10 ms·
> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how
by ccurrens 6y ago
> If you find password protected zips in the release the password is probably either "Intel123" or "intel123". This was not set by me or my source, this is how it was aquired from Intel.
Can't say I'm surprised, people are lazy.
Another large tech company I used to work for commonly used an only-slightly more complex password. But it was never changed, so people who had left the team still could have access to things if they knew the password. It was an entry point into the system more than the company's Red team.
- schmichael 6y agoPassword protection may have been used to bypass antivirus and other filters. While you should treat dumps like this with a lot of suspicion, treat password protected zips with a heaping dose of care as they may have been used to evade automated defenses.
- ccurrens 6y agoThat's an excellent point I wouldn't have considered. I have no intention of looking at the dump anyway, but thanks for the warning.
- 1-6 6y agoI think the proper term is Honeypotting.
- deleted 6y ago[deleted]
- pjc50 6y agoYes - but not for hostile purposes, but because your own company's antivirus won't let you mail an executable to a colleague.
- marcosdumay 6y agoUsually this. Or in my workplace, an image. Antivirus are some crazy shit that may trigger on any random action and will teach people to follow the most unsafe procedures without questioning, so they can get anything done.
- myself248 6y agoI've heard it put this way: If you force users to trade convenience for security, they will find a way to obtain convenience at the expense of security.
- hinkley 6y agoIf you make it harder for people to do the right thing than the wrong thing, they will choose the wrong thing. This has been brought up a million times in the context of DRM, but it is true in the general case as well.
- tombert 6y agoI could be mistaken on this, but wasn't this basically the sales pitch for Spotify? Basically saying "you'll never get rid of piracy, but you can compete with it".
- setr 6y agoNot sure about Spotify, but I know gabe newell had famously made basically this argument, in regards to steam's success
- danudey 6y agoThis was the sales pitch for iTunes and the iTunes store: "We approached it as 'Hey, we all love music.' Talk to the senior guys in the record companies and they all love music, too. … We love music, and there's a problem. And it's not just their problem. Stealing things is everybody's problem. We own a lot of intellectual property, and we don't like when people steal it. So people are stealing stuff and we're optimists. We believe that 80 percent of the people stealing stuff don't want to be; there’s just no legal alternative. So we said, Let's create a legal alternative to this. Everybody wins. Music companies win. The artists win. Apple wins. And the user wins because he gets a better service and doesn't have to be a thief." https://www.esquire.com/news-politics/a11177/steve-jobs-esquire-interview-0703/ https://www.esquire.com/news-politics/a11177/steve-jobs-esqu... Another point of reference: because they had no legal ground to stand on, HBO targeted Canadian torrenters of Game of Thrones with an e-mail saying, among other things, "It's never been easier to [watch Game of Thrones legally]!" This was true, it had never been easier. It had also never been harder. For the entire time that Game of Thrones was being aired, the only legal way for Canadians to watch it was to pay about a hundred dollars per month for cable and the cable packages that would give them HBO. You could buy it on iTunes, but only as a season, after the season was over. So yeah, I kept torrenting it, everyone I know kept torrenting it, and everyone hated (or laughed at, or both) HBO the whole time.
- stefan_ 6y agoYour company's antivirus, or GMail. A binary? A zip with a binary? Nuh-uh.
- Delk 6y agoTo be fair, emailing binaries (apart from known types such as images, PDFs, etc.) is a rare enough use case for legitimate purposes and an easy enough way of spamming malware to clueless random people that it's probably a reasonable default for gmail. Having an option to allow them might be okay though. (I barely use gmail so I don't know if it has one or not.)
- sjg007 6y agoAh you must be young...
- totetsu 6y agofor not using gmail? The hooked me in school
- Alekhine 6y agoHe means there used to be a time when people would mail binaries to each other more often, before they got too big and DRM'ed for that.
