CBS confirms reporter Sharyl Attkisson’s computer breached
washingtonpost.com
washingtonpost.com
A couple days later as I was working, my cursor kept getting pulled away from me and I figured there must be some tracking issue with the mouse, not giving it a second thought.
I started reading something at my desk and looked up - a tab had been opened in Chrome to some .ru domain name and someone was clicking a 'Pay with PayPal' link on the page.
With my PayPal password auto-filled, they would have had easy work of getting into my account to pay a large, arbitrary amount to themselves.
Luckily, I caught it just in time. They were so good at keeping control of the mouse that I had to run to unplug my router.
Point is, VNC is a really easy vector to gain access to a computer and there are apparently people or bot constantly port scanning everything to find what's unsecured.
Was definitely a wake up call for me and I wouldn't be surprised if this is a similar case.
This would not happen behind any home router I know of with UPnP disabled, unless you have malware on the machine.
Note: as was pointed out downthread, I'm being sloppy; CBS "detected" them.
Doesn't sound so dumb to me. Specifically removing data and then covering up traces of being there - sounds a little more than a 'script-bound teenager'.
And now, in light of NSA/PRISM - we have a good suspect is in a case like this. At the very least, there is grounds here to issue a suponea to the NSA since they should have plenty of data about her internet connection that could help in determining the responsible party.
Teenagers had rootkits that swapped out system libraries to hide processes and binaries back in 1996. The very, very lame teenagers had utmp and wtmp editors to "cover up their traces".
It's worth taking a moment to examine your thought processes here. "Now, in light of NSA/PRISM, we have a good suspect"? We clearly do not.
And yes, if "the NSA" were to break in it's possible they might not be able to do it tracelessly. E.g. no one as of yet is suspecting a black bag job.
Have you read the news man? Everybody should have a bias to blaming the NSA for breaking into journalist laptops! Geez, they have motives and the means.
I can also imagine that an investigative journalist, whose livelihood is made in part based upon tips received from people external to the newsroom, might easily become a target for a spear phishing attack from any of those potential actors.
But to immediately attribute this to the NSA strictly based on the facts laid down in this article, that seems like making a heavy use of a Jump to Conclusions Mat.
I'm assuming other state actors (the DoJ currently is saying "Not to our knowledge"), or someone attacking for political motives but not a formal state actor.
I believe "someone attacking for political motives but not a formal state actor" is the second most likely scenario, after "laptop was randomly popped by a drive-by Java or Flash vulnerability and WaPo wants it to be more newsworthy than it is".
I sound cynical about news organizations here, but I'm not. I just think they suck at reporting on computer security stories.
She's a CBS reporter, CBS is reporting this analysis, and they're the ones who hired whomever did the forensic analysis. Here it is from the horse's mouth:
http://www.cbsnews.com/8301-201_162-57589367/cbs-news-confir...
Case in point: JSOC developed their own intelligence capability that was a rival to that of the CIA and used it for their own purposes. That was one of the things that the DoD did that seems to replicate a capability available elsewhere in the USG and almost entirely for the purpose of escaping oversight.
BTW, Jeremy Scahill (author of Blackwater and Dirty Wars) reported that HIS laptop was hacked. When you combine this with the surveillance of AP reporters and it does seem that certain parts of the USG seem to feel that journalists are worthy and legitimate intelligence targets.
If these were claims about the relative performance of programming language runtimes, we'd be 1000 comments deep into a massive debate thread.
We have the AP having their phone records pulled.
You don't think there is a little there to be worried about? Do you think the Chinese have anything to gain from hacking a reporter's laptop?
Occam's razor man. Learn it.
I have a hard time believing any sort of script kiddy would risk major jail time and a high profile arrest for hacking into a journalists laptop for no profit.
The NSA/Gubberment however, does have quite a bit to gain from this information/deletion
Then you don't pay attention to script kiddies.
If that is the case, could this problem be solve by installing linux? I am not a linux fan, but the point of the source code being open and review by millions of people starts making me feeling more secure.
NSA does not need Microsoft's help to break into computers.
"National Security Administration doesn't need Microsoft to break into computers." vs "The National Security Administration doesn't need Microsoft to break into computers."
Too much of a tangent, perhaps?
