Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

BeOSPOS posted:

what's ccne?

this whole ordeal is sounding more like a spy novel :hchatter:

Counter Computer Network Exploitation (literally identifying the command and control servers of identified malware and then hacking those)

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



kalstrams posted:

oooh i see, i missed the background that now they bombed it

yeah for the 2016 census they turned down upstream DDoS and instead just decided that they would block any connections from IPs outside australia. this lasted as long as you'd expect and they still got owned multiple times.

cinci zoo sniper
Mar 15, 2013




cheese-cube posted:

yeah for the 2016 census they turned down upstream DDoS and instead just decided that they would block any connections from IPs outside australia. this lasted as long as you'd expect and they still got owned multiple times.
:rip: 'straya

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
so it looks like one of the exploits from the eqgrp leak actually pops ASAs: https://xorcatt.wordpress.com/2016/08/16/equationgroup-tool-leak-extrabacon-demo/

Pile Of Garbage
May 28, 2007



computer molester posted:

so it looks like one of the exploits from the eqgrp leak actually pops ASAs: https://xorcatt.wordpress.com/2016/08/16/equationgroup-tool-leak-extrabacon-demo/

apparently you need SNMP read and SSH/telnet access so any properly configured device in a properly designed network will be fine.

so yeah game over man

e: vvv yeah my bad sorry dude vvv

Pile Of Garbage fucked around with this message at 15:43 on Aug 16, 2016

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

cheese-cube posted:

apparently you need SNMP read and SSH/telnet access so any properly configured device in a properly designed network will be fine.

so yeah game over man

that's not why i posted this- it gives credence to the theory that this is a legit leak

surebet
Jan 10, 2013

avatar
specialist


surebet posted:

anyone know the best way to print an ida gdl graph? google says graph-easy but it's been a literal decade since i touched perl

anyone? i've been looking for an excuse to print something on the 60" laser plotter in the marketing department

fins
May 31, 2011

Floss Finder

surebet posted:

anyone? i've been looking for an excuse to print something on the 60" laser plotter in the marketing department

ida:
code:
ProduceCallGdl
graph-easy
code:
graph-easy graph.gdl graph.pdf
-> print?

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

Captain Foo posted:

snowden talkin on tweetz0r that the equation group hack is likely russians demonstrating CCNE in order to show that they can prove U.S. responsibility of any attacks sourcing from that server, which he speculates is now being made more public in order to halt escalation of attribution in the DNC hack
yea this is worth reading, here's the text

quote:

The hack of an NSA malware staging server is not unprecedented, but the publication of the take is. Here's what you need to know: (1/x)
1) NSA traces and targets malware C2 servers in a practice called Counter Computer Network Exploitation, or CCNE. So do our rivals.
2) NSA is often lurking undetected for years on the C2 and ORBs (proxy hops) of state hackers. This is how we follow their operations.
3) This is how we steal their rivals' hacking tools and reverse-engineer them to create "fingerprints" to help us detect them in the future.
4) Here's where it gets interesting: the NSA is not made of magic. Our rivals do the same thing to us -- and occasionally succeed.
5) Knowing this, NSA's hackers (TAO) are told not to leave their hack tools ("binaries") on the server after an op. But people get lazy.
6) What's new? NSA malware staging servers getting hacked by a rival is not new. A rival publicly demonstrating they have done so is.
7) Why did they do it? No one knows, but I suspect this is more diplomacy than intelligence, related to the escalation around the DNC hack.
8) Circumstantial evidence and conventional wisdom indicates Russian responsibility. Here's why that is significant:
9) This leak is likely a warning that someone can prove US responsibility for any attacks that originated from this malware server.
10) That could have significant foreign policy consequences. Particularly if any of those operations targeted US allies.
11) Particularly if any of those operations targeted elections.
12) Accordingly, this may be an effort to influence the calculus of decision-makers wondering how sharply to respond to the DNC hacks.
13) TL;DR: This leak looks like a somebody sending a message that an escalation in the attribution game could get messy fast.
Bonus: When I came forward, NSA would have migrated offensive operations to new servers as a precaution - it's cheap and easy. So? So...
The undetected hacker squatting on this NSA server lost access in June 2013. Rare public data point on the positive results of the leak.
You're welcome, @NSAGov. Lots of love.

