Live data from Hacker News

Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

trendsnewsline.com

41–50 of 102 posts

Re: Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

#41
post #5

Earlier quoted context omitted.

I'll happily wait for someone else to open that archive and let us know whats in the folder. Somehow feels like a great way to get a bunch of people to download a rar with a zero day

Yes, an example: https://blog.google/threat-analysis-group/government-backed-... I also do not understand how Anonymous would sift through 10TB to confirm the validity of the claims.

> Instead of bailing out, ShellExecute proceeds to call “shell32!ApplyDefaultExts” which iterates through all files in a directory, finding and executing the first file with an extension matching any of the hardcoded ones: “.pif, .com, .exe, .bat, .lnk, .cmd”.

So the vulnerability is not in WinRAR, but rather in the ShellExecute windows code that desperately tries to find something else to run when asked to execute a file that does not exist.

As my security officer says at $dayJob, "having a security hole there for thirty years does not make it somehow less of a security hole".

Re: Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

#42
post #29
post #10

Earlier quoted context omitted.

Judging by the OP's profile, we should be happy that the "AI" managed to recognize a number :)

I am not an LLM [edit] ( as far as I know ;-), but thanks for the profile crit I probably should tidy it up.

Yep, the safe assumption with a profile like that is that it's something automated.

Also yes, that's the file size column. Uncompressed left, compressed right. It's a directory but the screenshot doesn't say how many files it contains.

Re: Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

#43
post #5

Earlier quoted context omitted.

I'll happily wait for someone else to open that archive and let us know whats in the folder. Somehow feels like a great way to get a bunch of people to download a rar with a zero day

So always wait for others to do something? Don't just download it on your windows home pc with your private data of course.

In some cases, yes.

An unknown threat, potentially from the supposed nation-state target itself, has a very high risk.

I'm not versed in creating ultra-sterile lab conditions -- things can escape VMs, escape your network, nothing is impossible. Do I instead bring it to my employers systems and let them take the risk? And to what benefit, when I can just wait?

Re: Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

#45

Earlier quoted context omitted.

You don't have to download the whole 10TB...

Seems very odd an ai account?* is posting a seemingly unknown 'news' site to a very large unverified file that didn't seem to pass the desk of any major news org and all the 'sources' of this leak come from the same mediafire link, not even a torrent? *account details looks odd, copy and pasting ai summary of article

[deleted]

Re: Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

#49
post #22

Earlier quoted context omitted.

Because the article is currently down so the summary is all there is for now. Yes it provides no extra information but in the [hnews hug of death] of the article it is the only information at the moment

>Because the article is currently down so the summary is all there is for now. Although ironically this "release" article also seems like an ai summary. Although prose could just be foreign language speaker speaking english. https://archive.md/2C1WB#selection-252.1-277.611

Ironically, a primary use case for AI will be to summarise AI summaries of articles and CVs.

In a sea of slop…

Re: Anonymous Release 10TB Leaked Data Exposing Kremlin Assets, Russian Businesses

#50

If this is real, there will be claims made and the general public has no way to verify. 10TB is technically challenging to handle for the vast majority of people. Would be really important for someone to re-upload and index the extracted files for online browsing.

Just like the Panama Papers?

Did anything even happen after the Mossack Fonseca law firm was hacked? All I remember was a few people stepping down from govt positions, some rich folks get caught in the xfire (some football player used them).

But nobody went to jail.

Post reply on HN