I did enough research to conclude that it was not a settled issue. Its clear that if the initials were lower case and referred to a generic agency that deals with national security it would be "the national security agency" similar to the "the fishing tackle section of a sporting goods store." On the other hand a gander at DoD's style guide[1] makes it clear that they do not like the "the."
I'd love to see why you think its opposite. That's not dickish, that's a desire to answer a question that's been nagging me for a long time.
[1] http://www.dtic.mil/whs/directives/corres/writing/Writing_St...
From the english.SX:
"Is it proper to use “the” before the name of a government organization?" http://english.stackexchange.com/questions/76976/is-it-prope...
"Using the definite article with acronyms and initialisms" http://english.stackexchange.com/questions/30596/using-the-d...
"Definite article with proper nouns, titles followed by a common noun" http://english.stackexchange.com/questions/2327/definite-art...
"The definite article usage with objects that have names" http://english.stackexchange.com/questions/16988/the-definit...
"Capitalising the definite article in names" http://english.stackexchange.com/questions/84288/capitalisin...
Similarly, "the Department of Defense", "the National Security Agency".
Don't believe it? See what the agency calls itself on its website: http://www.nsa.gov/
Though I do not think this story has anything to do with MAPP.
MAPP or no MAPP, Microsoft does not have the technical capability to produce reliable exploits for all of the vulnerabilities it's made aware of.
Also, we both know NSA has a (less-well-known) charter for coordinating vulnerability response and computer security across the agencies; NSA has a public huge defensive interest in this stuff as well.
NSA doesn't need Microsoft to enable it to break into arbitrary Windows machines. But it might need their help to keep up with every attack vector on Microsoft code, which is what you need to do if you're doing defensive work.
http://www.techdirt.com/articles/20130614/02110223467/micros...
I'm not at all sure Linux is the solution; the only plausible culprit for whom that would be a barrier is a non-state actor doing a modern variety of "Will no one rid me of this turbulent priest" (http://en.wikipedia.org/wiki/Thomas_Becket). But the reported sophistication of the attack makes that less likely that previously speculated, and I assume that "Linux" is not a high enough barrier to a state actor.
It's the setup I'm using now.
If not, you're subject to a "black bag" job that could easily bypass all your protections, e.g. a physical key logger that would pick up your password/pass phrase that unlocks your disk encryption so you can use it.
Otherwise, do you surf the net from it? I don't take all your precautions, but I do run my browsers in a dedicated VM that has limited access to the rest of my infrastructure.
Pretty much. It's a single user MacBook Air, and I carry it with me at all times, never leaving it out or in the open, or even at home. For suspicious individuals, the CIA can obtain a warrant without notifying the individual, and search his/her apartment/home at convenient times when away, so I never leave it at home, either.
It's pretty much the only computing device I have that has highly sensitive data on it. I don't really care if they take my Kindle Fire; the only stuff on that is books and personal email.
It doesn't really matter, because I've also set up a randomizing encryption passcode generator that only works with a synthetic amino acid solution that corresponds to my genome that I carry in a vial around my neck. If under duress, all I have to do is break the vial, and the system will be impenetrable. I also have another sample of the synthesis in my home, but government people can only access it with a warrant -- which they probably won't have.
If you assume the OS is Windows, is it normal to even log those?
Commands entered by that user, in a shell, assuming the shell's history file wasn't cleared. So maybe you'd get a history of what someone did if they sat down at your computer and typed things while you were away refilling your coffee.
Your shell history isn't going to show a trace if someone actually remotely roots your computer and starts executing commands.
sudo su
and accessing a shell history should do the trick, right? Please correct me if I'm wrong.But if someone's used a privilege escalation method on some vulnerable software and injects code that makes system() calls as the root user, that's not going to show up in root's shell history.
Shell history is just a convenience for the user typing things in the shell; it doesn't log everything that goes on in the box as that given user, and isn't an audit trail.
Other possibilities:
1) A script file containing a list of commands was recovered during forensics, which did something obvious like search for something and delete. This is common for automated attacks, and seems unlikely for a targeted attack.
2) "Commands" is being interpreted too literally. They could have observed that files were deleted, and consider the act of deletion to be a "command". You can't really take technical reporting from mainstream media to be that accurate.
powercfg -lastwake
"Computer waking up" is meaningless without controlling for updates and other factors, including dog/cat/mouse bumping into a mouse cable.