hobbesmaster
Jan 28, 2008

cold war II: cyber punk edition looking good

Pile Of Garbage
May 28, 2007



man the nsa sucks if they are fielding tools which don't automatically dispose of themselves

Shame Boy
Mar 2, 2010

surebet posted:

anyone? i've been looking for an excuse to print something on the 60" laser plotter in the marketing department

ida know :v:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

hobbesmaster posted:

cold war II: wizard punk edition looking good

yeah i am completely enamored with the idea that cold war 2 is fought with the press instead of violence, just like how it's actually really unironically nice that the us and israel hosed up iran's centrifuges with stuxnet instead of explosives

watch die hard 4 all you want (hopefully this is zero times) but wizardwar is much better than the alternatives

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
don't worry, i'm sure there are gonna be plenty of small-scale proxy wars for superpowers to have a pissing match over in the future

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

yeah i am completely enamored with the idea that cold war 2 is fought with the press instead of violence, just like how it's actually really unironically nice that the us and israel hosed up iran's centrifuges with stuxnet instead of explosives

watch die hard 4 all you want (hopefully this is zero times) but wizardwar is much better than the alternatives

yes i too can't wait for our national power grid to go down because some russian oligarch thought John Kerry wasn't nice enough to him at a diplomatic dinner

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Parallel Paraplegic posted:

yes i too can't wait for our national power grid to go down because some russian oligarch thought John Kerry wasn't nice enough to him at a diplomatic dinner

in most cases dealing with a power grid going down due to a network compromise is much easier to recover from than a missile hitting a key substation, power plant, or what have you

also to take down the electricity of the entire continent (canada and united states share grids), it would be impressive being that it's mapped out like this:



you have four power grids to go after and when the last big power grid downtime occurred, it only affected the american northeast and ontario

in other news:
https://lkml.org/lkml/2016/8/15/445

quote:

From <>
Subject Fake Linus Torvalds' Key Found in the Wild, No More Short-IDs.
Date Mon, 15 Aug 2016 15:34:01 +0000 (UTC)

It was well-known that PGP is vulnerable to short-ID collisions,
and many experiments were done to demonstrate that. [0]

Nevertheless, real attacks started in June, some developers found
their fake keys with same name, email, and even "same" fake signatures
by more fake keys in the wild, on the keyservers. [1]

All these keys have same short-IDs, created by collision attacks, led
with some discussions about the danger of short-IDs. Now, it is worth
to mention this issue again, since fake keys of Linus Torvalds, Greg Kroah-Hartman,
and other kernel devs are found in the wild recently.

> We don't know who is behind this, or what his purpose is. We just know this
> looks very evil.

Search Result of 0x00411886: https://pgp.mit.edu/pks/lookup?search=0x00411886&op=index
Fake Linus Torvalds: 0F6A 1465 32D8 69AE E438 F74B 6211 AA3B [0041 1886]
Real Linus Torvalds: ABAF 11C6 5A29 70B1 30AB E3C4 79BE 3E43 [0041 1886]

Search Result of 0x6092693E: https://pgp.mit.edu/pks/lookup?search=0x6092693E&op=index
Fake Greg Kroah-Hartman: 497C 48CE 16B9 26E9 3F49 6301 2736 5DEA [6092 693E]
Real Greg Kroah-Hartman: 647F 2865 4894 E3BD 4571 99BE 38DB BDC8 [6092 693E]

Everyone,
> In short, that cutting a fingerprint in order to get a (32- or 64-bit) short
> key ID is the worst of all worlds, and we should rather target either always
> showing full fingerprints, or not showing it at all
> (and leaving all the crypto-checking bits to be done by the software, as comparing
> 160-bit strings is not natural for us humans). - Gunnar Wolf

DO NOT TRUST ANYTHING SHORTER THAN THE FINGERPRINTS.

