Vault 8 – Source code and analysis for CIA software projects
wikileaks.org
wikileaks.org
If you want an example of the kind of analytical techniques that people use for attribution in the US government and sophisticated industry groups, then refer to the Diamond Model of Intrusion Analysis: http://www.activeresponse.org/wp-content/uploads/2013/07/dia...
https://cdn.securelist.com/files/2017/10/Guerrero-Saade-Raiu...
It was on HN before, but it vanished quickly -
A self-signed certificate using the CN of a website which the target device may already connect to (assuming it has KAV) is useful for stealth as it allows your implant to blend into traffic more easily.
However, attributing an attack based on the CN of an invalid TLS certificate would be very silly, as literally anyone can generate one (Instructions for generating the self-signed certs are actually right there in the source bundle).
You don't need to look at a physical server to make these conclusions.
> just took the word of a campaign affiliated and funded company
Literally a company PAID to provide security.
The Company was PAID for remediation, to write an execute report, and to testify.
Why would you pay a private company versus the United States Government that would have much more man power and most likely free services?
You generally pay someone when you want a favorable outcome, isn't that Politics 101?
Here is a pretty interesting presentation from the Snowden leaks regarding attribution of Chinese CNE (Warning: TS/SI content): https://www.eff.org/files/2015/02/03/20150117-spiegel-byzant...
I was trying to be courteous to any readers with an active security clearance, as viewing such material may require them to report the incident.
> (U) Definition: Special Intelligence, or SI, Is a sensitive compartmented information (SCI) control system designed to protect technical and Intelligence Information derived from the monitoring of foreign communications signals by other than the intended recipients. The SI control system protects SI-derived Information and information relating to SI activities, capabilities, techniques, process and procedures.
Page 80 here: https://fas.org/sgp/othergov/intel/capco_reg_v6-0.pdf
"Evidence" doesn't have to be irrefutable to make it into a court of law (and the standards are far lower for the court of public opinion).
well, I say that constant hopes for transparency and the strides we take towards those goals will keep the United States high on the list of nations with decents human rights.
WL is one of those strides, and I think it's invaluable.
It's 'interesting' that given the muck that WL has raked up about the U.S. that anyone could be upset about their ( the US ) having been a target..
You would be naive to take for granted that WikiLeaks is acting exclusively out of principle.
That's where you're wrong. Wikileaks' mission is "transparency for governments and privacy for people". Perhaps they seem to have affinity for publishing things contrary to the US' interests and you're right that the US isn't uniquely bad at protecting human rights, but the US (and Western European sigint community) violates privacy on a scale that's simply unmatched, it's reasonable for them to treat the Anglosphere's sigint as their primary adversary.
I don't know, but I would be surprised of Russia even captured 1% of the data that the NSA captures routinely (or was capturing at the height of its excess).
Additionally, Russia seems to keep quiet about what they do which is lying by omission at worse. A lot of US security officials have lied under oath about what the US is doing - I think it's more important to expose active and direct and popular lies than incidental lies.
We now know that all comms implant to C2 are TLS with a unique (fake) certificate tree. They use unique, single use domains for operations. I don't believe there was enough information in vault 7 to identify IOC's that could be used for behavioural analysis. We also now know that the C2 fronting servers negotiate 'Client Cert optional', which is a fairly unique configuration item.
The git repo contains 3 binary builds of the client/server malware. I think this is more important for detection than their docs.
Regardless, its all public domain now.
What you're saying comes from the documentation included in the source, yes. But if you dig into the Confluence dump from back in March, you'll see that the User's Guide and Developer's Guide PDFs for Hive were attached to one of the wiki pages already, explaining how this all worked. It did not get any press attention as it was quite mundane compared to the more interesting leaked wiki pages, but I would really hope AV companies and others in infosec noticed this already.
/*
* Computing a "safe" DH-1024 prime can take a very
* long time, so a precomputed value is provided below.
* You may run dh_genprime to generate a new value.
*/
char *my_dhm_P =
"E4004C1F94182000103D883A448B3F80" \
"2CE4B44A83301270002C20D0321CFD00" \
"11CCEF784C26A400F43DFB901BCA7538" \
"F2C6B176001CF5A0FD16D2C48B1D0C1C" \
"F6AC8E1DA6BCC3B4E1F96B0564965300" \
"FFA1D0B601EB2800F489AA512C4B248C" \
"01F76949A60BB7F00A40B1EAB64BDD48" \
"E8A700D60B7F1200FA8E77B0A979DABF";You'll be able to find this same C̶I̶A̶ ̶b̶a̶c̶k̶d̶o̶o̶r̶ DH-1024 prime in tons of other projects:
https://github.com/mstorsjo/rtmpdump/blob/master/librtmp/rtm...
https://github.com/travelping/nattcp/blob/master/polarssl.c#...
elif str(beacon_hdr.os) == '40':
beacon_data['os'] = "MikroTik-MIPSBE"
elif str(beacon_hdr.os) == '41':
beacon_data['os'] = "MikroTik-MIPSLE"
elif str(beacon_hdr.os) == '42':
beacon_data['os'] = "MikroTik-x86"
elif str(beacon_hdr.os) == '43':
beacon_data['os'] = "MikroTik-PPC"I'm sure this time is just coincidence, too.
