"Although these are old, they are classified as zero-day attacks because there is no solution."
They are?
"Although these are old, they are classified as zero-day attacks because there is no solution."
They are?
https://news.ycombinator.com/item?id=23929312
Both blog posts probably ended up on the front page and got quite a bit of attention because the words "0 day" and "tor" were used in close proximity, something the author is apparently very fond of doing (the posts are part of a series titled "Tor 0day").
1. purchase VPS products at a bunch of providers who accept bitcoin / crypto
2. ddos your target
3. see if you notice any of your hosted boxes go down
4. once you know the provider pop them (they're usually running some shitty WHMCS or similar homebrew solution, old Cpanel, etc. etc. and they're almost always resellers and amateurs) and move laterally to your target
When the feds do it against online drug markets (and they have been for years) they have the bonus of having decent network insight / view by working with backbone providers
There is just no way to hide multi-Gb of traffic
Checkout this project which is now being more widely deployed to prevent a lot of these attacks:
> TORAUTHPASSWORD - Password which is used for your Tor Control Port Authentication with NGINX. Alphanumeric without spaces (example: passwordIcanremembertyping)
> KEY - Alphanumeric Key for the shared front session key. Random between 64-128 would do fine. (example: isthis64charactorsalreadyicantbelieveitwowsocoolwaitnotyetohdarn)
Good overview of threats.
I would definitely see this under the umbrella of various secret agencies, especially those with an "offensive" position in cyber-warfare.
You won't ever see any of this documented due to the "parallel construction" method. And for what it's worth, almost all of the Wikipedia content on that one (https://en.wikipedia.org/wiki/Parallel_construction) deals with DEA usage of this.
Besides, the general way of "hacking services to distribute malware" has already been done, most famously in 2013 when the feds burned a Firefox 0-day to unmask a child porn ring: https://krebsonsecurity.com/2013/08/firefox-zero-day-used-in...
https://en.wikipedia.org/wiki/Network_Investigative_Techniqu...
https://www.eff.org/pages/playpen-cases-frequently-asked-que...
A DoS attack is nothing to these people. The only difference between them and cybercriminals is the fact the law legitimizes their work.
Tor is a tool like any other. It has certain strengths and certain weaknesses. When you're evaluating any security product you always have to determine if the security properties the tool provides match up with the security properties you need. Tor is no different.
https://blog.torproject.org/announcing-vanguards-add-onion-s...
We struggled to find a commonly accepted term for vulnerabilities at this stage of their life cycle, but we finally settled on n-day vulnerability. This term have been relatively well accepted by the vulnerability research community.
The exact length of this period is completely dependent on the velocity of the community to adopt a mitigation such as a patch. Heartbleed and Shellshock had been massively mitigated in a matter of days or weeks, but EternalBlue based-attacks still caught a lot of production systems off-guard more than a year after its disclosure.
A zero day starts with it's exploit or public disclosure and ends with a released patch. It's not a zero day for private disclosure.
Edited based on child comment about clarity
If I find an RCE in Cisco IOS and report it Cisco, who sits on it for a few dozen months, and you later find the same RCE and circulate it amongst your friends, who exploit it, your friends are exploiting a zero-day vulnerability.
I feel like in common parlance calling something a 0-day would imply that it is something the manufacturer didn't expect and has no solution for which is a big problem. I guess whatever communicates information best. I kind of feel like we just use 0-day to mean big problems, everything else is just a bug that has some age, and then fixed stuff doesn't get remembered. Right?
That seems fairly useful, at least in communicating to the general tech media.
Zero days are known, exploited and used all the time by all sorts of black hats, govt institutions etc.
Which was/is more relevant when commercial software is updated at most once ever year or two
But it appears no one can agree anymore, making the term useless.
It was years later that a "0day" went from a copy protection removal/crack ("0day warez") to its more general modern usage in computer security.
See: https://www.google.com/books/edition/_/8ETRQhDytIsC?hl=en&gb...
It's a useful distinction. 0-days are special because your target has no idea such a vulnerability even exists. This makes them very different than known but still unpatched vulnerabilities.
For example, if you're running some ancient mailing list software that you know has an unpatched XSS vulnerability, you can have your front end servers scan for attempts to exploit that and abort the requests. Or lock it down with a CSP policy. Or if you know your image manipulation library has tons of vulnerabilities, you could run it in a locked-down sandboxed environment where exploitation doesn't get the attacker much of anything.