Live data from Hacker News

How hackers abused satellites to stay under the radar (2015)

arstechnica.com

61–69 of 69 posts

Re: How hackers abused satellites to stay under the radar (2015)

#62

Earlier quoted context omitted.

- did you have a cellphone in your pocket? - where did you get the cash? - by talking about it you negated all the advantages you built up - if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store - you may have left fingerprints in the store - the cabdriver has seen your face and knows your home address, you should have walked to the s…

Just woke up. Here you go: > did you have a cellphone in your pocket? Of course not. > where did you get the cash? I withdrew $500 from an ATM, then spent several days breaking them into $20's at various tiny Mexican restaurants. No, I didn't have a phone while doing this either. Important note: I planned on waiting a year after the operation before touching the funds to further reduce the risks. > by talking about i…

> If you have a list of questions 10 times as long, better ask them so that someone else doesn't make any mistakes either.

I really do not wish to turn this thread into a basic tradecraft tutorial, besides no matter what I add there will always be more stuff that you will mess up.

The only thing I want to achieve here is that people do not follow your silly advice and get themselves killed thinking they have discovered a fool-proof recipe for taking on large and dangerous game.

Re: How hackers abused satellites to stay under the radar (2015)

#63
I've done a significant amount of research on these threat actors. Despite the high tech exfiltration method and nation state support, researchers were still able to easily find their infrastructure. Satellite communications were encrypted via self-signed ssl certificates. Using internet scanning, we could track their IP addresses and associated domains using the SHA-1 of their certificate (map certificate to hosting IP). Happy to answer questions, but you can also read more here. https://blog.passivetotal.org/snakes-in-the-satellites-on-go...

Re: How hackers abused satellites to stay under the radar (2015)

#64

Earlier quoted context omitted.

Just woke up. Here you go: > did you have a cellphone in your pocket? Of course not. > where did you get the cash? I withdrew $500 from an ATM, then spent several days breaking them into $20's at various tiny Mexican restaurants. No, I didn't have a phone while doing this either. Important note: I planned on waiting a year after the operation before touching the funds to further reduce the risks. > by talking about i…

> If you have a list of questions 10 times as long, better ask them so that someone else doesn't make any mistakes either. I really do not wish to turn this thread into a basic tradecraft tutorial, besides no matter what I add there will always be more stuff that you will mess up. The only thing I want to achieve here is that people do not follow your silly advice and get themselves killed thinking they have discover…

I agree that most people shouldn't try this, just like most people shouldn't try to be startup founders.

But you're the foolish one if you think nobody can succeed. There are no fool-proof recipes. You do your best, prepare meticulously, and play the odds.

I've spent many years reading police reports and paying attention to how people are caught. (The annoying thing about learning craft as a lone wolf is that you have to pay attention to deplorable characters to learn the cutting-edge techniques used to catch them.) This doesn't make me smart, nor does it make me invulnerable. Leaving ego at the door is step zero.

You bet it's large and dangerous, and that's partly why I backed down. But there are ways.

It's easy to be a keyboard warrior. It's not so easy to do anything about the problems that face us.

I like you. But you're dismissive of anything you feel treads on your domain. Are you sure you're the only one who's carefully considered the issues?

If you have points, I'm sure nobody would object to this thread turning into a tradecraft workshop. Things like that are why we're all here.

Re: How hackers abused satellites to stay under the radar (2015)

#65
post #55

Earlier quoted context omitted.

1) How does the satellite come into this. 2) How does the C&C server complete the request. Are the hanging ports on the victim's side? 3) If the C&C server completes the connection, how do they carry on talking? Just like spoofing IPs, you can't ever get a reply. Or do they do the John decoy thing for every packet?

1) The satellite system system broadcasts to everyone (apparently poorly/not encrypted) in the area, so it isn't necessary to take over any upstream routing in order to get a hold of the incoming packets. They just arrive at your doorstep, and since you configured them to be rejected by normal clients you know you won't have to compete for the response. 2) The C&C just responds over regular land-line. (Since the sate…

I believe you are correct in your understanding. Mine was a little different. I thought this was a classic asymmetrical routing scenario on the Internet with a cool eavesdropper twist.

I'm assuming that because the sat system broadcasts unencrypted, you can sniff all the packets for all hosts on that network just like you can on a wifi network with the proper promiscuous mode receiver. An unencrypted shared broadcast medium.

So packet flow is routed inbound from victim as such

(victim SYN to decoy IP) to (internet) to (sat broadcast to geographic area decoy and attacker C&C)

But packet flow outbound from C&C to victim is handled differently via landline

(spoofed decoy IP) to (landline/internet) to (victim)

So packets come in via sat link but go out via spoofed source on a landline.

Re: How hackers abused satellites to stay under the radar (2015)

#66

Earlier quoted context omitted.

One person entered a dark alley, and then a few minutes later one person with the same build wearing different clothes left...

Once you're wearing goodwill clothes on top of your regular clothes with a coat in winter, you end up looking quite different.

Sure, you might look different, but you won't be more (or less) than one person. Anyone with a counter can solve that riddle, and if we're talking about state-level tracking infrastructure, CCTVs and other parts of the Panopticon are on the table.

Re: How hackers abused satellites to stay under the radar (2015)

#67

Earlier quoted context omitted.

