Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

271–280 of 502 posts

Re: Technical report on DNC hack [pdf]

#271
post #239

Earlier quoted context omitted.

The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.

Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Sure, HDD firmware hacks are cool, but in terms of R&D time far less efficient if you're willing to spam attempts to get in the front door. And I'd say they chose the appropriate level of sophistication given the success of the penetration. The DNC isn't exactly an air-gapped Irania…

Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface?

Then how is this evidence of a 'state-sponsored actor'?

And how did the narrative of this story ever get derailed from what it should have been, which was, "The DNC, and John Podesta in particular who had both his gmail and his Twitter accounts hacked, are incompetent", to "this is Russian interference in a US election"?

Re: Technical report on DNC hack [pdf]

#272

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

Check out the Mooltipass it's the hardware security device I want but can't afford because of college.

Can experts weigh in on the utility of this thing? To my ignorant eyes it looks excessively complicated.

To save you a search it's here: https://www.themooltipass.com/

Re: Technical report on DNC hack [pdf]

#273

Earlier quoted context omitted.

Could you elaborate? Once you have a password shouldn't it be as easy as just downloading all the emails? Any email client should have the functionality built in. edit: seeing some reports they used "sophisticated" SQL injection... okay...I mean for a lay person it seems sophisticated, sure. But for anyone in the industry it's one of the oldest and easiest tricks in the book. I really suspect news sources are knowing…

You can read about the backdoors they used here: https://www.crowdstrike.com/blog/bears-midst-intrusion-democ... The summary: One used Powershell modules and Windows Scheduler to run scripts. Another used a combination of Twitter and public sites like Github/Dropbox for command and control. In my opinion, neither is impressively sophisticated, and a skilled application developer could whip up something similar in a w…

Your "summary" leaves out the key points. The SeaDaddy, X-Agent, and X-Tunnel tools used in these attacks have only been used by two groups, using the same control servers each time, on European, American, and World Anti-Doping Agency targets that the Russians had strong motive to attack, with some of the attacks being attributed to Russia by multiple other means.

If it turned out that Russia was not behind these attacks, the scale of the bad publicity for Crowdstrike, Fidelis, Palo Alto Networks, etc. would nearly put them out of business. Unlike you, they have skin in the game and don't make these claims lightly.

Re: Technical report on DNC hack [pdf]

#274
post #246
post #243

Earlier quoted context omitted.

Wasn't the NSA spying on the whole Internet or something? Are you telling me the NSA saw no evidence of Russia hacking the DNC servers? They wouldn't necessarily have to reveal their "methods" that it was the Russians if it was the NSA catching them and not some Kremlin CIA spy. But who knows, maybe they are too busy spying on hundreds of millions of Regular Joes to watch out for all of the Russian attacks.

Haven't the NSA already said they believe it was the Russians? As you suggest, they would be the ones to know.

Source? I googled it and only found articles suggested the opposite.

ex.https://theintercept.com/2016/12/29/top-secret-snowden-docum...

Re: Technical report on DNC hack [pdf]

#275

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

This is not evidence, and it is unlikely evidence would be released. The Administration (as is usually the case for any US executive on any issue unless they are seeking action that requires legislation or a court verdict or something similar by some formal body outside of the executive branch) is not engaging in an effort to prove anything to anyone.

This is an analysis report with information (including most significantly the IOCs in the accompanying files), some of which is previously released and some of which is newly declassified, for use in defending against and forensically identifying attacks by the threat groups identified.

No one is passing this off as evidence of anything.

Re: Technical report on DNC hack [pdf]

#276
post #255
post #244

Earlier quoted context omitted.

This (complaining about the lack of evidence) just seems ludicrous to me. Does the FBI have a history of declassifying stuff like this so that randos on the internet can independently verify its conclusions? When high-level intelligence people collude to lie to the American people and discredit a president, do they usually do it via press release clearly written by a PIO? The accusation that people who find this cred…

The FBI has a history of political activism, to put it lightly. Here's a fun one: https://en.m.wikipedia.org/wiki/FBI–King_suicide_letter You're being foolish if you trust a word the FBI says without solid evidence.

Seriously. Clapper lied directly to congress under oath on TV. The whole "they know whats best for us and our only choice is blind faith" attitude is really disturbing.

Re: Technical report on DNC hack [pdf]

#277
post #31

Earlier quoted context omitted.

How do bunch of ip addresses form china/Sweden/germany/canada make this attack attributable to russians .

I guess the real question is, why should these IP addresses from those countries make this attack attributable to Russia? Unless you can answer that, yours doesn't really make much sense.

>why should these IP addresses from those countries make this attack attributable to Russia?

"DHS has released a Joint Analysis Report (JAR) attributing those compromises to Russian malicious cyber activity, designated as GRIZZLY STEPPE. "

This is one of the 'GRIZZLY STEPPE Indicators' . Am i reading this wrong ?

Re: Technical report on DNC hack [pdf]

#278

Earlier quoted context omitted.

> This attacks could be easily mitigated. [...] second, we should start using physical cryptographic keys instead of passwords Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.

I think it's a generational thing. Americans of a certain vocation and certain age and older tend to have no idea about how this whole Internet thing works. No matter what their education level or achievement level. Obama held onto his Blackberry for almost 2 years after SS told him you can't use that thing. I suspect what needs to happen is each branch of government needs to have infosec people assigned to it that s…

I think it's a generational thing. Americans of a certain vocation and certain age and older tend to have no idea about how this whole Internet thing works. No matter what their education level or achievement level

That is an impressively dismissive statement.

Re: Technical report on DNC hack [pdf]

#279

Earlier quoted context omitted.

That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.

The report just didn't get into that much detail but they did say: "the code delivers Remote Access Tools (RATs) and evades detection using a range of techniques." A "range of techniques" includes things like rootkits. >No rootkits, The attackers did use stealthy persistence techniques often called 'rootkits". "the SeaDaddy implant developed in Python and compiled with py2exe and another Powershell backdoor with pers…

Can't one just buy a RAT?

Also, the WMI think they describe doesn't look like rootkit, more like cron analogue for Windows. I.e. on Unix it would be like installing a command inside crontab. That's not what is usually called a rootkit - a tool that is designed to conceals its presence (and other tools presence) from regular OS tools.

Re: Technical report on DNC hack [pdf]

#280

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

It is more like:

1. Hackers drove a custom built tank that has Moscow factory markings.

2. Similar versions of the tank were used in other campaigns attributed to Russian intelligence.

3. Crew in the tank has been associated with Russian intelligence operations going back ten years.

4. The tank left from a building known to be associated with Russian intelligence hacking campaign.

Thus, the hackers probably take orders from Russian intelligence.

Post reply on HN