DrPossum
May 15, 2004

i am not a surgeon

Cocoa Crispies posted:

watch die hard 4 all you want (hopefully this is zero times) but wizardwar is much better than the alternatives



lol if you aren't living this dream already

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Parallel Paraplegic posted:

yes i too can't wait for our national power grid to go down because some russian oligarch thought John Kerry wasn't nice enough to him at a diplomatic dinner

that's more something the uk has to worry about, the us power grid is nowhere near integrated enough for it to be a problem.

ate shit on live tv
Feb 15, 2004

by Azathoth

I love this tweet, because of the people that are mad about it.

to be clear though, julian assuange is garbage.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

BeOSPOS posted:

what's ccne?

this whole ordeal is sounding more like a spy novel :hchatter:

it's downright cyberpunk

like, forget for a moment how lame cyberspace turned out to be in reality. we have two cyberarmies, and not just any two random cyberarmies but usa vs russia, we have cyberweapons that hack each other, cyber interference in a foreign country's elections, even untraceable cybermoney. all of which commented in real-time in cyberspace's stream of consciousness (twitter)

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

hackbunny posted:

it's downright cyberpunk

like, forget for a moment how lame cyberspace turned out to be in reality. we have two cyberarmies, and not just any two random cyberarmies but usa vs russia, we have cyberweapons that hack each other, cyber interference in a foreign country's elections, even untraceable cybermoney. all of which commented in real-time in cyberspace's stream of consciousness (twitter)

spankmeister
Jun 15, 2008






hackbunny posted:

it's downright cyberpunk

like, forget for a moment how lame cyberspace turned out to be in reality. we have two cyberarmies, and not just any two random cyberarmies but usa vs russia, we have cyberweapons that hack each other, cyber interference in a foreign country's elections, even untraceable cybermoney. all of which commented in real-time in cyberspace's stream of consciousness (twitter)

yeah it owns p hard


also usa russa but also china (and iran to a lesser extent)

hobbesmaster
Jan 28, 2008

hackbunny posted:

it's downright cyberpunk

like, forget for a moment how lame cyberspace turned out to be in reality. we have two cyberarmies, and not just any two random cyberarmies but usa vs russia, we have cyberweapons that hack each other, cyber interference in a foreign country's elections, even untraceable cybermoney. all of which commented in real-time in cyberspace's stream of consciousness (twitter)

still waiting on deus ex like augments

Shame Boy
Mar 2, 2010

fishmech posted:

that's more something the uk has to worry about, the us power grid is nowhere near integrated enough for it to be a problem.

integrated with the internet or integrated with itself? because i love reading the postmortem write-ups of massive blackouts and they're always like "2:35 AM - 500kV line 1 sags into tree and breaker trips" "2:35:30 AM - 500kV line 2 overloads due to increased stress from line one being down" ... "2:40 AM - entire new york regional grid initiates isolation protocol disconnecting itself from the rest of the country" etc

not integrated with the internet is believable though

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av
and let's not forget that this year this happened:

spankmeister
Jun 15, 2008






hackbunny posted:

and let's not forget that this year this happened:



I was there, ground zero man.

ate shit on live tv
Feb 15, 2004

by Azathoth

hackbunny posted:

and let's not forget that this year this happened:



What was this? I assume a power outage?

spankmeister
Jun 15, 2008






Powercrazy posted:

What was this? I assume a power outage?

