4 ms·
Except I have isolated the code and can reproduce it on demand, and have the photo's & video's as evidence so nice try. However having just read this https://w
by tr1ck5t3r 10y ago
Except I have isolated the code and can reproduce it on demand, and have the photo's & video's as evidence so nice try.
However having just read this https://www.facebook.com/dragosr/posts/10151655183445588 https://www.facebook.com/dragosr/posts/10151655183445588 I can see he has explained much of what I was witnessing on some systems as well.
Cant rule out a modern day version of one of these https://en.wikipedia.org/wiki/Phoebus_cartel https://en.wikipedia.org/wiki/Phoebus_cartel considering the Windows MSR partition I have copies of which effectively stripes the Windows Partition as well.
Some people are desperate to keep this quiet though, so perhaps suggesting what you have is your way to introduce doubt into an argument which is after all a valid debating technique.
- kbart 10y agoWith all due respect, everything you said sounds like some kind of conspiracy theory. If you have isolated this case, write a blog post of how to reproduce it, post said photos & videos, so people might at least take their time to read it. I'm sure with all the experts here on HN somebody would provide an explanation. There are hell lots of processes happening at modern system boot time, if it does something you don't understand, it doesn't necessarily mean malware. " The OS's seem to actively hide the malware if you use a hex editor to scan the drive or infected files, so over time, some of that open source code has become compromised" This part, in particular, I find hard to believe. You can inspect open source system and compile everything yourself. Did you try to reproduce this behavior on minimal systems (i.e. BeagleBone) or QEMU?
- tr1ck5t3r 10y agoOf course it sounds like a conspiracy theory, except the code or software suite which bad bios is part of, doesnt just affect the bios. It also spreads across the USB bus. In order to stand a chance of tracking this down, first you need a maker pc ideally an old one with EIDE ribbon cables say from early 00's, in other words one that is built from individual components not a branded pc. In no particular order of significance, make sure you have no speakers switched on and connected to the device as I have detected/heard a high pitched frequency a bit like morse code but not morse which could be detected by other devices with a microphone and speakers, eg a smart phone, tablet or laptop, coming from a Dell Laptop. This sound is virtually inaudible in that you will only hear it in a silent room, normal office environments are too noisy and depending on how often you listen to music with headphone's depends on how good your hearing is as well. A point to note, hearing is damaged more easily at the high end frequencies than the lower end (bass) frequencies. Have a mother board which supports PS2 mouse & keyboard connections, but use a USB mouse. One thing I have observed in Ubuntu 16.10 live CD when it strikes, is when the screen starts dimming (power saving) and then goes blank, the USB system seems to stop. So if you move your USB mouse to bring the display back up it doesnt work, but moving the PS2 mouse does bring the screen back up from power save so the malware doesnt appear to work "so far" on ps2 devices. If you happen to be printing to a USB Printer in my case a HP LaserJet 1200, the printer system (CUPS) will say the printer is paused and the only thing you can do to get it printing again is to reboot which means having to boot from a live cd and download said webpage again. Sometimes you have to do this for each page the website goes over. This is whats called resource burn. Get a USB CD/DVD device, although its slower, when the firmware of this is changed(infected) it starts emitting a different noise like its jumping around alot more to read stuff. As I have a silver ubuntu 16.10 disc, these cant be burnt again so are a little safer as nothing can be added to these discs, but I suspect burnable CD/DVD's despite choosing the option to make them burn proof ie cant be added to, can be. Looking at the disc under a microscope or jewelers loupe might confirm this. The hex editor in the Parted Magic disc I have here (its about 3-4years old at least) wont show infected files eg a webpage printed to a pdf in its entirety, but looking at the raw partition searching for a matching part of the string data and then doing a side by side comparison using the hex editor opened twice will show the data goes beyond the sector it stops at having loaded an infected file. Now I'm not a security expert, my background is database programming but I have been programming computers since an early age and have noted the changes in