Black ops: how HBGary wrote backdoors for the government
arstechnica.com
arstechnica.com
I'm glad this whole thing has happened.
Apparently both companies are deep into fighting the war on terror, are they seriously pursuing business against U.S. citizens?
Always follow the money. The government is concerned about "cyber-security type things" and there will be no end of shady and less-shady firms willing to charge millions of dollars for providing whatever the government thinks it wants (which is probably not what it needs).
And as you pointed out these firms don't operate in a vacuum, they form networks. They compete with each other but also look for a possible strategic partnership if one comes along.
The real key is to recruit someone who retired from the military or from one of the 3-letter-agencies. (At least ask them to serve on the board). Just that right there nets you an enormous amount of projects. You thought big enterprise runs on golf-ware, but big government projects also run on friend-ware and friend-of-a-friend-ware. It is very much an incestuous family.
"I got this word doc linked off a dangler site for Al Qaeda peeps"
I find his choice of words there to be rather amusing.Interesting that these people brainwashed themselves and believe there are actually lots of Al Qaeda operatives out there hiding in the bushes, researching methods to kill their victims using fecal matter. These are the kinds of people who get lots of government money for "security" related projects...
It's possible such exploits don't exist, are misrepresented or were never in HBGary's possession. Exploits have a shelf life that degrades as other actors are likely to discover the same bug, maybe 6-18 months in general wisdom. But, it is always possible to claim you have a private cache and then buy them if/when they are needed.
Regardless, it seems anon got a SQL dump, root on a web server and a ticket box, and a google apps admin account - these aren't the types of places marketable vulnerabilities are usually kept.
I thought only black hats sat on exploits.
Windows installs a Plug and Play device and its driver automatically. http://www.microsoft.com/resources/documentation/windows/xp/...
A USB attack device could probably also emulate a hardware CD-ROM.
I wonder if they could emulate a crypto accelerator and actually use stock drivers with backdoored hardware?
Plug it in, makes the OS think it's a keyboard while the user thinks it's a USB stick.
I only know this because I watched an excellent video explaining the 0-day vulnerabilities that stuxnet used by Microsoft leet hax0r Bruce Dang.
Came up as the third result for "daemon" on Google. There's a lot I don't like about Google, but sometimes it just works.