3 ms·
From the text, it is pretty clear he wants people to think he's from Russia. From this I conclude two things: 1. He's not Russian. 2. This a good hacker but a
by s_q_b 10y ago
From the text, it is pretty clear he wants people to think he's from Russia. From this I conclude two things:
1. He's not Russian.
2. This a good hacker but an amateur at OPSEC.
- iondream 10y agohe may not be so good. they could be using very old operating systems. I believe the NY subway is running OS2 and win xp.
- rincebrain 10y ago[1] says Windows 2000, and whatever version of Flash ran on there, so...shooting fish in a barrel? [1] - https://news.ycombinator.com/item?id=13051310 https://news.ycombinator.com/item?id=13051310
- s_q_b 10y agoThe most secure voting machine certified in my county runs Android Jelly Bean from 2012. It's fish in barrels all the way down...
- rincebrain 10y agoAs much fun as Android is, I don't _think_ there's any public RCEs that recent, while I can think of a couple of recent Windows XP+ RCEs that are probably also doable-but-unpatched on Win2k: [1] - https://www.cvedetails.com/cve/CVE-2013-3175/ https://www.cvedetails.com/cve/CVE-2013-3175/ [2] - https://www.cvedetails.com/cve/CVE-2012-1852/ https://www.cvedetails.com/cve/CVE-2012-1852/ [3] - https://www.cvedetails.com/cve/CVE-2012-0173/ https://www.cvedetails.com/cve/CVE-2012-0173/ [4] - https://www.cvedetails.com/cve/CVE-2012-0002/ https://www.cvedetails.com/cve/CVE-2012-0002/ (Those were just the ones I quickly found that allow RCE on XP SP2 (the oldest thing that they still provided patches for, so most likely to be shared code with Win2k) without requiring active interaction on the target's behalf, e.g. not including "convince target to open X malformed file, receive payload")
- s_q_b 10y agoWell, the most common voting machines are iVotronics from ten years ago, which are pretty laughable. Dr. Appel at Princeton already hacked these systems back in 2006. There's even a flash card on the top of the machine, which even the state's hand-picked pen tester had to admit could be accessed even with a tamper-proof lock in place. It's starting to bother me that the PA election officials keep saying that the voting machines aren't connected networked together, and that one would need 4,500 cards to compromise an election. It's just flatly false, since every county feeds into a central system such as Unity or GEMS, which themselves are provably insecure, and can be infected via the compact flash cards when they're collected. You would only need a few people in key counties to swing an entire election. What I would give for the days of hanging chads...
- eridius 10y agoJust because you think the message looks like it suggestions a Russian hacker doesn't mean that it isn't in fact Russian. Sometimes a cigar is just a cigar.
- s_q_b 10y agoThis is a personal opinion based on experience, speaking for myself alone, made with access only to public information. Take it for what you will.
- ryanlol 10y agoI'm not sure how you could legitimately come to those conclusions based on on the publicly available information. There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch. However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being from Ukraine, Romania or Russia. And unless I'm missing something, there's even less information about his OPSEC practices.
- s_q_b 10y agoA few hints that tickle my spider sense: 1. Yandex is an email provider that is almost exclusively to the new Russian sphere of influence. This is a the first thing that would jump out to an attribution analyst. Combined with the non-native language mistakes, a first pass analysis would indicate Russia. But the name of the game is deception. 2. The "mistakes" in the text are not those which a Russian-speaker would make. The most obvious signal is leading space before the comma.
- i336_ 10y agoGoogling the email address shows a few hits with other IDs, so at the very least this has gotten around a bit. (I haven't chased down the search hits, there may/may not be some leads as to what it is out there)