Can someone tell me if there's actual malfeasance this time or just more edgy moaning about the spy agency doing its job?
I'm happy to call out the security apparatus when it actually oversteps its bounds (Eg the Snowden leaks). But so far as I can tell wikileaks vault 7/8 isn't a leak in the public interest. Its just anti-American wankery.
I honestly wouldn't be too surprised if a lot of these applications were used today with relatively little change.
Author:User#142 Date: Fri Oct 30 09:58:22 2015 EDT User's Guide date corrections.
But the point is moot anyway: either their tools are still relevant today, in that case it's good to see what they can use against the people, or they are not, in which case it won't hurt them if we see them and it's not "anti american".
Why don't you read it and decide for yourself?
So what, that’s been wikileaks MO since day one. Assange has been very transparent about his intentions.
Read his essay from 2006 https://web.archive.org/web/20070129125831/http://iq.org/con...
Assuming you weren't involved in any of this, ask yourself: did I authorize it? Did the legitimate authority of my civil peers (to which I am willing to cede) authorize it? Did my representatives authorize it? (Not everyone in congress is on these top-secret commitiees, it's entirely possible that some action could be taken that the voters of an entire state had essentially zero say in.)
Finally,
What would happen if a cleared individual decided to take an action without asking anybody or telling anybody? You know, like Snowden, except not conscience-driven to make sure we all heard about it. It's not like established systems have ever suppressed secrets that would make them look bad if widely known, right? Right?
CIA or Wikileaks? CIA absolutely not, Wikileaks probably yes.
>Without oversight, how could they possibly be kept on the good side?
CIA is the foreign intelligence agency of a particularly murderous country, they can’t possibly be kept on the good side.
Wikileaks seems to have oversight built in that they need to be trustworthy enough for people to leak to them.
>Having gone so long without oversight, how far have they strayed?
CIA has a long history of doing terrible things, I doubt they’ve strayed too far from that.
>What would happen if a cleared individual decided to take an action without asking anybody or telling anybody?
What would happen if the sun came up in the morning? Things would probably be the same they were yesterday.
I (or we?) stand in one of the many countries where this threat is developing, but one of the few countries where our predecessors have secured the liberties for us to do something about it. So in this sense, we are the custodians of ourselves: and any true American would tend to their government while discussing with their countrymen how they can do the same.
(Hopefully that addresses your point, now that I see what you're really saying.)
In most countries, sadly the answer is still no.
And no, if you're from a country that's openly hostile to free speech, you really can't speak freely online without fear of reprisal. In an abstract sense I can't speak with a complete lack of fear of reprisal either - but essentially what I'm trying to exhort people to realize is that taking on the personal risk of saying the "wrong thing" in public is a civil duty: the civil duty of maintaining our government.
I have many questions but two are very high on my list:
1. one of the commit messages mentions merge from a git remote hosted at devlan.net. Who owns that host and is it a hidden CIA server or repurposed captured host?
https://wikileaks.org/vault8/document/hive-log/page-41/#pagi... Merge branch 'master' of ssh://stash.devlan.net:7999/hive/hive
https://www.whois.com/whois/devlan.net
It kinda looks like a captured host registered originally by a French admin.
2. Why Solaris? Microtik and the other router targets make sense in combination with generic Linux machines, but Solaris sticks out and there must be an interesting explanation for targeting that. What kind of internet facing Solaris hosts are out there or which orgs use it in such a capacity to become a target for the CIA?
2. <conjecture> Kaspersky ? </conjecture> + ISPs, universities, etc.
It must be an interesting life for the French admin of the "real" devlan.net since the leaks.
2. I don't get the Kaspersky reference. Can you explain?
ISP and University: I suppose you mean those would be running public Solaris hosts, right? And that therefore the CIA has been hiding on those servers. I sure would hate the CIA to spy on scientists, though it's not unheard of that one of the agencies knocks on a door of a scientist who just happened to be on the verge of publishing something they deem a risk. Happened in the past and sure still does. The imbalance and abuse of power is the problem and here it's legalized/constitutionalised. An agency can spy on my private life and professional work without being questioned, but we aren't allowed to demand a transparent administration or any of the many ranches of government.