Google Hack Attack Was Ultra Sophisticated, New Details Show
wired.com
wired.com
Chinese government has all the source code of Windows systems:
http://news.cnet.com/2100-1016_3-5083458.html
Including:
Windows Vista, Windows XP, Windows Server 2003, windows 2000, Windows CE 6.0/5.0/4.2(PSK), Microsoft Office Pro 2003, Microsoft Office Systems
It's reviewed by top three Chinese universities and other three government agencies.
The Party is the new overload of 0day farmer.
The irony is too rich.
1. Customized compilation result different address offsets thus an exploit is not very generic portable.
2. Everyone can do a static vulnerability scan for Linux source code, so if there is a hole it's more likely to be well known in the industry
Recently series of events with google.cn suggests that this is just a test ground for industrialized 0day farming for closed source software as a strategic weapon.
http://www.reddit.com/r/netsec/comments/app8q/_/c0issy7
The more you poke into it the more it looks like a full scale war
People with computer security talent founding security companies shouldn't be surprising, especially here of all places !
http://blogs.adobe.com/conversations/2010/01/no_evidence_to_...
most companies have offices in india, china. And even risking a moral point here, all companies have chinese employees.
Hell, when I worked for a shady company here [regret] most employees used to sell the email database.
what about the oposite? use employees to insert vulnerabilities instead of selling data.
Will anyone run `cvs blame` on the IE4 source code?
here's the follow up on that line of thought.
If you are a super-smart black-hat villain who wants to plan a mass global attack, what better place to start than with Google and Adobe's source code?
I wonder if Microsoft was targeted too.
For example having white-listed software only able to run (of course engineers need to install stuff all the time so they might have to be a different case, but joe bloggs shouldn't need anything new - it can be assessed by security before installing).
Indeed -- and especially their auto-upgrade mechanisms.
There may yet be more to Google's anger that's not yet been revealed. What if the attackers didn't just look around, but changed (or tried to change) Google content/code at the source?
Said my card was compromised, I called in and they said their systems were hacked and he gave the name and location of the system...
You might not know it, but sounds like BoA was compromised as well.
The article mentions that your average cybercriminal is lazy, and I can believe that - you're only going to put as much time in to an attack that you're going to get out in financial reward. But if a commercial hack was going to bring about the same financial-level of reward, I bet the cybercriminals wouldn't be sloppy.
Places like google have a high potential for a high payout, and they know it. Therefore the cybersecurity is higher, requiring a better caliber of criminal.
It still needed an employee to make the usual "install the dancing pigs"-style gaff while using IE6.
Also: Employees using IE6, inside Google, in 2010. Why weren't they using Chrome?
I guess they were testing something in IE6. Perhaps one of their own sites. Perhaps how some other site renders in it compared to Chrome. Who knows.
"Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6, Internet Explorer 7 and Internet Explorer 8 on supported editions of Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2 are affected."
http://www.microsoft.com/technet/security/advisory/979352.ms...
What do you even call that kind of disinformation? False flag doesn't seem to cut it.
The attack had originated from China, the company said.
From reading that, it's clear that the shellcode was obfuscated ('encrypting' it three times, though, would be unnecessary), but that's just a good way to muddle things up. Although from reading that it's obvious that it was a sophisticated attack in this day and age of cybercriminals who go for the easiest target available, nothing mentioned there hasn't been possible for almost any buffer overflow attack. Code obfuscation has been used for years for copy protection and to prevent static reverse engineering in general, and although nonstandard in exploitation, by no means unheard of. In my opinion a more impressive exploit would be one which used all printable ascii (which also is possible).
On a side note, some of the terms used are either misused or just wrong: although the payload may have been obfuscated, 'encryption' at least to me implies separate key/decryption schemes, which don't really work well from a shellcode point of view. You'd be better off using a static 'encryption' scheme like ROT13, but that seems more like obfuscation in this day and age, particularly since the code to deobfuscate it would have to be built in.
TL;DR: I think they throw around 'encryption' in places where it doesn't make sense to use it because it makes it sound scary, and it doesn't seem like any of the techniques used were 'new' or somehow more sophisticated then what was previously possible.
For simple IDS evasion, at least, so that you aren't throwing up flags: it could've been done to make forensics much harder.
In exploiting a remote system, which part of your attack would benefit from being encrypted?
There are all extremely advanced (but known) evasion steps for a very targeted attack. It's rare to see all of them successfully used in one attack because of the complexity and skill required.
Undercover agents were sent to Google Shanghai Office, cracked Gmail source code and get away with a 1 million RMB reward
Huh?
