At Facebook, zero-day exploits, backdoor code bring war games drill to life
arstechnica.com
arstechnica.com
The only way an attacker could have come across this URL would be if they had access to our codebase specifically - the string in the "extra_log" param was hardcoded in the PHP endpoint. It didn't even occur to me that they might have placed it there. Only when someone pointed out that this param was actually md5("october") did we start to wonder if it might be a drill.
The engineer's computer was compromised using a real zero-day exploit targeting an undisclosed piece of software.
What the diddly ding dong is Facebook doing with real 0-day exploits (besides using them in fire drills)? More importantly HOW did they get their hands on 0-day exploits? And what other exploits do they have/buy/finagle? Is it on a regular basis?I suspect it wasn't actually a "0-day" in that sense, but rather a disclosed but unpatched vulnerability, and described as "a real 0-day exploit" in the article because of the typical reduced fidelity of press articles.
So then next question, how come the vulnerability was unpatched?
Does that mean they used the discovery of the vulnerability as an opportunity to create the drill (as a "might as well use this" scenario) or was the drill planned with the 0-day and then the developer was notified?
Which came first here, the vulnerability or the plan for the excercise? I would imagine priority would be to patch the system rather than plan a drill, no?
Edit: mkjones says they bought the 0-day: https://news.ycombinator.com/item?id=5199757
I've seen 0days found by engineers at other tech companies, so I find it likely that somebody at Facebook could run across one if they tried.
But in terms of 0-day exploits, I believe there is a ready market for them if you know where to look, and are willing to pay.
P.S. I have a mustache. Enjoy! :)
For example: https://www.immunityinc.com/canvas-cep.shtml
This is standard practice for the industry and quite common. But do note that not all 0-days are created equal: a 0-day that effects 1000 users is 1000x the significance of one that effects only one user (with some notable exceptions). Also realize that 0-day is often used misleadingly - anything that was first used in the wild is a 0-day, even if that event was months ago, the vendor has been informed, and crucially - even if a patch has been issued by the vendor. Pentest firms often oversell their "0-days" in an effort to appear more advanced to their clients.
As the article noted, they started the whole drill relatively early in the morning on a workday (a Wednesday, iirc, which are the days where we do not have meetings). About half an hour after we'd fixed the obvious problem and were starting to dig deeper, the guys organizing the whole thing stepped in and let us know it was actually a drill, but that we were going to keep treating it as if it were real.
It actually ended up being a super interesting and eye-opening experience, and drove good changes to some of our infrastructure. I had no idea we'd go so far as buying a 0-day and using it to test our own systems and response, but I think it shows that we don't screw around when it comes to making sure we're secure.
Where did they get the 0-day?
If you don't know where to aquire (buy) 0-days, then you probably shouldn't know.
http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...
Sorry Ars but the term "Advanced Persistent Threat" was not coined in 2010. Businessweek was using the term in 2008[1] and that was hardly the first time it appears in the literature.
[1] http://www.businessweek.com/stories/2008-04-09/an-evolving-c...
Rest of world (including many governments) "we are not allowing use of Facebook for the intelligence threat it poses against our entire societies". Techy people: "Facebook isn't good for your privacy, internet users!"
Facebook PR puff piece: "Look, we take security very seriously, we even dumped some serious money on it!"
Bottom line: you can have great people but when you are such a high profile target holding the personal information of millions, it's not going to stop you from being abused or strong-armed by your host-government.
Fundamentally, centralization of anything to the level that Google or Facebook represent is a bad thing.
The Facebook story is about response to attack.
A little off-topic question - how do stories like this get reported (got picked-up by arstechnica)? This isn't some standard Press Release or entry in the companies' blog. Is it initiated by companies (FB in this case) themselves? Or is it the journalists constantly sniffing companies for such stories? It's something I've always been curious about coming across such stories. I am assuming there is standard PR practice for such things (for example I wonder how did that FBI e-mail snapshot got shared by arstechnica, despite the blurring and e-mail being ultimately set-up, there must be strict policies in terms of what to share and what not...) Someone please shed a light ~
Why so complicated? Zero-day exploit? After all, Facebook is not Iran's nuclear facility. And in case of large software companies social engineering is generally easier and more effective than zero-day exploits.
I'd suggest simulating more realistic attack by anonymous, with attempts to social-engineer facebook employees out of their pa.. laptops.
Facebook has on the order of a billion users. That's a huge cache of interesting content and access no matter how you slice it.
Spear phishing is a specifically targeted phishing attack that appear to come from a legitimate source... often one of authority within the targeted organization.[1]
1. http://searchsecurity.techtarget.com/definition/spear-phishi...
Also, Anonymous is far from the most sophisticated attacks a company like Facebook will see. They tend to stick to DDOS and easy SQL injections.
Are Facebook and Google critical functions?
I would have thought infrastructure is properly "critical", various websites not so.
- make up a fake security alert
- wait until a real attack is underway
Perhaps I'm missing something, but I do not see a connection to Office Space.