- bawolff 6y agoThere was also a time when alt.binaries was a thing (technically not email, but usenet is pretty similar)
- Nasrudith 6y agoFor not sending binaries by email - there is no shame to being young in this case as it means never developing the bad habits. Before Dropbox and similiar it was far more a norm and various file sharing systems like SharePoint may wind up not actually used. Non-computer technical people often do so in companies all the time and practically use it as an ersatz version control system to the cringe of IT.
- danudey 6y agoIn February, I e-mailed a python script to one of our developers to help debug an issue with their SSL configuration. Two days ago, I needed the script again but couldn't find it. Went to our e-mail thread and it said "the following potentially malicious attachments were blocked", showing mine, but... even from my outgoing mailbox? That seems ridiculous and problematic, considering that it sent fine at the time. I know that e-mail shouldn't be used as a replacement for Sharepoint or Dropbox or whatever, and I should have a local copy of what I need, but it just seems annoying and arbitrary. Anyway, I just logged into Outlook Web and downloaded it from the message there. Problem solved.
- dillonmckay 6y agoThis has happened to me with gmail. Zipfiles I had sent in the past are no longer allowed to be downloaded from my sent items folder through the standard interface.
- majewsky 6y agoIf I had to deploy AV for mail, I would absolutely scan outgoing mail as well. Imagine if some compromised mail account in my org sends malware to accounts in other companies. These companies could then sue my company for negligence if they can show that we did not scan our mail for viruses on outbound (which could potentially be done by examining mail headers). (I am not a lawyer.)
- hnick 6y agoWe just rename our files with .novirus on the end. I assume the main point is to stop executables from outside running with a click, or internal forwards of the same by compromised users which is why it's so easy to bypass.
- swiley 6y agoShouldn’t you put it in either eg artifactory or a code repo?
- somehnguy 6y agoYes. Whenever I email or transfer a zip via any method really I always put a basic password on it. I've been bitten way too many times by dumb filters that pick some file out of the zip and declare that it is malicious. I also don't trust messenger apps to not pull my files out and do who knows what with them. A basic password prevents this junk 99% of the time for almost no effort. It won't stop a determined system from cracking the password. But that isn't what I'm trying to defend against.
- saagarjha 6y agoGmail doesn't seem to like archives it can't open :/
- blue52 6y agoLol wonder why?
- neltnerb 6y agoAh, the halcyon days of merely changing the file extension from .exe to .txt...
- jon-wood 6y agoThis brings back happy memories of a college (senior high for the Americans in the audience) computing teacher finding a friend and I had been writing irritating malware instead of doing actual work, and his only comment being “if you’re going to email that to yourself change the extension so it doesn’t get flagged for IT support”.
- j1elo 6y agoGmail won't even let you send a JAR file, or a zip you made out of a project where it happens to be a .jar file somewhere deep in some random subdirectory.
- Spooky23 6y agoIIRC, You can do it by embedded the content into an Office file, which is a zip file.
- lmilcin 6y agoI have left Intel couple of years ago, that's exactly what passwords were used for. It was pretty annoying to try to send files and putting them in encrypted archive wast the most convenient method. It was not just for binaries but for scripts, html, etc.
- loktarogar 6y agoat my first job they used a similar password as their go-to "temporary" password for users etc. I found later when I got to work with the users that they rarely changed this password even when "forced" to, and in many cases had it up on post-its next to their monitor.
- reaperducer 6y agoand in many cases had it up on post-its next to their monitor. These days a post it is probably the best way to secure your password. 99.9999999% of password hacks come over the wire now, from people in other cities, states, or nations. If someone is in your building, in front of the computer, even without the post-it, you're probably toast.
- loktarogar 6y agoA post-it is not a good way to secure your office's generic temporary password.
- cbanek 6y agoThe shared stupid passwords like this that I've seen/had to use in my career would utterly shock you. Like hunter2 levels of shock.
