4 ms·
The beauty of this article is they assume its Chinese probably because of an IP address associated with the Chinese. However, did Mandiant [1] think to time th
by moremetadata 4y ago
The beauty of this article is they assume its Chinese probably because of an IP address associated with the Chinese.
However, did Mandiant [1] think to time the round trip of the packets, in other words, assuming TCP and not UDP used, did the round trip of the return packet take about the right amount of time crossing the globe, or was some switch infrastructure "hacked" or modded nearby perhaps in the same country, which made it look like the packets were going to a Chinese ip address with appropriate time lags?
I bet they didnt!
[1] https://www.mandiant.com/ https://www.mandiant.com/
- delfinom 4y agoPretty sure if we are using packet latency at the means of determine if it's a foreign attacker or not, my entire US based company would look like it's in China because our shitty guaranteed 50 Mbps fiber pipe for our office is always saturated. Wooo US quality internet outside big tech bubble areas.
- imwillofficial 4y agoThis is a terrible metric for attribution. But your overall premise is sound. In the age of vault seven leaks, attribution at the state actor level is really just larping.
- moremetadata 4y ago>This is a terrible metric for attribution. It may be the only metric for attribution, once those packets have left your network, who knows where they go! >attribution at the state actor level is really just larping. Is Larping the new name for Walter Mitty? I know Walter is a favourite with the British establishment. https://www.google.com/search?q=DODIDCA_59_PIV.crl https://www.google.com/search?q=DODIDCA_59_PIV.crl http://crl.disa.mil/crl/DODIDCA_59_PIV.crl http://crl.disa.mil/crl/DODIDCA_59_PIV.crl
- elevation 4y ago> switch infrastructure "hacked" or modded nearby perhaps in the same country That's not how it works. Spoofing a source IP is easy. But if you don't own the IP you spoofed, all the routers on the internet will deliver the target's response packets to an IP that isn't you (some DDoS attacks work this way.) No bidirectional communication could occur this way, and you generally need feedback from a target to assess and pivot. To get bi-directional communications on an IP you're spoofing, you'd have to configure all the internet routing infrastructure between you and the attacker to send you their responses. But once some router in Illinois starts advertising that it can route a Chinese network in 2 hops, you've left a significant written record of your tactics that will make network operators suspicious. You'd get the same effect for much less effort by simply relaying your attack through a computer that's actually in China.
- moremetadata 4y agoSo we know a member of staff was fired, but the data resolution, which may be deliberately vague, is it took place sometime over a 30 day period. Is this like T-Mobile staff not being paid enough and then T-Mobile getting hacked? Now there's lots of attack vectors when staff are involved, some more than others. I know AV software updates are largely signatures of known malware rehashed, but not new malware like Stuxnet which took some AV companies over a year to reverse engineer before they could even decide if it was malware. But depending on the level of access this member of staff had, or depending on how lax NI's IT policies were, it could have simply been something like a switch ACL redirect using Netgears terminology [1] or a Policy Routing [2] to use Cisco terminology off to some other device that appears to be of Chinese origin. Now its unlikely to be a BGP hijack like the one mentioned here [3], but having spoken with Cisco staff in the past, they do have a constant battle with hackers hacking their switches, but when looking at articles like EoL devices not having zero days fixed [4], does this demonstrate an old security risk or newly added security risk designed to force customers to upgrade to newer equipment? Monitoring the CVE's of devices, can highlight business practices, much like Youview here in the UK issuing a final update to multiple TalkTalk TV Huawei DN372T TV boxes which caused them to overheat and hang with now obvious way to downgrade to the previous stable version. Anyway I doubt it was some sort of BGP hijack [5] and I doubt it was some lizard squad-esque home router hack [6], and I am aware some multi functional home devices are simply not as robust as dedicated commercial solutions, by virtue of having a reduced attack vector by being dedicated to one task. But saying that, how hard is it reverse engineer firmware? We see firmware updates when cars engine management software gets remapped, why not an internal switch that for all intents and purposes appears to be the genuine article? There are ways to monitor some devices at the cpu instruction level like an Intel Processor Trace [7], much like a Jtag can also solicit information [8,9,10]. Thing is we dont know and there lots of possible attack vectors which could be deliberately misleading, like a member of staff losing a usb stick with staff data on somewhere between work, the pub and home[11]. Now considering how long ago some of these encrypted devices were lost, if one is stilling holding onto said device, biding time waiting for CVE's to appear in years to come, also seems to be a valid attack vector. I used to do that with my old hard drives all the time, ie put them into cold storage for a few years, then reactive them and see what viruses and other malware were now being detected on them. Its a constant moving target and time always tells, anyway I'm not disputing how things should work, but I know that interesting results can be obtained with misconfigurations. [1] https://kb.netgear.com/21728/How-do-I-redirect-a-traffic-stream-using-the-web-interface-on-my-managed-switch https://kb.netgear.com/21728/How-do-I-redirect-a-traffic-str... [2] https://www.cisco.com/c/en/us/support/docs/ip/ip-routed-protocols/47900-cat3550pbr.html https://www.cisco.com/c/en/us/support/docs/ip/ip-routed-prot... [3] https://news.ycombinator.com/item?id=30561518 https://news.ycombinator.com/item?id=30561518 [4] https://www.bleepingcomputer.com/news/security/cisco-won-t-fix-authentication-bypass-zero-day-in-eol-routers/ https://www.bleepingcomputer.com/news/security/cisco-won-t-f... [5] https://web.archive.org/web/20220629190453/https://bgpstream.crosswork.cisco.com/event/287556 https://web.archive.org/web/20220629190453/https://bgpstream... [6] https://www.forbes.com/sites/insertcoin/2015/07/09/lizard-squad-hacker-who-shut-down-psn-xbox-live-and-an-airplane-will-face-no-jail-time/?sh=72d980dd2ecd https://www.forbes.com/sites/insertcoin/2015/07/09/lizard-sq... [7] https://www.intel.com/content/www/us/en/developer/videos/collecting-processor-trace-in-intel-system-debugger.html https://www.intel.com/content/www/us/en/developer/videos/col... [8] https://spritesmods.com/?art=hddhack&page=3 https://spritesmods.com/?art=hddhack&page=3 [9] https://www.cisco.com/c/en/us/products/routers/8000-series-routers/trustworthy-framework.html#~trusting-hardware-components https://www.cisco.com/c/en/us/products/routers/8000-series-r... [10] https://www.cisco.com/c/en/us/td/docs/dcn/nexus3550/smartnic/sw/user-guide/cisco-nexus-smartnic-user-guide/exanic-x10x40.html https://www.cisco.com/c/en/us/td/docs/dcn/nexus3550/smartnic... [11] https://www.itpro.co.uk/607833/government-usb-lost-in-pub-car-park https://www.itpro.co.uk/607833/government-usb-lost-in-pub-ca...
- HybridCurve 4y agoThis is nonsense. Incidence response teams base their conclusions on whatever forensic data they collect. There are generally consistent patterns of behaviors with state actors and often investigators are even able to identify the different offensive cyber units of nation responsible. While the group of IPs involved would weigh into this calculus, it was likely not nearly as significant as you might be suggesting. What is the point of this conjecture and why suggest there is a reason to doubt their conclusions?