6 ms·
Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls? Two pieces of the story that don’t add up f
by simplecomplex 8y ago
Where did all the boards in question go? Why wouldn’t a company notice any of the outbound traffic using firewalls?
Two pieces of the story that don’t add up for me.
- radicalbyte 8y agoThere wouldn't be any weird outbound traffic; the attacker would use another cloud instance as a controller. They would use a US-based account (and IPs via VPNs) to control the controller.
- simplecomplex 8y agoThe traffic has to travel over wire as TCP/IP, regardless of what device generated it. It has to travel over wire somewhere! The device can’t magically communicate with China. Any outbound firewall could detect that, especially traffic going to ports that aren’t even open/used.
- true_religion 8y agoI think the idea is that the traffic goes over intranet to another computer that they legitimately control within the datacenter, then goes to China. Or if they can insert themselves into the maintenance team, they can retrieve their chips at a later date.
- lostmsu 8y agoAren't we talking about virtual machines running on this hardware?
- Filligree 8y agoUnless, just to provide a nightmare scenario, the routers that would detect it are also compromised.
- paulie_a 8y agoThe NSA did that, they literally intercepted routers en route. I'm guessing other agencies have too. Or you can just use the default credentials Cisco is addicted to leaving in their code.
- simondedalus 8y agoi gave you the benefit of the doubt when i read your earlier comment, but this doubledown shows you're extremely naive / have no experience with the space. you realize there are entire industries (plural) premised off the fact that you can't just throw up "any firewall" and detect this kind of thing, no? can you imagine how it would go down if a major corporation like apple experienced a hardware hacking based infrastructure breach, contracted a cybersecurity company, and the tech heading their case asked them like "well were you making sure to check which ports were open?"
- dpedu 8y agoCloud instances are generally firewalled off from each other, usually cross-account, vpc, etc. Two machines can't reach each other just because they're AWS instances. That would be silly.
- zaroth 8y agoThe attacker and target have VMs on the same hardware. The attacker has a fake presence serving cat pics which is constantly sending “valid” logging traffic to an S3 bucket. The chip passes the stolen data between the VM instances by DMA. The stolen data hitches a ride inside an otherwise innocuous TCP packet storing log entries in that S3 bucket. Logs are routine backed up off site. There would be absolute nothing at the network level to distinguish the infiltrated packets. Lower latency scenarios could be devised which would be similarly invisible but allow better command & control.
- robryk 8y agoIt seems that you're arguing for a different functionality of the implanted chip than the original article. Original article supposes that the implanted chip was used to modify the boot process of the BMC in such a way that the BMC loaded its software over the network. The question is why this network activity wasn't easily detectable and firewalled off by default. It seems that you suppose that the chip can be directly used for some sort of userspace-inside-a-VM to ring0(?) escalation. In particular, you suppose that the chip has access to main memory. Can you elaborate on what functionality do you think the implant could've had?
- PeterisP 8y agoNot the parent poster, but the chip can indirectly used for such an escalation - the chip would have the capacity to modify BMC software as it's loaded from a nearby memory chip; and BMC has direct access to main memory that enables all kinds of interesting escalation scenarios.
- jonathankoren 8y agoI don’t know what you mean by the first question. The implication was that this was a bit of a drift net attack. Compromise a few lots, then wake them up a few months later figure out where they are. Most aren’t useful, but if you got the right batch, some might end up someplace interesting. I would assume the reason why no one noticed outbound traffic is because it’s dormant.
- simplecomplex 8y agoSo if there’s a bunch of compromised boards, where are they? Which boards? If they truly are in a bunch of datacenters, and we know the manufacture and models, why hasn’t anyone just gone and looked? Or Why haven’t the leakers just provided the actual chip? It should have been as easy as ordering one.
- jonathankoren 8y agoWhy are you assuming people haven't looked? > Why haven’t the leakers just provided the actual chip? It should have been as easy as ordering one. Sure, let me just order up a state intelligence compromise. It's right here on Alibaba right under Official_PLA_61398.
- wyldfire 8y ago> Why wouldn’t a company notice any of the outbound traffic using firewalls? The attacker could use this to escape AWS/shared computing sandboxes/containers in order to attack their peers. Exfiltrating the data stolen could be easily hidden in something that looks like legitimate customer traffic.
- simplecomplex 8y agoHuh? The traffic has to travel over wire as TCP/IP, regardless of what device generated it. Any outbound firewall would detect that, especially traffic going to ports that aren’t even open/used.
- tomc1985 8y agoIf I were an attacker in that situation I'd probably find a way to get my data to hitch a ride with other outgoing data
- deleted 8y ago[deleted]
- wyldfire 8y agoMany/most AWS customers use ssh sessions to interact with their allocated nodes. And when it's not ssh traffic, it's often https. What good does it do to detect the bad traffic if you can't distinguish it from legitimate customer traffic? > has to travel over wire as TCP/IP, BTW, this is not the case. If exfil via conventional system networking is too hard to avoid detection, they'll find another channel. RF via LOS, ultrasonic, or some of a million other ideas.