- david_draco 6y ago> Like ******* levels of shock. What do you mean with 7 star levels?
- dleslie 6y agoAlso, the passwords are listed in docs that appear to be alongside the encrypted files. That's a bit like leaving the keys to your house _on top_ of your front doormat.
- danudey 6y agoIt's kinda like hiring a security guard for insurance purposes, even though they have strict instructions to never do anything, under any circumstances, other than call emergency services.
- Nasrudith 6y agoTo be fair having someone aware and around to watch and phone emergency services has a use.
- reaperducer 6y agoIt's kinda like hiring a security guard for insurance purposes, even though they have strict instructions to never do anything, under any circumstances, other than call emergency services. I see you've worked in retail.
- MrStonedOne 6y agoCommonly password protected zips are used to bypass security systems that block all zips with exes in them. I doubt the encryption was believed to be a security barrier.
- TeeMassive 6y agoI worked for a company that made servers. In the on board management system's source code I remember seeing "base64 encryption". I think they removed it by the time I left, but still.
- at-fates-hands 6y agoI was an admin for a medium sized company and handled their websites. Almost all of them (about a dozen or so) were hosted on Go Daddy. Plus they had about two dozen reserved domains they were sitting on like www.yourcompanysucks.com and others. I left the company 5 years ago. Just checked the login to see if it still worked. Yeap. Any disgruntled employee could change the password, lock them out of all of their sites (including several e-commerce sites that amount for a large chunk of revenue) and then if they really wanted to, delete all of them. I remember talking the main network guy about any backups when a lot of the ransomware stuff was making the rounds. The big, really big stuff on their network (mostly ERP stuff) was backed up in two or three places. Their web stuff? Yeah. . . NOPE. Pretty scary how lazy people are about stuff like that.
- netsharc 6y agoI wonder if a malware should just grep for "pw:" or "password:" and then try the string it finds against anything encrypted. Or forward it to the control center. Also the contents of files like password[s].txt
- tomrod 6y agoI knew one company who used the same password for bios as wifi.
- dasb 6y agoNo one who knows what they're doing uses zip passwords as security. The passwords are probably there for other reasons.
- dandare 6y agoA company I know insists on rotating passwords fairly often. Everybody just increases the number at the end of their favourite password, i. e. intel1255
- kps 6y agoI once worked at a place that required passwords to be changed every month and contain at least one upper and lower case letter, digit, and punctuation, and not match any previous password. So the password for August, 2020 would be “August, 2020”.
- SturgeonsLaw 6y agoThis is super common, to the point where Microsoft used a similar password scheme as an example when talking about password spraying attacks at an RSA conference presentation https://www.zdnet.com/article/microsoft-99-9-of-compromised-accounts-did-not-use-multi-factor-authentication/ https://www.zdnet.com/article/microsoft-99-9-of-compromised-... It's why I'm advocating within my organisation to get rid of password expiration and enforce 2FA for clients, but there's a lot of inertia to push against with some of them. At least uptake of 2FA is consistently increasing.
- kube-system 6y agoIf you need backup, NIST standards agree with you. Scheduled password expiration weakens security by encouraging users to make predictable passwords, and by entrenching password resets as a routine and unscrutinized process.
- CapricornNoble 6y agoMany DoD websites are the same. It's so annoying. I use a password manager at home but at work I don't have that luxury (installable software is tightly controlled and very limited).
- Sylamore 6y agoWhere I work they use a password filter to stop you from doing that... But it doesn't stop you from spelling out the numbers instead, plus that makes your PW longer
- reaperducer 6y agoAnother large tech company I used to work for commonly used an only-slightly more complex password I know a brand-name healthcare company that uses Passw0rd for its internal WiFi, which is easily reachable from an interstate rest area.
- jyriand 6y agoSome people/companies think that if you are behind VPN you can use simple and obvious passwords.
- de6u99er 6y agoAnother password is "I accept" (based on the leakers Twitter messages).