Live data from Hacker News

“NASDAQ is owned.” Five men charged in largest financial hack ever

arstechnica.com

121–130 of 143 posts

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#121
post #83

Upvoted, did make me enjoy the read. 6 months since the first SQLi to the "Nasqad is owned". 6 months... Sometimes I've play Neo from a pub connection with recycled hardware (not buy with my card number) but at most one week to the same target. I wish I could have the skills of those people. Not that I want to make money stoled from unknown people... I just would like to have their skills.

"Sometimes I've play Neo from a pub connection with recycled hardware (not buy with my card number) but at most one week to the same target."

Could you explain what you are saying here?

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#123
post #56

Earlier quoted context omitted.

The IDF's ICT unit also has a very large budget (it's actually the only unit with an increasing budget despite a 2 billion overall budget drop), and with access to all kinds of technologies that only a government can afford. When the engineers get out of there, they know things that few people know about.

Yep. This is why many people believe that Stuxnet was developed by Israel - it was so advanced that only a country like that could have done it.

According to Snowden it was co-written by Israel and the US.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#124

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

From my experience with employees who originally came from russia to germany is that they were all pretty smart... most of them were also really good at chess for example, so i guess its something about the education there...seems to be quite math heavy

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#125
post #70
post #54

Earlier quoted context omitted.

That's exactly what defines SQLi. Incorrect filtering of user data is precisely the reason why SQLi is a vulnerability.

Incorrect handling I'd say. If you're filtering apostrophes from your user input you're doing it wrong.

This is a semantic quibble. Your point could be restated as, "if you're not filtering potentially dangerous data out of your SQL queries (i.e. you're not using a fixed vocabulary of properly-quoted phrases) then you are vulnerable to SQLi."

think of it this way: no matter how you slice it, there are Bad Things you need to keep out of your SQL, and an easy layperson term for doing so is 'filtering'.

Recall that 'filter' != regexp.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#126

Is anyone aware of a) whether other security auditors or services could have identified these vulnerabilities and b) what it takes to sell to these exploited firms? My understanding of security is fairly small, but it seems to me that there's a market to be had here ... If the expertise exists to dramatically reduce exposure, it's a question of sales or ease of use. If the expertise doesn't exist yet, someone smart m…

software is fundamentally broken in some way that it just gets harder and harder to keep a lid on the more effort we make. There is money to be made selling inflatable rafts before a tsunami, but it's pretty depressing work and pretty much everyone is still going to die. The only semi-workable answers are air gapping and drastically reducing the size of your code base, and neither are working that awesome for people or is anyone much willing to do it. Look at google chromeos. One of the lowest attack surface pcs on the market and it was designed from the ground up assuming they'd get owned regularly. Very few other orgs are doing either one.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#127
Wow, the US Attorney is really going out of his way to fill this one up with bullshit. I knew something was very wrong when goodin claims hundreds of millions in losses on a carding ring and it didn't take long to find it. The only people that would pay $50 for anything having anything to do with credit cards would be fbi investigators. Hell they're the only ones that would pay one tenth that.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#128
post #83

Upvoted, did make me enjoy the read. 6 months since the first SQLi to the "Nasqad is owned". 6 months... Sometimes I've play Neo from a pub connection with recycled hardware (not buy with my card number) but at most one week to the same target. I wish I could have the skills of those people. Not that I want to make money stoled from unknown people... I just would like to have their skills.

"Sometimes I've play Neo from a pub connection with recycled hardware (not buy with my card number) but at most one week to the same target." Could you explain what you are saying here?

Yes, I see my sentence was not clear at all.

There I was saying, that even if I have make some security research, from a internet connection not related with me, with hardware not related with me, I've never work on it more than 1 week. This people was 6 months against the same target (owning it) without being detected.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#129
post #22

Earlier quoted context omitted.

In Israel, military service is compulsory for all men when they are 18 years old. The best hackers in the country are detected and lured into cyberwarfare positions where they need to be the best cyber attackers in the world for 3 years. You bet that these guys are among the best in the world.

> for 3 years Not exactly true. There are a few different computer groups, one of which requires only three years and it is nowhere near the level of sophistication of an average programmer (they are mostly responsible for the technological infrastructure of the army). The other programs require a degree beforehand (so they only go into the army at about 22) and then require 5 years of service. These are the people w…

You describe the mamram thing, but aman conscripts people who are better at 17 than good compsci grads from the technion at 22. They do 4 years, not like atuda. aman also gets people from talpiot and the best mamram has to offer.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#130
post #21

Earlier quoted context omitted.

Sanitizing your inputs is apparently even harder than salting and hashing your passwords, something even the big-name companies tend to mess up. Sigh.

Little Bobby Tables, we call him.

http://xkcd.com/327/
Post reply on HN