- auslander 8y ago> notice any of the outbound traffic Outbound traffic is allowed unrestricted in 95% of the deployments, it is just a life fact, people trust their own systems.
- nineteen999 8y agoYep, lack of egress filtering everywhere. Scary how many cloud deployments I see that are like this. Improvements in automation tools and the ability of cheap cloud resources enable people to roll out instance after instance with the same basic configuration mistakes.
- auslander 8y agoYum update, pip install whatever :)
- nineteen999 8y agoRubygems for everybody! Or arbitrary docker containers. My current deployments allow outbound SMTP only. All software packages (rpm or whatever) get pushed in via rsync from the outside, or are built in an adjacent lab behind the firewalls and pushed across.
- auslander 8y agoIt may affect the very source box you are using for package downloads. I bet it is allowed to go outside unrestricted. Funny you mentioned Docker, it is a security nightmare in itself.
- nineteen999 8y agoIndeed, although it is connected via rather restrictive corporate proxy. I'd rather have one box on my network exposed where I can monitor it than a thousand instances with unrestricted outbound access in AWS though. Oh yeah - docker. I thought this one was pretty funny: https://threatpost.com/malicious-docker-containers-earn-crypto-miners-90000/132816/ https://threatpost.com/malicious-docker-containers-earn-cryp...
- lawnchair_larry 8y agoReally, you think it’s easy to spot a few stealthy packets among trillions? You have far too much faith in detection capabilities. Many of the best companies go years without detecting rogue traffic. Also, just because you don’t know where the boards are does not mean that they don’t exist.
- acdha 8y ago> Why wouldn’t a company notice any of the outbound traffic using firewalls? This is telling you that your experience is limited, not that the story is wrong. Trying to do egress filtering at scale is extremely hard for all but the most basic threats. If they open a socket to data-collector.pla.cn, yes, probably a majority of large shops would notice that within a few months but what if it's just a connection to S3/EC2, buried in the noise of all of the legitimate use of those services? Think about how hard it is if the attacker is smart enough to bundle that into other traffic: compromise your mail server and have it respond slightly differently to some spambots, have a webserver respond to the Baidu crawler with actual data encoded in the cookies it sets knowing that the Great Firewall can pick the data up (Baidu doesn't even have to be involved – just something which gets packets somewhere they can see them), etc. If it's on a network with people, that's especially easy – is that user-agent hitting sites in China a bot or just the staffer who keeps tabs on market news for that region? (But, you may say, our user and server networks are tightly segregated! Does that apply perfectly to your terminal servers? How would you know if your web proxy started making a few extra requests?) The mention of seeing a problem first in a Siri data center was interesting to me because those data centers probably have very consistent network activity and it'd seem like the kind of place where the defense team would have the best chance.
- mgiampapa 8y agoGeneral practice for things like BMC and other out of band control systems is to put them on isolated vlans and default deny any non-approved traffic. There is no way that any large tech company security operation misses this traffic phoning home from a management vlan.
- vel0city 8y agoBMCs can often also communicate on the other non-dedicated ports. It is not impossible for a compromised BMC to see traffic on an ethernet port or change its VLAN and go out on the same VLAN as the rest of the normal traffic.
- acdha 8y agoThat's true but right now I can think of at least three options where that wouldn't be relevant: 1. The implant can use the host network interface before the host OS starts 2. The implementation depends on VLAN tagging and the implant simply uses configures its network interface to use the same tag as the host interface 3. The implant can compromise the host OS when it loads and use its networking stack after it loads
- perlgeek 8y ago> Why wouldn’t a company notice any of the outbound traffic using firewalls? If you deploy several thousand of those backdoor chips, you wouldn't set them up to ping your C&C infrastructure all on its own. Rather, you'd use a magic string as a trigger to activate the backdoor in some few targets to reduce the chance of the outbound traffic being detected.
- imhoguy 8y agoWouldn't be it possible to somehow hide a signature and instructions in legit MPEG payload? Think of video scaling service getting prepared video file with a binary pattern which once detected by hacked HW/FW would activate the hidden instructions and plant results in a response.
- toyg 8y ago> Why wouldn’t a company notice any of the outbound traffic using firewalls? IIRC the original story mentioned en passant that at least one company detected some odd behaviour on the network, which eventually resulted in hw examination and the uncovering of these moles. TBH, that part is immaterial: it might well be some parallel construction to avoid giving away NSA intel capabilities. > Where did all the boards in question go? Warehouse 51 [1] of course. https://media1.fdncms.com/chicago/imager/best-approximation-of-the-final-scene-in-raiders-of-the-lost-ark/u/slideshow/9953342/raiderslastscene-teaser.jpg https://media1.fdncms.com/chicago/imager/best-approximation-...