I don't really get the part with Russian nested dolls. Was it like this?: For example, there is a code which is encrypted three times. And that crypt-code by itself is executable which decrypts itself into another executable, and so on. If this is true - I'm really impressed.
Google Hack Attack Was Ultra Sophisticated, New Details Show
81–90 of 116 posts
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#82Earlier quoted context omitted.
Linux security assumes source code visibility, Windows doesn't?
Yes, Windows' closed-source nature has allowed MS to rely on security-though-obscurity . Now that one of the entities MS has taken behind it's golden screen has turned out to be a black hat, MS' approach is looking foolish.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#83I find the fact that Adobe got hacked by a pdf vulnerability kinda funny.
most companies have offices in india, china. And even risking a moral point here, all companies have chinese employees.
Hell, when I worked for a shady company here [regret] most employees used to sell the email database.
what about the oposite? use employees to insert vulnerabilities instead of selling data.
Will anyone run `cvs blame` on the IE4 source code?
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#84I find the fact that the targets were source code repos very interesting. If you are a super-smart black-hat villain who wants to plan a mass global attack, what better place to start than with Google and Adobe's source code?
> what better place to start than with Google and Adobe's source code? I wonder if Microsoft was targeted too.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#85Earlier quoted context omitted.
> what better place to start than with Google and Adobe's source code? I wonder if Microsoft was targeted too.
What's the point, when the Chinese government already has all their source code?
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#86Earlier quoted context omitted.
Linux security assumes source code visibility, Windows doesn't?
Yes, Windows' closed-source nature has allowed MS to rely on security-though-obscurity . Now that one of the entities MS has taken behind it's golden screen has turned out to be a black hat, MS' approach is looking foolish.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#87I don't really get the part with Russian nested dolls. Was it like this?: For example, there is a code which is encrypted three times. And that crypt-code by itself is executable which decrypts itself into another executable, and so on. If this is true - I'm really impressed.
I'm not impressed with the Russian doll encryption. Like with DRM, you have to give away the keys to your users. So the analysts had to work a little more than usual to examine the code. Big deal. There was never a question of if they would be able to analyse it, but just how long it would take. There must be something else they have not disclosed that is making them take notice.
[Edit: added 2nd sentence.]
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#88Another aspect perhaps most of people ignored is: Chinese government has all the source code of Windows systems: http://news.cnet.com/2100-1016_3-5083458.html Including: Windows Vista, Windows XP, Windows Server 2003, windows 2000, Windows CE 6.0/5.0/4.2(PSK), Microsoft Office Pro 2003, Microsoft Office Systems It's reviewed by top three Chinese universities and other three government agencies. The Party is the new o…
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#89In other news, I was just sent an Email by Bank of America... Said my card was compromised, I called in and they said their systems were hacked and he gave the name and location of the system... You might not know it, but sounds like BoA was compromised as well.
Re: Google Hack Attack Was Ultra Sophisticated, New Details Show
#90I find the fact that the targets were source code repos very interesting. If you are a super-smart black-hat villain who wants to plan a mass global attack, what better place to start than with Google and Adobe's source code?
what better place to start than with Google and Adobe's source code? Indeed -- and especially their auto-upgrade mechanisms. There may yet be more to Google's anger that's not yet been revealed. What if the attackers didn't just look around, but changed (or tried to change) Google content/code at the source?