10 ms·
Coinbase: Responding to Firefox 0-days in the wild
- Deimorz 7y agoThis was the original article that talked about this attempt: https://robertheaton.com/2019/06/24/i-was-7-words-away-from-being-spear-phished/ https://robertheaton.com/2019/06/24/i-was-7-words-away-from-... HN discussion: https://news.ycombinator.com/item?id=20283922 https://news.ycombinator.com/item?id=20283922
- deleted 7y ago[deleted]
- wyldfire 7y agoThis is among the critical differences between MtGox and Coinbase.
- ceejayoz 7y ago"We're not run by idiots"?
- wyldfire 7y agoWell, sure, I suppose that's step zero. But there's a lot more work required beyond that in order to survive continuous attacks.
- apl002 7y agothis gave me a good laugh
- notriddle 7y ago"We didn't literally start out with trading cards."
- arcticbull 7y agoThat's not a great one, Nintendo started out as a playing card company after all. Where you start is quite irrelevant. It's where you end up that matters, and I think MtGox demonstrates that quite clearly.
- wyldfire 7y agoI don't hold MtGox's origins against them (plus I'm a MtG fan). But Nintendo didn't pivot from playing cards to guarded stagecoaches, they stayed in the entertainment focus and evolved over a century into electronics. The stakes were always low.
- arcticbull 7y agoPretty low bar honestly, even if they had pivoted to stagecoaches it’s hard to knock them if they’d been successful. The ends are more important. Gox was really stupid though.
- grubles 7y agoThat doesn't explain listing Bitcoin Cash (Bcash) - an altcoin that shares its mining algorithm with Bitcoin but only has a very small amount of hash rate backing it. Any small Bitcoin miner can decide at any moment to switch to mining Bitcoin Cash and cause block reorgs or mine blocks with no transactions at all. A similar event actually happened with another asset they offer - Ethereum Classic. https://cointelegraph.com/news/ethereum-classic-51-attack-the-reality-of-proof-of-work https://cointelegraph.com/news/ethereum-classic-51-attack-th...
- hollerith 7y agoHuh, I would've thought that since people will pay over 300 usd for one Bitcoin Cash coin (according to 3 web sites I just sampled), there would always be plenty of miners competing for them.
- wmf 7y agoBCH is and will be mined proportionately to its price; since its price is far lower than BTC it also has far lower security.
- hollerith 7y agoOK, but I would've guessed that the reward for hijacking BCH's blockchain would be proportionally lower. And please keep in mind the context of my first comment: I was replying to the assertion that the mere fact that Coinbase continues to let its customers trade in BCH is evidence that Coinbase is run by idiots.
- NullPrefix 7y agoWe didn't implement ssh server in php
- deleted 7y ago[deleted]
- londons_explore 7y agoCoinbase should be hiring pentesters and giving them employee level access - even access to commit and deploy code. Any insider shouldn't be able to steal more than the hot wallet, and even that should be hard. I actually wouldn't put much effort into border security. At coinbases level of risk, evildoers will have no qualms bribing an employee to install a backdoor in their machine.
- ryacko 7y agoThe trouble is finding someone to bribe who won’t suddenly start buying new things.
- bravoetch 7y agoTo follow through on that though, what makes you think that would be anything noticeable? Suddenly a coinbase employee buys a cool car or other new toy... So what? Nobody would think that was exceptional.
- ryacko 7y agoI think this is why investigations require low levels of evidence to start, but high levels of evidence to end. Just because it isn’t exceptional doesn’t mean that it isn’t worth looking into. People who are greedy are impulsive and are unlikely to hide an inflow of cash.
- ALittleLight 7y agoTheft isn't restricted to impulsive people though. It's mostly restricted to people who think they'll get away with it. Clever and cautious people may actually be able to.
- ryacko 7y agoUh. Yes. But things don’t disappear do they?
- dmortin 7y agoDoes it a help in this case if one runs the browser in a sandbox? E.g. in docker? They can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it?
- oldstrangers 7y agoHaving two 0-days for one of the most popular browsers tells me they probably have access to whatever they want.
