8 ms·
The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] wi
by dsukhin 5y ago
The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain.
Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration. Perhaps someone was able to inject a message instead of the regular canned text through some sort of reflection attack? This explains why replies to the message result in a canned response. The system also now appears to be temporarily down. So it’s getting some sort of attention (internally taken down (most likely) or maybe denial of service from the abuse).
The Reddit thread suggests the recipients’ emails are likely ARIN IP range contacts. Those are very available from tools like this [2] so nothing interesting with that, but the real question is WHY someone would do this at all? This was clearly given some thought (on who to send this to who would actually take the time to verify the headers) but given the sloppiness of everything else, is this just a script kiddie flex? Whoever it is pissed off the FBI and gained absolutely nothing.
[0] https://bja.ojp.gov/sites/g/files/xyckuh186/files/media/document/a_a_fed_id_mgt_global_04-8-2010.pdf https://bja.ojp.gov/sites/g/files/xyckuh186/files/media/docu...
[1] https://www.justice.gov/tribal/page/file/1260671/download https://www.justice.gov/tribal/page/file/1260671/download
[2] http://itools.com/tool/arin-whois-domain-search http://itools.com/tool/arin-whois-domain-search
- technion 5y agoAwesome. A guide written in 2019 from the FBI that suggests Internet Explorer.
- fortran77 5y agoI would assume they're recommending Edge now. We switched from IE to Edge around that time; and our company is very security conscious because of our clients.
- RNCTX 5y agoI would assume you're wrong. I don't think you appreciate how many government websites run ancient software sold to them by a politician's cousin, who thinks even having a developer on staff is a waste of money.
- throwaway743 5y agoThey also run ancient shit that was promoted internally. Not to mention how many sites/tools are outsourced to vendors who then outsource development to foreign development vendors. To clarify, this is concerning from a security standpoint and is not out of xenophobic bigotry.
- havkd 5y agoWhat’s wrong with internet explorer? It’s still in active support.
- Aeolun 5y agoI think the problem is that you have to clarify it's still in active support
- technion 5y agoIt's actively supported by a company who themselves recommend against it and described its use as technical debt (in 2019) https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-perils-of-using-internet-explorer-as-your-default-browser/ba-p/331732 https://techcommunity.microsoft.com/t5/windows-it-pro-blog/t...
- Wowfunhappy 5y agoThey didn’t say not to use IE, just to restrict IE’s use to specific applications where it’s needed. The FBI has technical debt too!
- bogwog 5y agoWhere have you been for the past 20 years? Amish country? Because there weren’t many other places to take shelter from the horrors of IE.
- msisk6 5y agoYep, as late as earlier this year there's a ton of stuff inside the DHS that still requires IE and flash.
- dessant 5y ago"Life is too short to depend on unstable software" https://news.ycombinator.com/item?id=29209353 https://news.ycombinator.com/item?id=29209353
- enkid 5y agoIt could be the Russians trying to make the FBI look incompetent and make people trust the government less.
- macinjosh 5y agoOh no! Best check under the bed and in the closet for those dang ruskies /s
- RhodesianHunter 5y agoWhat's the point of comments like this? Do you honestly not believe that Russia enlists hackers to poke at the seams in the US?
- chayleaf 5y agoNot the OP, but, well, just as it could've been Russians, it could be North Koreans, Chinese, or anyone else. As a Russian, the comment just seemed unnecessary, though I'm obviously biased.
- boomboomsubban 5y ago>Do you honestly not believe that Russia enlists hackers to poke at the seams in the US? No, but I believe you should have some evidence before you start accusing them. Otherwise it is very much the "blame Russia" type comment that poster was mocking.
- macinjosh 5y agoThe point is to show how absurd the left has become with their xenophobia towards Russians.
- RhodesianHunter 5y agoIt's not xenophobia when their legal system incentivizes hacking foreigners and hacks just happen to keep popping up from Russia. Nor is pointing out blatantly obvious trends "left".
- tyingq 5y ago"Enter your official business email address...Do not use hyphens or dashes in the social security number (SSN#) and Date of Birth fields....Enter your employer’s information in the “Employer” fields" Oh, fun. Connected to a treasure trove of LEO personal info.
- buzer 5y ago> The Reddit thread suggests the recipients’ emails are likely ARIN IP range contacts. It's likely multiple different sources. I just noticed I got it as well on my personal email (which has custom domain) and I don't own any IP ranges.
- _jal 5y agoYeah, I got it to two accounts I use with ARIN, as well as another that is confusing me. That one is not very old, I know I have the entire outbound history for it, and have not used it for ARIN or anything similar.
- jerry1979 5y agoThe twitter link[0] posted in another thread appears to show a copy of the attacker's email. It looks like the attacker sent the email in a bid to lay down psychological cover fire in order to get sysadmins to work with an attacker who would identify themselves as "TheDarkOverlord". [0] https://twitter.com/spamhaus/status/1459452609979371520/photo/1 https://twitter.com/spamhaus/status/1459452609979371520/phot...