4 ms·
While hill staffers and other washington movers and shakers were being carpet bombed two years ago during budget negotiations, it was really eye opening how muc
by trotsky 14y ago
While hill staffers and other washington movers and shakers were being carpet bombed two years ago during budget negotiations, it was really eye opening how much individual effort was put forth. They were exploiting a flash 0-day that was embedded in various .xlsx .docx and .pdfs - pretty slick as it got them around noscript policies and outside any sandboxes.
The turn around time was crazy - on at least two occasions the workflow went:
recent victim gets first/early copy of policy paper written that day -->
document is taken, translated to a different format and has 0 day inserted -->
emails with exploit are sent to no more than 10-15 people the victim frequently discusses the topics covered in the paper with. -->
Many include personalized notes that include observations the victim had sent to the author -->
Time from initial email receipt to exploits all mailed: around 3 hours
Now that's how you get a 95% open rate.
related:
http://contagiodump.blogspot.com/search/label/CVE-2011-0611 http://contagiodump.blogspot.com/search/label/CVE-2011-0611
- mshron 14y agoCitation needed? If true, that's a pretty crazy story.
- modeless 14y agoYeah, what? Who is sponsoring 0-day exploit attacks against Hill staffers? Do the parties go that far to get an edge against each other in negotiations? That seems like it would be front page NYTimes material.
- snowwrestler 14y agoChina.
- codemac 14y ago> Who is sponsoring 0-day exploit attacks Anyone who could profit is our starting set. And the budget for the federal government funds massive amounts of private entities that have a vested interest in finding out ahead of time what their and their competitors funding will be. Notably, hedging their bets on an exchange. And, maybe obviously, some of these private entities are the very entities that are consulted for the federal government's email and computer security policy.
- ubernostrum 14y agoPolitical parties in this country would never stoop to criminal activity to gain strategic information. Why, if such a thing were to happen, and to involve high-ranking government officials, I bet it would be a major national scandal and maybe even lead to some unprecedented resignations!
- tripzilch 14y agoSounds like something types like HBGary could've been hired to do.
- niels_olson 14y agoSiri: remind me to downvote Trotsky if no citation provided by Monday