- dmortin 7y agoFor high value targets, probably. For average spear phising I don't think they spend more resources to break out from docker. Since default docker runs linux, running the browser in a linux docker can be enough, because they usually have windows exploits.
- danieldk 7y agoThey can then break out from the browser, but only get to docker with that exploit, and it's unlikely they have a docker exploit too at hand, is it? If you are running Firefox on X11 (which most Linux users probably still do), you do not need to escape Docker. You can make screenshot, capture keystrokes, and send keystrokes, all through the X11 socket. (Furthermore, you do not need a Docker exploit, a Linux kernel exploit can be enough to break out of a container. This is one of the reasons for e.g. gVisor to implement syscalls in userland and in a safer language.) Using VMs as e.g. Qubes OS does is probably a bit safer than a Docker container.
- MrRadar 7y ago> If you are running Firefox on X11 (which most Linux users probably still do), you do not need to escape Docker. You can make screenshot, capture keystrokes, and send keystrokes, all through the X11 socket. Also, this is why Wayland is much more restrictive about these types of operations. People love to complain that "I could do thing with X without special privileges" but the world has moved on since X was designed and it absolutely has not kept up.
- ianhawes 7y agoInteresting to me that the attackers were well equipped in their phish and 0days, but then opted to drop fairly detectable RATs.
- staticassertion 7y agoYeah, they could have moved processes before execing the shell. Detecting "Firefox + Shell" is quite easy and standard, even in existing SIEMs. Detecting "arbitrary program + shell" is at least moderately more difficult. It's the attacker's dilemma though. They only need to trip one alarm to trigger IR.
- notathing 7y agoThe biggest fail here was that 32 bit program warning, which probably alerted the employee. Notice that they didn't actually have an alert for Firefox+Shell, they detected that later by inspecting the audit logs.
- staticassertion 7y ago> We detected the attacker at this stage, based on a number of behaviors (e.g. Firefox shouldn’t spawn a shell). They explicitly state it was one of the behaviors they detected as suspicious.
- dead_mall 7y agoI was thinking the same thing. The RAT they used is well known in underground skiddie forums; it's known for being expensive and shitty.
- repolfx 7y agoVery likely that they bought the exploit and did the rest themselves, so, their skill at phishing, exploiting and RATing won't be correlated.
- vbezhenar 7y agoThose attacks would not work if they did not enable JavaScript on every website by default.
- tyscorp 7y agoThose attacks would not work if everyone stopped using computers.
- OrgNet 7y agoits almost like the NSA designed all programming languages to insure that it would be impossible to make a perfect program
- NieDzejkob 7y agoI find the explanation of "to err is human" far more likely.
- jakeogh 7y agoI keep JS off by default* and it's teriffic. Using a browser with it enabled is tedious, slow and distracting in addition to the obvious heka-less-secure. * http://surf.suckless.org/ http://surf.suckless.org/
- aitchnyu 7y agoI see my colleague making a web app that forces the browser into 100% CPU on scroll, just to animate a shrinking nav bar. Also a page that wont settle in for 15 seconds until assets from Google Fonts downloaded and all scripts have run. So I secretly pray for a draconian anti-js order imposed on us, even though my minimal Vue scripts will go away.
- oehpr 7y agoThis was mentioned in a previous HN thread and I thought it was a brilliant idea. By default, browsers should throttle websites. Throttle their CPU and their ram usage, and websites can then ask for permission to be unthrottled. We have very capable computers now. But the web feels just as slow. Some negative pressure against bloat is sorely sorely needed.
- xchaotic 7y agoThis point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it...
- vageli 7y ago> This point to an actual use of the cryptocurrency - exploiting a 0 day against someone who might have a crypto wallet means you can actually directly make money off exploits. Prior to crypto, having a 0 day wasn't equal with ability to make blackhat money with it... Why would that be the case when it is not illegal to sell exploits?
- mnbvkhgvmj 7y agoBanking malware has existed for a while.
- fsh 7y agoBanking has insurance against fraud and transactions are generally reversible.