operating systems. So staying within the laws of physics, and considering wifi has been built into CPU's (Intels VPro/AMT for example) but possibly deactivated by microcode is cheaper CPU's, is all the above just a side show? Or does this code only become activated when some CPU microcode is switched on for example, making it impossible for other's with CPU's not affected to find this? Another clue you might have an infected system, is when using dd to zero a device, the device either never completes throwing the usual "out of space" error or it throws an Input/Output error suggesting the block device has a reliability issue. The make and model of CD/DVD drives and so far some Western Digital hard drives, seem to be rewritten when the system is infected. In theory, just because a manufacturer doesnt provide a firmware upgrade, doesnt mean you cant upgrade the firmware. Just look at the package FlashRom which I discovered a few days ago, or hddguru.com for some of the firmware tricks that can be carried out on different devices. Another clue, is Iptables doesnt seem to work properly, when setting rules (I always go for log and drop) for everything, not just filter, but nat, mangle, raw and bear in mind here in the UK IP TV stations provided by the ISP's are delivered over IPv6, even if you set iptables for IPv4, how many set iptables for IPv6? If you poke around with your ISP supplied router, download the config file you'll find IPv6 settings plus some also provide wifi access points which are unecrypted and accessible open to anyone who wants to fly a little drone and drop a PiZero into your properties gutter hacking your wifi. I can post some photo's to my imgur account if they stay up there, if not post an email address to here and I'll send some photo's of the bios screen from an old pc which shows the drive's make and model being changed, taken on an old digital camera's so it cant be hacked unlike so many of todays wifi enabled device's and I'll post a couple of PDF's which seems to cause Input OutPut errors. In the PDF case, yes I will need to start looking at the PDF reader's code that ship's on Ubuntu 16.10 to see what it does but its not something I have done before. Here's a screen shot of a UEFI bios which shows that the bios can load and unload drivers http://imgur.com/gallery/npR9ZIw http://imgur.com/gallery/npR9ZIw The bottom line with all of this stuff is who do you trust? When you phone a call centre how do you know you are talking to a call centre and not the spooks? You cant prove it, and this is what all of this seems to be about. In law you need evidence, which is interesting because the Snoopers Charter now in law here in the UK specifically section 56.4 allows all spook activity from 1985 onwards to be considered legal. And you cant talk about their methods. If you know about the phone system FreeSwitch you'll know you can run your own phone company with it, whilst setting up call intercepts so irrespective of what number an extension dials, it always go through to the same extension. A similar example is when visiting a company, sometimes in reception there might be a single phone which you pick up and it automatically rings another extension. If you added a VOIP number to and set FS to record all calls, as the VOIP is shunted to FS, FS detects it needs to play back the ringing tone's to the caller which it does, now as its also setup to record conversations, the caller can leave a message and there is never a billing record to suggest the call connected. What a great way for spooks to communicate within a country, unless of course all phone's are actually recorded and for arguments sake what the Govts tell us is just a lie to stop up from getting upset about being spied on all the time ala the Panaopticon? Practically anything can be done with digital technology and with the resources and ingenuity of nation states, you can pull off a Brexit or Trump election if you so wanted! Take digital TV, how many channels to keep you entertained? Bread & Circus springs to mind, and divide and conquer also springs to mind, which starts with everyone being educated into what ever takes your fancy, whilst few actually have an overview of whats really going on in life. Maybe life is more like the Matrix than it appears to be? PS. On the point of a microcode switch being in play, I have observed Raspberry Pi SD cards which load on one Rpi but take the same SD card out and place it in another Rpi, and the same SD card wont boot, so microcode/Rpi firmware is quite likely a factor, and the same probably applies to Intel/AMD CPU's which is why I wonder if its a modern day pheobus cartel forcing people to go out and buy new hardware. HP PSU's in network printers and laptops also seem to have a tendency of blowing up as well.