Knock Knock Who's There? – An NSA VM
reverse.put.as
Knock Knock Who's There? – An NSA VM
1–10 of 46 posts
Re: Knock Knock Who's There? – An NSA VM
#2What can ordinary users do to protect themselves other than patching?
Re: Knock Knock Who's There? – An NSA VM
#3It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
Wipe and reinstall often, rotate passwords at same time, also teaches good backups.
ad blocker by default and always up to date system.
Use VMs or other machines for dubious websites and wipe those often (like a raspberry?)
Careful what you execute on your machine
Then if you're really paranoid:
Some external firewall running suricata for alerting
Logging to an external system so you can review things in case of issues.
Re: Knock Knock Who's There? – An NSA VM
#4It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
Rootkits/exploits appear on any operating system. Wipe and reinstall often, rotate passwords at same time, also teaches good backups. ad blocker by default and always up to date system. Use VMs or other machines for dubious websites and wipe those often (like a raspberry?) Careful what you execute on your machine Then if you're really paranoid: Some external firewall running suricata for alerting Logging to an extern…
Re: Knock Knock Who's There? – An NSA VM
#5It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
Re: Knock Knock Who's There? – An NSA VM
#6Re: Knock Knock Who's There? – An NSA VM
#7It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
Re: Knock Knock Who's There? – An NSA VM
#8I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil?
Intelligence services are the worst terrorist organizations, and most people targeted by them are in fact very friendly persons. If only intelligence services dealt with the actual criminals and not revolutionaries, we wouldn't be having corruption and power abuse scandals every other week in all "developed" nations.
Re: Knock Knock Who's There? – An NSA VM
#9It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
So this was far more reaching than Windows.
To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you.
However, on reading this article my first thoughts are if this method evades detection by not having a listening port that a network scan or locally using ss/netstat can detect then perhaps you would still be able to benefit from egress filtering (only allowing outbound connections to things you need and blocking the rest). On a router most connections are through the router (FORWARD table) as opposed to directly locally originated and outbound (OUTPUT table).
Re: Knock Knock Who's There? – An NSA VM
#10> I made local presentations at 0xOpoSec and BSidesLisbon but those slides were never published for obvious reasons (aka live implants all over the Internet). I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil? Intelligence services are the worst terrorist organizations, and most people tar…