Google's version: http://queue.acm.org/detail.cfm?id=2371516
That's more about natural disasters, like losing a network node to a meteor. The Facebook story is about response to attack .
At Facebook, zero-day exploits, backdoor code bring war games drill to life
41–50 of 52 posts
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#42>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#43>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…
Facebook has on the order of a billion users. That's a huge cache of interesting content and access no matter how you slice it.
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#44Earlier quoted context omitted.
I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code"). As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole th…
> I had no idea we'd go so far as buying a 0-day Where did they get the 0-day?
http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#45The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?
For example: https://www.immunityinc.com/canvas-cep.shtml
This is standard practice for the industry and quite common. But do note that not all 0-days are created equal: a 0-day that effects 1000 users is 1000x the significance of one that effects only one user (with some notable exceptions). Also realize that 0-day is often used misleadingly - anything that was first used in the wild is a 0-day, even if that event was months ago, the vendor has been informed, and crucially - even if a patch has been issued by the vendor. Pentest firms often oversell their "0-days" in an effort to appear more advanced to their clients.
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#46>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#47Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#48The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?
I'm trying really hard not to read your post in Ned Flanders' voice. But in terms of 0-day exploits, I believe there is a ready market for them if you know where to look, and are willing to pay.
P.S. I have a mustache. Enjoy! :)
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#49>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…
Facebook is probably more of a target than Iran's nuclear facilities. Having an omniscient view of Facebook's users would be extraordinarily valuable to anyone in power, not to mention the ability to spearfish.
Spear phishing is a specifically targeted phishing attack that appear to come from a legitimate source... often one of authority within the targeted organization.[1]
1. http://searchsecurity.techtarget.com/definition/spear-phishi...
Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life
#50>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…
Also, Anonymous is far from the most sophisticated attacks a company like Facebook will see. They tend to stick to DDOS and easy SQL injections.