> If you have a list of questions 10 times as long, better ask them so that someone else doesn't make any mistakes either. I really do not wish to turn this thread into a basic tradecraft tutorial, besides no matter what I add there will always be more stuff that you will mess up. The only thing I want to achieve here is that people do not follow your silly advice and get themselves killed thinking they have discover…

I agree that most people shouldn't try this, just like most people shouldn't try to be startup founders. But you're the foolish one if you think nobody can succeed. There are no fool-proof recipes. You do your best, prepare meticulously, and play the odds. I've spent many years reading police reports and paying attention to how people are caught. (The annoying thing about learning craft as a lone wolf is that you hav…

> I've spent many years reading police reports and paying attention to how people are caught.

The jails are full with people who thought they were really smart. Reading police reports does not prepare you for the reality, it only gives you a theoretical knowledge of what life on the other side of the line is like. Ironically, it might be the worst possible source of input because it only shows you what did not work, it does not show you what did work because you'll never hear about those things.

> It's easy to be a keyboard warrior.

Precisely.

> But you're dismissive of anything you feel treads on your domain.

No, I'm dismissive of advice that could get people in a lot of trouble. It's funny how people will prefix even the mildest legal advice with huge disclaimers but it's perfectly ok to dish out tradecraft advice of which you admit you only have a theoretical understanding and which could easily get someone in trouble, jailed or even killed.

You might as well tell people to watch CSI for inspiration if they decide to go after the mob by their lonesome.

And no, people are not here for advice on how to start a war with organize crime on a budget, I can see how it is nice to fantasize about being some kind of vigilante super-hero but those are typically movies, not real life. In real life unless you have a powerful organization of your own behind you when you start messing with the dark side you will wind up dead. Talking tough is not going to get you points and clothes bought in a thrift store do not offer magical protection.

But every time you power up your cellphone you tell a lot of people that can be bribed where you are (burnerphones hide your identity only as long as you use them in places that are not associated with you), every time you walk out the door you leave a nice DNA trail, every time you use an app on your phone (and plenty of them just running in the background) will tell tons of people (and networks where you can buy this info for cents or even for free) where you are to within an even smaller radius and so on.

Being anonymous and staying anonymous over a long period of time are really not the same things. The risk of discovery goes up with every interaction and with the power of computers behind the party doing the search the fight is asymmetrical.

Let me give you one concrete example of how short the distance can be between being at large and the dreaded knock on the door.

Camarades.com had a bit of a problem with people stalking others and one lady in particular was taking her chances. For 10 seconds she once pointed her camera at something else than her body, a mirror in the room, which reflected part of the scene outside. That was all it took for some crazy Italian to figure out where she lived and to show up on her doorstep three days of continuous driving later. I'm sure she never saw that one coming and for you in the tech world this may seem like an 'obvious' mistake to make. But just like that you too will be making obvious mistakes, just different ones.

Re: How hackers abused satellites to stay under the radar (2015)

#68

So this has to be some sort of state sponsored hacking right? I can't think of a non government group who would have the knowledge, money, or motivation to research this just to mask their origin when there are far simpler ways of receiving transactions (ie. bitcoin)

Not necessarily. I briefly pretended to be a criminal, mostly for fun. (Most readers will go "Uh huh" at this, but it was just a game.) Say you're developing the next Silk Road. Say you have perfect opsec, and you never reveal any personal info. What are your risks? The #1 risk is discovery of your physical location. Before every action, you must ask yourself: Will the next keystroke get me caught? It takes immense d…

> Why? Because when your opponent is a nation-state, you have a risk of being found via any other method. You can't drive anywhere because of license plate trackers. You can't show your face at the store thanks to facial recognition. You can't wear the same outfit without being picked up on CCTV's near your home base in the same outfit that you were wearing at the store.

If your threat is a nation-state, you'd also do well to avoid walking anywhere critical where you might be recorded, because of gait signature identification, but you seemed to have ignored that.

Re: How hackers abused satellites to stay under the radar (2015)

#69

Earlier quoted context omitted.

I agree that most people shouldn't try this, just like most people shouldn't try to be startup founders. But you're the foolish one if you think nobody can succeed. There are no fool-proof recipes. You do your best, prepare meticulously, and play the odds. I've spent many years reading police reports and paying attention to how people are caught. (The annoying thing about learning craft as a lone wolf is that you hav…

> I've spent many years reading police reports and paying attention to how people are caught. The jails are full with people who thought they were really smart. Reading police reports does not prepare you for the reality, it only gives you a theoretical knowledge of what life on the other side of the line is like. Ironically, it might be the worst possible source of input because it only shows you what did not work,…

I appreciate the post, and you're an excellent writer. But I did address every one of your points. Cellphones have to be used with the same care as the original operation. Those 10 seconds you mention are something you can't do. If you're someone who is foolish enough to make those mistakes, you shouldn't be involved in any of this.

One thing that's helped me is to plan operations that can fail gracefully. For example, if anyone had spotted me during the op, I would've scrubbed it. No harm done. But since it was successful, I probably would have known about any mistakes that would've led to my exposure.

Note that word "probable." Once again, there's no such thing as a foolproof plan. You can only try.

None of my comments were "advice," either. They're an example that you can make progress, even if you're a lone wolf. Your first paragraph goes both ways: We don't hear about the successes.

The list of failures is long. If you don't have a meticulous personality, then these choices aren't for you. Meticulousness is more important than intelligence, though you do need a minimum level of competence to do anything.

But to insinuate that nobody anywhere can do anything is -- well, we'll let history be the judge of that.

Post reply on HN