The last sentence is very poetic. I get the idea, but since I'm not Christian, I'm not so sure about the exact analogy. Anyway, the real meaning is that eventually freedom of speech will come to China, and at that time, we (the author and the Chinese people) will celebrate Google's return.
P.S. I cried a little bit after the paragraph. I guess I'm moved.
P.S. 2. Machine translating is never good at this kind of stuff... I'm native Chinese.
It's observable phenomenon that all Christian Chinese favor Google more than any other search engines.
Doesn't stop them though so the author may be one of those.
Was it like this?:
For example, there is a code which is encrypted three times. And that crypt-code by itself is executable which decrypts itself into another executable, and so on.
If this is true - I'm really impressed.
[Edit: added 2nd sentence.]
http://praetorianprefect.com/archives/2010/01/the-aurora-ie-...
-Google -Microsoft -Boeing -Intel -Cisco (imagine the value of their source code) -Apple -Any of the defense contractors etc.
I think we must assume that the source code for most major products is available on the black market.
Rackspace, Yahoo,Symantec,Northrop Grumman,Dow Chemical
If you, even within your general field (say mathematics), talk to an expert, he will easily give you arguments that will seem sophisticated to you, and simple to him. He's spent more time learning, getting familiar with, and thinking about those arguments, and that's the simple reason.
Here, the Chinese government is through a nationalistic sentiment endorsing hacking and education about the same. It is a large country, and many of the people conducting the attacks were not amateurs, using already established techniques. They were professionals, I wager, learning, getting familiar with, and thinking about how to attain their hacking-goals.
An educated person, in any subject, will seem infinitely more sophisticated than a non-educated one. And I argue that China, more than anybody else, invests into young men doing just that.
By walking in and trying to take what it viewed as Google's most valuable assets, the Chinese state signaled that Google would never win in China. The playing field wasn't just rigged by one or another forms of low-level favoritism. The state at a fairly high level had decided it was going to 'p0wn' all the competition. So at that point, it was pretty obvious Google had nothing to lose by leaving China and perhaps even more intellectual property to lose by staying.
I would imagine that while using encryption doesn't imply massive resources, developing custom encryption does.
But I know enough not to feel comfortable commenting on this in a public forum.
(Not trying to pass a value judgment on you, just suggesting a reason you guys might not be getting an answer to your question.)
why?
I'm guilty of reading the article
“The encryption was highly successful in obfuscating the attack and avoiding common detection methods,”
One of the malicious programs opened a remote backdoor to the computer, establishing an encrypted covert channel that masqueraded as an SSL connection to avoid detection
And yes, people will learn to break into systems without my help, and yes, openness is the best defense we have against these things. I've just decided I'm just not going to put anything out there that could possibly be used like that.
I tell you one of the reasons why: about twelve years ago, back in the Windows 3/95 days, I got a call from some stock brokers in New York. They wanted to know basically how to spy on their employees.
So I sketched out a system where software would take pictures of their desktops every few seconds -- this was a long time before such software ever existed. I also sketched out several ways you could keep the software from being detected.
I never knew if they wrote the system or what happened to my design, but it never sat well with me. I always wished I could have went back and not provided them with the information.
So now I don't do that anymore.
This is the least favourite part of my job too. I have a couple of uncomfortable memories from university days when I ran my mouth about some little ideas.
I'm pretty sure the bad guys aren't going to gain much by any vagues sketches of an approach that apparently requires a whole modern state to execute... The original is specific in points...
And there are zillions of reasons for people not to reply to my post. I know I'm not always that interesting...
This is the kind of scenario that gives security people nightmares. It takes VERY sophisticated processes and technology to find covert backdoors on your network, and very few places devote the manpower or $$$ to the effort.
(This is why I use Foxit for PDF reading, I don't have a PDF plugin enabled in my browser, PDFs download to disk, and similarly QuickTime, RealPlayer, WMP etc. plugins are all disabled, with only Flash enabled but controlled via FlashBlock.)
Would a company like Google really outsource the cleanup/forensics of an attack?
“The initial piece of code was shell code encrypted three times and that activated the exploit,” Alperovitch said. “Then it executed downloads from an external machine that dropped the first piece of binary on the host. That download was also encrypted. The encrypted binary packed itself into a couple of executables that were also encrypted.”
One of the malicious programs opened a remote backdoor to the computer, establishing an encrypted covert channel that masqueraded as an SSL connection to avoid detection. This allowed the attackers ongoing access to the computer and to use it as a “beachhead” into other parts of the network, Alperovitch said, to search for login credentials, intellectual property and whatever else they were seeking