- mnbvkhgvmj 7y ago> transactions are generally reversible Not really. If your account is compromised you may indeed get your money back from the bank's insurance (although in some countries that is less likely than others). However, the criminal behind the malware will probably have got at least some of the money. International transfers are not generally reversible. Cash withdrawals are not reversible. Even electronic transfers to another bank in the same country (maybe this varies by country) are only reversible if the money has not been withdrawn. And then there have been cases of actual bank systems being compromised so that criminals can just increase the balance of accounts directly.. And cashpoints (atms) being compromised.
- flyGuyOnTheSly 7y ago>We collected IOCs from the host in question and started hunting broadly in our network. We did not see any of the IOCs anywhere else in our environment, and blacklisted all the IOCs that we had at that time. Can someone explain what they mean by IOCs?
- CorralPeltzer 7y agohttps://en.wikipedia.org/wiki/Indicator_of_compromise https://en.wikipedia.org/wiki/Indicator_of_compromise
- ChrisCinelli 7y ago> CVE-2019–11707 was simultaneously discovered by Samuel Groß of Google’s Project Zero and the attacker. At least another time in the last week I read on other threads on HN or related links that vulnerability were found almost the same time by independent people. Here we have a researcher from Google’s Project Zero and the attacker. How do you explain these coincidences? What is the chance that some prominent researchers being targeted and their systems are actually exploited?
- lvh 7y agoThis is not an uncommon phenomenon and not specific to vuln research. It happens all the time in mathematics, the sciences... [0] Far more likely: there is a related cause that made two people think to try the same thing at approximately the same time. Someone publishes a new JIT type confusion bug, someone realizes "oh man it never occurred to me that X could trigger bug type Y", they start digging, and... [0]: https://en.wikipedia.org/wiki/Multiple_discovery https://en.wikipedia.org/wiki/Multiple_discovery
- ChrisCinelli 7y agoThanks for the comment. I think where I read of the other synchronous discovery was hinting to what you wrote but I deliberately wanted to hear about the probability of researchers being compromised. Maybe this is not the case but if somebody has powerful means, knowledge on how do successful targeted attacks, and access to the right 0 days, it would make sense that can use their resources to find other 0 days in this way.
- kccqzy 7y agoThe article clearly states that the attackers and the researchers use very different ways of triggering the vulnerability. It is a coincidence.
- WrtCdEvrydy 7y agoThe same chance of getting two movies with the same premise (Armageddon and Deep Impact, White House Down and Olympus Has Fallen)
- victor22 7y agoRemember, not your keys, not your bitcoin. Stay off coinbase.
- notathing 7y ago> A criminal gang operating in India kidnapped and tortured cryptocurrency traders in recent weeks before demanding 80 bitcoins as ransom, police say. Three men had been held captive for 15 days inside a high-rise building and were beaten or tortured... Not even their family members were aware of the abduction. The victims had lost all hope because they had no access to anyone https://www.newsweek.com/cryptocurrency-traders-abducted-tortured-india-criminal-gang-arrested-bitcoin-ransom-1449274 https://www.newsweek.com/cryptocurrency-traders-abducted-tor...
- TooCleverByHalf 7y agoIm confused why this is a response to the parent.
- Izkata 7y agoIt's the same argument as this xkcd: https://xkcd.com/538/ https://xkcd.com/538/ Though granted it confuses keys for passwords.
- jameslevy 7y agoFor the average person, using Coinbase with 2FA is going to be better than managing their own private key. Even if their hot storage was penetrated, which is unlikely, they have insurance and other means of making sure that customer deposits are unaffected.
- dymk 7y agoBetter take all my cash out of the bank then and put it under my mattress.
- keypusher 7y agoI know a lot more people that have lost crypto because they lost their keys than people who lost it on Coinbase.
- anhldbk 7y agoI find this info is interesting > The attackers went through a qualification process and multiple rounds of emails with potential victims, making sure they were high-payoff targets before they directed victims to the page containing the exploit payload. It's a well-prepared plan combining social engineering and technical exploits
- auslander 7y ago> exploit code was delivered from a separate domain, analyticsfit[.]com They paid some registrar for the domain. Can police request payment details? Can someone buy domain on stolen credit card?