Live data from Hacker News

The Elite Hackers of the FSB

interaktiv.br.de

11–20 of 25 posts

Re: The Elite Hackers of the FSB

#11
post #6

Earlier quoted context omitted.

What about this is state propaganda? Turla/Snake is very real, the fact that they attacked several agencies like the german foreign ministry and others is very real, as well as that all of the connections shown in this article do exist and can be verified by doing some googling.

The article contains no proof except for references to documents published by the same government that is producing the article itself. It's propaganda.

.. just a quick reminder for anyone outside of dictatorships: there is independent media/press in germany, the article was not produced by any government entity.

Re: The Elite Hackers of the FSB

#12
There's simply no forensic evidence of their claims here -- just a CPU-draining powerpoint show of nothingburgers. This reminds me of a slightly more modern version of Condoleeza Rice presenting fake evidence of Saddam Hussein's WMD development. Just a basic appeal to authority with a total lack of evidence.

Re: The Elite Hackers of the FSB

#13

I have an interesting story that I can only recently share due to the statute of limitations passing. I'll stay anonymous for this story. A number of years ago, I worked on a security team "somewhere". When I joined the place, I was given some context by the other employees about advanced intrusions in the past. For years I spent late nights pouring over my laptop trying to find every imaginable way of breaching the…

Cool story, that does indeed sound like a plot out of a movie!

How were you able to extract a password from just listening to scp (ssh really) traffic though? Also, how did you know that someone's entire network was SSL MITM'd, only by looking at the data they dumped? Did the hackers store a readme file along with every dump?

Re: The Elite Hackers of the FSB

#14
post #13

I have an interesting story that I can only recently share due to the statute of limitations passing. I'll stay anonymous for this story. A number of years ago, I worked on a security team "somewhere". When I joined the place, I was given some context by the other employees about advanced intrusions in the past. For years I spent late nights pouring over my laptop trying to find every imaginable way of breaching the…

Cool story, that does indeed sound like a plot out of a movie! How were you able to extract a password from just listening to scp (ssh really) traffic though? Also, how did you know that someone's entire network was SSL MITM'd, only by looking at the data they dumped? Did the hackers store a readme file along with every dump?

The traffic containing the clear text password was not scp, it was the reverse shell they sent themselves. Reverse shells are unencrypted on the wire, and when scp prompted for the password, they typed it in over their reverse shell. A significant oversight on their part. If it was a team, it must have been a less experienced member who made that mistake.

As far as the SSL MITM goes, they indeed documented their attack with various files containing notes in English. They had a separate directory (within the target's folder) containing the certificates they were using in the attack.

Re: The Elite Hackers of the FSB

#17
post #13

Earlier quoted context omitted.

Cool story, that does indeed sound like a plot out of a movie! How were you able to extract a password from just listening to scp (ssh really) traffic though? Also, how did you know that someone's entire network was SSL MITM'd, only by looking at the data they dumped? Did the hackers store a readme file along with every dump?

The traffic containing the clear text password was not scp, it was the reverse shell they sent themselves. Reverse shells are unencrypted on the wire, and when scp prompted for the password, they typed it in over their reverse shell. A significant oversight on their part. If it was a team, it must have been a less experienced member who made that mistake. As far as the SSL MITM goes, they indeed documented their atta…

Can't help but imagine your www-data which spawned nc, and it seems too amateurish for a high profile hacker group. Makes it seem as if they've copy-pasted the first one-liner reverse shell found on Google. Even the Metasploit framework has introduced payloads a while ago which do traffic encryption/obfuscation. Much more subtle reverse shells are used in the wild, where a compromised machine reaches out to hacker's server once in a while and receives commands and dumps output, even over something like ICMP/Loki or Covert TCP.

Re: The Elite Hackers of the FSB

#18
post #11
post #6

Earlier quoted context omitted.

The article contains no proof except for references to documents published by the same government that is producing the article itself. It's propaganda.

.. just a quick reminder for anyone outside of dictatorships: there is independent media/press in germany, the article was not produced by any government entity.

>there is independent media/press in germany, the article was not produced by any government entity.

Perhaps, but the public broadcasting channels (Öffentlich-rechtlicher Rundfunk) aren't part of this. You can predict their reporting and spin with good accuracy depending on which political party they're aligned with (SPD -> ARD, CDU -> ZDF, NDR -> Die Grünen).

Re: The Elite Hackers of the FSB

#19

I have an interesting story that I can only recently share due to the statute of limitations passing. I'll stay anonymous for this story. A number of years ago, I worked on a security team "somewhere". When I joined the place, I was given some context by the other employees about advanced intrusions in the past. For years I spent late nights pouring over my laptop trying to find every imaginable way of breaching the…

hey, as one of the reporters writing the article, I'm intrigued, obviously :D

Re: The Elite Hackers of the FSB

#20
post #5

The WebGL graphics background on this site causes my Laptop to chug pretty severely, to the point where I'm not able to read the content.

The website UI/UX is truly amazing, and as a web dev, I wish I knew how to write websites like this.

I'm thankful for Firefox reader view. Had that not worked, it would have been a quick Ctrl-A, Ctrl-C, Ctrl-V into my fav editor. Good article. I'm not sure why someone would intentionally make it more difficult to read. The world is swimming in content, but I'm not so certain attention spans have increased. Risky business.

That said, I don't disagree that the special effects seem impressive -- not that I'm competent to judge.

Post reply on HN