DARPA Wizard Grand Challenge

Machines doing binary exploitation in an attack/defend CTF scenario. Very cool.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

hobbesmaster posted:

still waiting on deus ex like augments

cyberpunk literature was way too optimistic about man machine interfaces, basically in 30 years the only innovation in the field was multi-touch interfaces. that's a far cry from "jacking in". everything else is still the same as back then except faster or smaller or both

I think they figured computers wouldn't get much faster and you'd have to wire brains into the network to get anything serious done, with all the cool poo poo that comes with it (like wagering your sanity as opposed to just your dignity, and cool drugs). but computers did get much faster, to the point we now use cray-like supercomputers to animate anime tiddies, but we still can't touch those anime tiddies except in the vaguest sense

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Also the fact that we have a combination mondo computer / camera / telephone / gps in our pockets at all times

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Parallel Paraplegic posted:

integrated with the internet or integrated with itself? because i love reading the postmortem write-ups of massive blackouts and they're always like "2:35 AM - 500kV line 1 sags into tree and breaker trips" "2:35:30 AM - 500kV line 2 overloads due to increased stress from line one being down" ... "2:40 AM - entire new york regional grid initiates isolation protocol disconnecting itself from the rest of the country" etc

not integrated with the internet is believable though

integrated with itself dude. like you just described why they can't take down the whole country's grid, things like that would at most take out a couple of states and a canadian province while everything else automatically separates itself for protection, and that's beyond the fact that there's even greater separation between the various over-regions

it would suck and be annoying, but it's stuff that every major city and business has contingency plans for.

although yes, separately, a ton of stuff isn't really internet accessible, so if russia wants to shut it down they're going to need to have a guy that can go do it physically in person.

hackbunny
Jul 22, 2007

I haven't been on SA for years but the person who gave me my previous av as a joke felt guilty for doing so and decided to get me a non-shitty av

Captain Foo posted:

Also the fact that we have a combination mondo computer / camera / telephone / gps in our pockets at all times

and in typical lame real world fashion they don't do anything cool, they're mostly terminals for mainframes buried somewhere, and all their power goes into animating anime tiddies or the moral sfw equivalent. cyberpunk as written by douglas adams

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

fishmech posted:

that's more something the uk has to worry about, the us power grid is nowhere near integrated enough for it to be a problem.

if russia want our power grid to go down all they need to do is wait for a cold winte and jack the gas (natural gas, not gasoline) price up again.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
honestly the easiest way to gently caress up things for an entire continent is to "accidentally" have a ship drop anchor where it shouldn't. figure out where new york and london have the least amount of latency on which fibre line and you can make everything go sideways for a period of time

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

OSI bean dip posted:

honestly the easiest way to gently caress up things for an entire continent is to "accidentally" have a ship drop anchor where it shouldn't. figure out where new york and london have the least amount of latency on which fibre line and you can make everything go sideways for a period of time

pretty sure that's hibernia atlantic's 2012 cable between halifax and somerset, england

moonshine is......
Feb 21, 2007

Someone commented on the english being all messed up in this shadowbrokers thing. Wouldn't that make sense because there's no way you want anyone doing any stylometry on it? So run it through google translate a couple times.

gonadic io
Feb 16, 2011

>>=

moonshine is...... posted:

Someone commented on the english being all messed up in this shadowbrokers thing. Wouldn't that make sense because there's no way you want anyone doing any stylometry on it? So run it through google translate a couple times.

*nsa secretly subpoenas for all of google's translate logs*

ate shit on live tv
Feb 15, 2004

by Azathoth

moonshine is...... posted:

Someone commented on the english being all messed up in this shadowbrokers thing. Wouldn't that make sense because there's no way you want anyone doing any stylometry on it? So run it through google translate a couple times.

Surely there is a better way to achieve that effect then language translation? Though I have no idea tbqh. I mean even just using a thesaurus to choose archaeic/ambiguous words.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Powercrazy posted:

Surely there is a better way to achieve that effect then language translation? Though I have no idea tbqh. I mean even just using a thesaurus to choose archaeic/ambiguous words.

one person writes release, another edits it without their approval/input and so on until you have a mishmash of multiple different writing styles/voices?

Adbot
ADBOT LOVES YOU

flakeloaf
Feb 26, 2003

Still better than android clock

and thus "military writing" was born

  • Locked thread