Leaked Hacking Team code to edit browser history?
github.com
github.com
I think it is rather cheeky (and dangerous) to accuse companies of doing such horrible stuff, when all we have is a few leaks (without context) to go on.
See for instance: https://github.com/hackedteam/rcs-common/blob/master/lib/rcs... which generates test keystrokes, test users and test programs for chat. The file names of the "planted" evidence is far too obvious, and they generate a hash for it. In short there is nothing in this code that implies this is used to plant evidence.
Even if they have a terrible track record, this code implies nothing that they are currently accused of. It is not like the code is heavily obfuscated or missing other parts. Let's not forget these leaks were "planted" too and we have no idea about its integrity.
Any tool you can use to upload files on a remote system can be used for that. Hacking Team's tools certainly allow that but I very much doubt they have a tool specialized for planting child porn/evidence on a computer.
But then... we're so used of seeing child porn used as a straw man to increase surveillance that's it's pretty fun to see it used against one of the companies making tools to help with said surveillance. Even if it's wrong.
I'm not saying it was intended to happen like this but it is sad it did.
I never did any Ruby but what I understands from it is that it take the process argument (if null, it take one at random from that array, seems like default values to test, bad idea but nothing that seems to be their only purpose as that argument is way more useful), it then take path argument (again same stuff with possible default values), the size argument (again but 123456789 as default) and write all that into a string including the current timestamp, which I guess is then added to a file.
As far as I know, there's no standard way to serialize browser history and I doubt it would contains the process and the size of the file.
There's another method that do that in reverse, I guess to then parse that same string.
If I had a guess, I would say that this the part that serialize/deserialize log information from evidence gathering (the actual gathering would happen elsewhere, which I can't find right now, and would call that module to serialize it).
You can find the actual evidence gathering on the clients like in this file, where it's also enriched with metadata and encoded the same way the ruby script does (at least to me, not a c++ programmer, it seems to be the case). https://github.com/hackedteam/soldier-win/blob/master/Soldie...
Also, while there are plenty of functions for getting data from the target device like `URL_GetBrowserHistory` there are as far i can tell, no obvious equivalents for putting them.
While no doubt, this works very well for industrial espionage and probably against journalists, I have a hard time believing, that it works well against actual criminals who must expect beeing targeted all the time. Or am I overestimating the tech savviness of modern criminals?
All assuming the agencies are not messing heavily with the whole network at the same time, which i think is pretty dependent on the country it is used in.
The RCS software from Hacking Team is basically a Remote Access Trojan, right? As it says in the description:
"It is a tool for taking control of the endpoints, that is, the PCs" [0]
So they already have control over the system and are probably able to down- and upload whatever they want.
Isn't that a feature in all the "Lawful Intercept" tools? The only assurance that they don't upload incriminating stuff is their word. Or is the CP code snippet such a strong trigger?
[0]: https://wikileaks.org/spyfiles/files/0/31_200810-ISS-PRG-HAC...
If this code is ever verified, it seems like it could turn the verdict on some CP cases.
https://github.com/hackedteam/rcs-common/blob/38290d4eab2b2c...
Note that you can press "y" after clicking a line to expand the link. This just includes the commit hash so that if this file is modified in the future the link will still point to the same place.
Now ive never tried it myself, but i cant imagine theres much(if any), security on a history?
And I think this will remain true in many countries.
[1] http://www.usatoday.com/story/news/nation/2012/11/25/casey-a...