It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
Most ordinary users will connect to the internet using a router provided by their ISP so port knocking does not work. Unless they plant the malicious code on the router - that would be even harder to detect.
Knock Knock Who's There? – An NSA VM
11–20 of 46 posts
Re: Knock Knock Who's There? – An NSA VM
#12> I made local presentations at 0xOpoSec and BSidesLisbon but those slides were never published for obvious reasons (aka live implants all over the Internet). I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil? Intelligence services are the worst terrorist organizations, and most people tar…
Live implants, means if they published you or I can access the implants and therefore the victims' systems.
EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger, in french law) Or couldn't you partner with a security research lab with better legal counsel?
Re: Knock Knock Who's There? – An NSA VM
#13Earlier quoted context omitted.
Live implants, means if they published you or I can access the implants and therefore the victims' systems.
If you've got root RCE can't you use it to "close" the implant and make sure noone gets hurt like some have been doing to counteract IoT botnets? How is leaving a gaping hole better? EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger,…
Re: Knock Knock Who's There? – An NSA VM
#14Earlier quoted context omitted.
Live implants, means if they published you or I can access the implants and therefore the victims' systems.
If you've got root RCE can't you use it to "close" the implant and make sure noone gets hurt like some have been doing to counteract IoT botnets? How is leaving a gaping hole better? EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger,…
Re: Knock Knock Who's There? – An NSA VM
#15> I made local presentations at 0xOpoSec and BSidesLisbon but those slides were never published for obvious reasons (aka live implants all over the Internet). I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil? Intelligence services are the worst terrorist organizations, and most people tar…
Re: Knock Knock Who's There? – An NSA VM
#16Earlier quoted context omitted.
Live implants, means if they published you or I can access the implants and therefore the victims' systems.
If you've got root RCE can't you use it to "close" the implant and make sure noone gets hurt like some have been doing to counteract IoT botnets? How is leaving a gaping hole better? EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger,…
Re: Knock Knock Who's There? – An NSA VM
#17Earlier quoted context omitted.
Rootkits/exploits appear on any operating system. Wipe and reinstall often, rotate passwords at same time, also teaches good backups. ad blocker by default and always up to date system. Use VMs or other machines for dubious websites and wipe those often (like a raspberry?) Careful what you execute on your machine Then if you're really paranoid: Some external firewall running suricata for alerting Logging to an extern…
In this spirit I've been playing with spun up Firefox instances in a Google Cloud Run. The container is stateless and goes away after I close the page that connects to video stream of the other container in my browser.
Re: Knock Knock Who's There? – An NSA VM
#18> I made local presentations at 0xOpoSec and BSidesLisbon but those slides were never published for obvious reasons (aka live implants all over the Internet). I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil? Intelligence services are the worst terrorist organizations, and most people tar…
I sure wouldnt want you to have access to these :p
I just want holes to be fixed.
Re: Knock Knock Who's There? – An NSA VM
#19Earlier quoted context omitted.
Rootkits/exploits appear on any operating system. Wipe and reinstall often, rotate passwords at same time, also teaches good backups. ad blocker by default and always up to date system. Use VMs or other machines for dubious websites and wipe those often (like a raspberry?) Careful what you execute on your machine Then if you're really paranoid: Some external firewall running suricata for alerting Logging to an extern…
In this spirit I've been playing with spun up Firefox instances in a Google Cloud Run. The container is stateless and goes away after I close the page that connects to video stream of the other container in my browser.
Re: Knock Knock Who's There? – An NSA VM
#20Earlier quoted context omitted.
In this spirit I've been playing with spun up Firefox instances in a Google Cloud Run. The container is stateless and goes away after I close the page that connects to video stream of the other container in my browser.
For all intents and purposes Google is the civilian NSA, I'm not sure you're gaining anything by creating VM in their cloud!