Live data from Hacker News

At Facebook, zero-day exploits, backdoor code bring war games drill to life

arstechnica.com

41–50 of 52 posts

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#41

Google's version: http://queue.acm.org/detail.cfm?id=2371516

That's more about natural disasters, like losing a network node to a meteor. The Facebook story is about response to attack .

Next time Facebook should test their engineers response to an alien attack via a meteor.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#42

>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…

What makes you think this is the only security drill Facebook has performed?

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#43

>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…

While FB may not be a nuclear facility, I can pretty much guarantee you that people who use nuclear facilities (or their equivalent) have FB accounts. And that hacking those accounts and/or the computers that are used to access them would probably be a not good thing.

Facebook has on the order of a billion users. That's a huge cache of interesting content and access no matter how you slice it.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#44
post #31
post #27

Earlier quoted context omitted.

I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code"). As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole th…

> I had no idea we'd go so far as buying a 0-day Where did they get the 0-day?

They're readily available, if you're willing to pay the price:

http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#45
post #6

The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?

Trustwave was the outside party running the penetration test. 0-days are commonly used by pentesters, and are available for purchase by subscription as well as one offs that are made available via mailing lists etc.

For example: https://www.immunityinc.com/canvas-cep.shtml

This is standard practice for the industry and quite common. But do note that not all 0-days are created equal: a 0-day that effects 1000 users is 1000x the significance of one that effects only one user (with some notable exceptions). Also realize that 0-day is often used misleadingly - anything that was first used in the wild is a 0-day, even if that event was months ago, the vendor has been informed, and crucially - even if a patch has been issued by the vendor. Pentest firms often oversell their "0-days" in an effort to appear more advanced to their clients.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#46

>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…

Facebook is probably more of a target than Iran's nuclear facilities. Having an omniscient view of Facebook's users would be extraordinarily valuable to anyone in power, not to mention the ability to spearfish.

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#47
I love the facebook story but installing a camera with high resolution and zoom ability in an area where it's just supposed to be general watching is like putting an ICBM on a router to the internet (and I sure hope that's just physically impossible).

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#48
post #6

The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software. What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?

I'm trying really hard not to read your post in Ned Flanders' voice. But in terms of 0-day exploits, I believe there is a ready market for them if you know where to look, and are willing to pay.

This is what worries, me. Facebook is buying up exploits? I know there's a steady supply, but without knowing what software they're referring to or what the exact nature of the exploit was, it's hard to know what to think. Privilege escalation, arbritary code execution or what? Was it in the OS or some application they themselves developed? If it's the OS, then that would be really disturbing.

P.S. I have a mustache. Enjoy! :)

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#49
post #46

>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…

Facebook is probably more of a target than Iran's nuclear facilities. Having an omniscient view of Facebook's users would be extraordinarily valuable to anyone in power, not to mention the ability to spearfish.

Because I was unaware and looked it up:

Spear phishing is a specifically targeted phishing attack that appear to come from a legitimate source... often one of authority within the targeted organization.[1]

1. http://searchsecurity.techtarget.com/definition/spear-phishi...

Re: At Facebook, zero-day exploits, backdoor code bring war games drill to life

#50

>> The engineer's computer was compromised using a real zero-day exploit targeting... Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits. I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of thei…

The vast majority of these sorts of exploits are delivered via spearfishing, which is a form of social exploit in that a human being is fooled into clicking a link or opening a file that contains malicious code. The article doesn't specify, but I would bet that was the vector in this case too.

Also, Anonymous is far from the most sophisticated attacks a company like Facebook will see. They tend to stick to DDOS and easy SQL injections.

Post reply on HN