Vigilante Hacks Government-Linked Cyberespionage Group
motherboard.vice.com
motherboard.vice.com
...custom 0day html script...?
Who is this guy? Batman?
Can anybody explain how an html 0day might be able to pwn a php file uploader?
That sounds terrifying... but at least I can be somewhat reassured that nobody is going to waste that on my wordpress installation...
[0] https://web.archive.org/web/20180508063705/http://5.61.27.15...
A nodejs based webshell is like 5 lines of code.
edit: imagine a URL like this: http://yourtarget.example.com/webshell?cmd=whoami
And that runs "whoami" on the target machine and returns the results.
So why would anyone assume that these are state sponsored hacker servers that were infiltrated then?
Is Vice supposedly left leaning? Isn’t one of their founders an alt-right Proudboy?
I mean really no citations except for what the individual provided them and some half-baked analysis that words from the kaspersky report were in what they received.
That line right there sounds like very much the propaganda the U.S. government has been pushing lately to convince people to support "hacking back." I've only heard government members promote this.
I guess this could be an operation where they try to make "hacking back" into something "heroes" (vigilantes) do.
E.g. the hack of the Gamma Group [1] was also purportedly carried out by a vigilante, who later published guides [2], [3] that also use the "hacking back" language. What are the odds?!
[1] https://arstechnica.com/tech-policy/2014/08/leaked-docs-show...
[2] http://pastebin.com/raw/cRYvK4jb
[3] http://shadow.systems/phineas-fishers-hackback-ii/
[4] HN discussion of [3]: https://news.ycombinator.com/item?id=11512845
But it could be easily explained by the fact the government uses the phrase constantly in the media. It’s not necessarily unexpected that two hackers would use them use the phrase when discussing the merits of, well, “hacking back.”
Been around the world and outside the US it’s almost all Android, pretty scary that malware is apparently becoming more prevalent.
Even without malware, Android needs to fix its permissions. What's the point in enforcing security policies on phones when a legitimate app, when given permission to, can read text messages on an employee's phone and send all the data to China? Businesses care about not having communications with customers leaked and Android is absolutely the wrong platform for that.
This sentiment seems to becoming more and more popular; I wonder if we'll see more vigilantes (which the person in the article purports to be) as a result.
Feels like a decent percentage of the population have lost faith in the government and rule of law.
Which to be fair, wouldn't exactly be a shocking belief where cybersecurity is concerned. The police and authorities rarely do anything effective against hackers, virus creators and other internet law breakers in general, in part because it requires a lot of resources to investigate someone/some group who might very well be on the other side of the planet and outside the victim's legal system. In that sense, I'm not surprised it's getting more popular.
Especially when it comes to the CFAA in the US.
Some basic precautions and common sense is all you need to avoid the CFAA.
"more and more popular," maybe not amongst the infosec community, but "more and more likely to make it to a vote in the years that have passed since the introduction of CFAA?" that seems possible to me.
1. https://tomgraves.house.gov/uploadedfiles/discussion_draft_a...