Live data from Hacker News

How the U.S. Hacked ISIS

npr.org

51–56 of 56 posts

Re: How the U.S. Hacked ISIS

#51

I wish articles like this would divulge some details of the technical side of hacking, rather than keep it a mystical field of study. What did they hack and how did they “get in”? Contrary to the title, there is little “how” and mostly “what”.

Though the article does not outright say it, read between the lines when you see this:

> They even had file sharing through them. "If we could take those over," Neal said, grinning, "we were going to win everything."

Then see some public CVE's around that time, such as:

> CVE-2015-5474: BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.

> Project Zero 2018: Simply put, those JSON-RPC issues create a vulnerability in the desktop and web-based uTorrent clients, which both use a web interface to display website content. An attacker behind a rogue website, Ormandy said, can exploit this client-side flaw by hiding commands inside web pages that interact with uTorrent’s RPC servers. Those commands range from downloading malware into the targeted PC’s startup folder or gaining access to user’s download activity information.

And the remote code execution via media files / video virus (Hollywood movies, porn) https://www.cvedetails.com/vulnerability-list/vendor_id-5842... .

So you have file sharing going on, and can remote code execute, if: you get the target to visit a website you (partly) control, you get the target to click a (.torrent) link you crafted, you get the target to download a manipulated video file, compromised (Adobe) software, or cracked game with the payload. These if's are for a military that can easily DNS hijack, spoof (update) certs, ask help from allies who control 25% of all internet advertisements, set up convincing websites targeted to the region, or reroute internet traffic.

Re: How the U.S. Hacked ISIS

#52

"Folder directory deleted" Cringe.

I cringed a bit at that and the end of the next paragraph:

> Once he did that, he would see: 404 error: Destination unreadable.

Sounds like somebody got their ICMP types and HTTP response codes mixed up but, hey, they're journalists, not IT guys. We understood their point.

Re: How the U.S. Hacked ISIS

#53
post #46

This article has no substance and is seriously completely stupid.

You may be right, but this isn't a helpful comment. Per the HN guidelines [0]:

    Be kind. Don't be snarky. Comments should get more
    thoughtful and substantive, not less, as a topic
    gets more divisive.

    When disagreeing, please reply to the argument
    instead of calling names. "That is idiotic;
    1 + 1 is 2, not 3" can be shortened to "1 + 1
    is 2, not 3."

    Please don't post shallow dismissals, especially
    of other people's work. A good critical comment
    teaches us something.
[0] https://news.ycombinator.com/newsguidelines.html

Re: How the U.S. Hacked ISIS

#54

I would hope that a country with the largest military industrial complex in the world can hack a group of camel herders in a desert. Doesn't seem particularly impressive

Is the racism critical to expressing your view. I understand those terrorist are horrible evil people and inflicted pain and death on innocent people. Your racist comment is grounded in racism towards Arabs and Muslims. Most victims of ISIS are physically near them

Re: How the U.S. Hacked ISIS

#55
post #35

Earlier quoted context omitted.

That is a valid argument, but can be applied to any hush hush effort. But such "limited visibility" organizations often push to limit public control, after which their mission or methods may morph to support internal goals that may not be shared by the general public they were created to serve. It would be naive to require that all government information is shared with the public, but we should maintain robust oversi…

US citizens would be better served by having more oversight and transparency into the lobbying efforts of the NRA and health insurance companies, among others. The civil servants at the NSA have far more in common with 'the public' than any executive at a company that can afford to lobby Congress.

Totally agree. Follow the money will never be un-true.
Post reply on HN