3 ms·
RSA has posted a more detailed account to their blog: Anatomy of an Attack http://blogs.rsa.com/rivner/anatomy-of-an-attack/ http://blogs.rsa.com/rivner/anato
by trotsky 16y ago
RSA has posted a more detailed account to their blog:
Anatomy of an Attack
http://blogs.rsa.com/rivner/anatomy-of-an-attack/ http://blogs.rsa.com/rivner/anatomy-of-an-attack/
- mukyu 16y agoSadly, it provides basically no details. Skip to the appendix if you don't want to read irrelevant comparisons to U-Boats and stealth aircraft. Even there, the details are light. They got spearphished with excel files with flash payloads (CVE-2011-0609). Those installed "Poison Ivy" (some remote admin a la vnc/rdp). They spread out from those points attacking other accounts/computers/servers. They looked around for interesting things, put it in passworded RARs and FTPed them out to other compromised (non-RSA) servers (apparently "Good[DOT]mincesur[DOT]com | up82673[DOT]hopto[DOT]org | www[DOT]cz88[DOT]net"). There is very little useful information in their breakdown. Everything they mention is standard fair, certainly not something special to "Advanced Persistent Threats". The flash vuln (with excel files) has been known for weeks. There is no discussion of what the attackers actually managed to get their hands on.
- trotsky 16y agoAgreed that all of the "omg, APT" in there comes off pretty badly in light of the reported details. APT has more or less been poisoned as a term lately (see comodo, etc.) and amounts to the latest scapegoat scenario. "See, we can't be blamed! It's an APT!" is what I'm betting the RSA board hopes is the take away here. Of course they could also know something pretty significant that they're not telling. What was taken and how tough it was to get at internally could be a flag. If there was a really significant or telling element to the attack it may well be that they've been asked not to reveal it. Not that I'd bet on that side of the line.