6 ms·
As a blockchain security guy, it's really easy to spot the occasional North Korean heists on Ethereum. The big tells are: 1. They hack computers not code. Thei
by danielvf 4y ago
As a blockchain security guy, it's really easy to spot the occasional North Korean heists on Ethereum. The big tells are:
1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code.
2. They immediately exfiltrate the stolen money back to the real world via bazillions of mule accounts that are already standing by. In contrast to the "normal" hacker who attempts to obfuscate and hide funds on-chain, and slip away with some at a far future date.
Here's a writeup from a company after the big 600 million dollar NK hack.
https://roninblockchain.substack.com/p/back-to-building-ronin-security-breach https://roninblockchain.substack.com/p/back-to-building-roni...
- nhooyr 4y ago> Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. That's the primary way hacks are conducted by most hackers. Hackers are primarily social engineers, not technical. Technical hackers are extremely rare regardless of nationality.
- ourmandave 4y agoThe NSA called, they want their 0-day exploits back.
- zwkrt 4y agoIt's not that they don't exist, but the easiest way to gain access to a computer system is always going to be to ask for the password. https://xkcd.com/538/ https://xkcd.com/538/
- Cpoll 4y agoI have no evidence for this, but my feeling was always that the highest-volume exploits were just having a bot run yesterday's Day-0 on every IP listening on a port. You can't get that kind of volume by calling people and asking for their password. If you leave an unsecured mail server accessible to the internet, it'll start sending spam emails within 30 minutes. On the other hand, phishing emails are also automated, and that's essentially asking for the password.
- jcrawfordor 4y agoIt's probably safe to say that phishing is the most common method among APTs like state intelligence agencies. It's cheap, it's easy, it works. No reason to burn zero-days unless simpler methods with less exposure don't work, and they usually do. But we can broadly categorize security incidents into two bins: first are opportunistic attackers which broadly attempt a method that sometimes works. Two common examples are minimally-targeted phishing emails (think Best Buy invoice) and automated scanning for old versions of WordPress with known vulnerabilities. Second are targeted attacks, where the attacker chooses a target and then attempts different methods to reach success. Overall targeted attacks are far less common than opporunitistic ones, but because they involve a higher level of effort they're only attempted when there's a high level of motivation. Targeted attacks tend to result in greater financial losses than opportunistic attacks, for example, because compromising machines to add them to a botnet usually isn't worth the effort of a targeted attack, but getting banking credentials or crypto wallets usually is. All of information security is fairly bimodal in this way. It often seems like even technical professionals like software engineers struggle to understand basic security practices, but I think this is one of the biggest causes: most people tend to think about one case and ignore the other. Unfortunately one of the things that makes security very difficult is that both cases are real and the two require fairly different practices to deter, prevent, and detect. Social methods are far more common with targeted attacks because "true" social engineering involves a higher level of effort, like time on the phone. That said, phishing falls into an in-between where some consider it to be a social method but it is amenable to widespread automation. There's also a wide spectrum of effort in phishing. Many are tempted to try to categorize phishing activity into a binary of "phishing" and "spear-phishing" (I hate these terms), but that doesn't really reflect reality very well. In a large corporation you can usually find examples of phishing that are targeted to varying degrees of specificity: at anyone, at corporate employees broadly, at people in the industry, at employees of a company, a department in that company, and even carefully tailored to a specific employee. The frequency of course tails off as you get more specific, but then it's not that unusual for some organized crime group to run a sustained campaign of fairly closely-targeted phishing as happened recently with Twilio. Opportunistic attacks are certainly greater in volume to the extent that some call them "internet background noise," but most think that targeted attacks probably produce greater total financial damage. Security is very faddish though, not only on the defense side but also on the offense side, so it probably varies from year to year. For example, the emergence of ransomware was a major trend that required a strategic shift in defense in many organizations since ransomware attacks were fairly low effort but also very high damage in many cases.
- breck 4y agoIn 2011 I spent hours writing a script to brute force a wifi password at a hotel because I didn't want to pay $5 a day for wifi. It worked. I was pleased with myself. When I checked out they gave me a receipt and I went to throw it away and saw a handful of wifi passwords in the trash bin. Lesson learned.
- wkat4242 4y agoThose hotel wifi passwords are usually only valid during your stay so if someone throws them out they've likely expired or will do so soon. You still did well writing the brute force. How did you know the composition though?
- big_youth 4y ago> 1. They hack computers not code. Their normal plan is to steal keys by compromising users and computers. This is in contrast to the normal "hack" that works by finding and exploiting bugs in code. I'm just a 'regular security guy' but in that link you posted they detail that after the initial phishing compromise "The attacker managed to leverage that access to penetrate Sky Mavis IT infrastructure and gain access to the validator nodes." They don't detail the bugs that got them access to the nodes but this didn't give them control of the network so "the attacker found a backdoor through our gas-free RPC node, which they abused to get the signature for the Axie DAO validator. ...Sky Mavis requested help from the Axie DAO to distribute free transactions ... Axie DAO allowlisted Sky Mavis to sign various transactions on its behalf. This was discontinued in December 2021, but the allowlist access was not revoked." Sounds like a pretty classic hack to me. They got into the network, got access to some important servers (how? they should be totally segregated from the corporate network). Then found a depreciated endpoint that allowed them blindly sign transactions. This is bread and butter for any pentesting work, makes me wonder if any of these web3 orgs are hiring security firms to test their systems and not just smart-contracts.
- anonkogudhyfhhf 4y agoThe companies getting hacked are not the web3 ones like Ethereum or Terra. They are normally inside jobs with the founders stealing from the "decentralised" network they secretly control. It's the exchanges that are run like traditional business without the magic blockchain power.
- testTED 4y agoEthereum is not a company.
- anonkogudhyfhhf 4y agoNot officially but in practice nothing that distinguishes it from a company
- 4y ago
- blitzar 4y ago> steal keys by compromising users and computers Their keys their coins.
- jareklupinski 4y agoEvery once in a while I'll get a pleasantly worded email from a random address asking if I want to do 'low effort remote accounting services' to the tune of $3.5k a month. I'm almost convinced that this is how they recruit those mule burners, since signing up for employment requires a lot of personal information that can be leveraged into opening bank accounts or other financial vehicles in that person's name.