I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…
That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.
With computer crime it's especially obvious because most journalists don't know enough to understand what's hard and what's not, so they take the word of law enforcement, and law enforcement has big motivation to make it sound as bad as possible, since it enhances their significance and their success for catching one. "I've caught a sophisticated hacker" sounds better than "I've found a 13-year old kid that sent someone an email saying 'give me your password' and the poor shmoe was silly enough to do just that".
So there won't be a lot of reports about catching unsophisticated hackers. Usually it's always "highly sophisticated" ones.
OTOH, I think the actual (claimed) proof was using of certain bit.ly account etc. not sophistication per se.
Also, it looks like there were at least 3 attacks on the DNC, and phishing was only involved in one. Maybe the whitepapers talked about the other ones.