25 ms·
We may have witnessed a NSA "Shotgiant" TAO-like action
- mjolk 13y ago>In 2012, during an incident, we watched in real time as somebody logged into an account reserved for Huawei tech support, from the Huawei IP address space in mainland China. I'm a little skeptical. I wonder what they mean by "watched," because I doubt that they guessed the tty for reading or that the hacker joined a screen session. What is the likelihood that one would just "happen" to be staring at that server during an "incident."
- TrainedMonkey 13y agoFrom encrypting and emailing to a hotmail account, it sounds like they connected with Teamviewer/VNC type of software and author was watching what was going on the screen. I am somewhat skeptical as well.
- willvarfar 13y agoUnless the support staff use screen sharing software for doing support, and what was witnessed was an unannounced support session?
- dmix 13y agoGoogle "live incident response" software. The author works for a security company, they get hired to detect malware and intruders. You can remotely connect to machines and analyze memory, commands, etc. It doesn't matter what TTY it was when you have full system access. http://digital-forensics.sans.org/blog/2011/07/21/live-mem-forensic-analysis http://digital-forensics.sans.org/blog/2011/07/21/live-mem-f... https://code.google.com/p/grr/ https://code.google.com/p/grr/ https://www.mandiant.com/resources/download/redline https://www.mandiant.com/resources/download/redline
- jessaustin 13y agoI wonder what they mean by "watched"... My interpretation was that after IDS had identified a particular host, they had tailed syslog (or the equivalent) on that host. The observation that they would have missed it if they hadn't been watching seems to imply that normally their logs wouldn't have retained the level of detail needed to see either the event or the deletion of the logs of the event.
- robertgraham 13y agoIt was an internal system. We noticed with 'netstat' that it had a connection to an outside system. 'who' told us it was the account setup for Huawei remote support, and the IP address told us indeed that it was from a Huawei network. The SQL query took 15 minutes to run. We saw it using 'ps'. We then kept dumping their '.bash_history'.
- peterwwillis 13y agoThat's weird. Bash_history doesn't usually get flushed for every command you run; only when you exit an interactive shell. If you `kill -9 $$` or erase the .bash_history file and create it as a directory, it loses the history. The exception is if you create a custom PROMPT_COMMAND="history -a; history -n", which would append on each new bash prompt. (You'd think a hacker would know these things...?) As an alternative to dumping history, if your system has perl and strace and you want to watch a live ssh or bash session, I wrote a script that will do that. https://github.com/psypete/public-bin/blob/public-bin/src/system/dumpfd.pl https://github.com/psypete/public-bin/blob/public-bin/src/sy...
- acdha 13y agoThat "history -a" bit is extremely common if the environment has shared storage like NFS in use or multiple shells are common. It would not surprise me at all to see it on by default on an account used for debugging / support purposes as a cheap audit measure.
- gwu78 13y agoIt seems hard to believe someone doing something like this would not at least try to cover their tracks. export HISTSIZE=0? And how do you know these were unmodified versions of netstat, who and ps that you ran? Do they have mtree in this OS? I'm no security expert but this little story just sounds very unsophisticated given the seriousness you are attributing to it.
- jnbiche 13y agoSo what was the SQL query?
- noir_lord 13y agoSELECT * FROM USERS WHERE TERRORIST='1'
- LukeWalsh 13y agoSELECT * FROM HIDE_FROM_AMERICANS; ?
- notastartup 13y agoSELECT * FROM Foreign_Corporations fc INNER JOIN Foreign_Corporation_Employees fce ON fc.FCID = fce.FCID WHERE fc.Country IN ('Pakistan', 'Afghanistan', 'Iran')
- robertgraham 13y agoI can't reveal the exact SQL query because that's customer private information. However, it had both a subject and a timeframe that were peculiar. Googling the subject revealed news stories about it -- making it clear this was something the U.S. was interested in, but which would be no particular interest to anybody else.
- saraid216 13y agoCan you reveal the subject and timeframe? It doesn't seem like those would require customer private information.
- pja 13y agoIf you have a restricted timeframe & the information that the US government would be interested in knowing details about an event that happened in that timeframe, then that might well be enough information to identify the company involved, or at least reduce the list of candidates to a very short one indeed. The OP probably has a contractual duty to protect their client's identity & therefore can't take the risk that revealing more details would result in their client being identified.
- noir_lord 13y agoThe normal guidelines for developing a security strategy is to estimate the resources and capabilities ranged against you and the probability they will be levelled against you and then develop a strategy for mitigation (absolute security is impossible). The capabilities the NSA and GCHQ have developed are scary enough in and of themselves but the sheer breadth and depth of what they have achieved is far more horrifying, If I was the CTO for a large multi-national or a foreign government I'm not even sure where I'd start protecting against them.
- jobu 13y agoWhat I don't understand is why the US government would point fingers at the Chinese for putting backdoors in Huawei devices when it was really the NSA all along. It seems like they're shooting themselves in the foot by giving pointing out the backdoors. My best guess is that they assumed someone would figure it out eventually and they wanted to spread misinformation to get out ahead of that. Has anyone else come up with a better reason?
- UVB-76 13y agoI don't think they are referring to the same vulnerabilities. The US government was publicly accusing the Chinese government of inserting backdoors in Huawei products, while at the same time seeking and exploiting vulnerabilities in Huawei products themselves. Perhaps this was an attempt to cover tracks by pre-emptively blaming the Chinese government for backdoors installed by the US government, should these backdoors ever be discovered. Personally I'm inclined to call Hanlon's razor on the hypocrisy of it all.
- Ihmahr 13y agoI think an important part of the mission of the NSA is to spread fear, so that people are more likely to consent. This means terrorist (which of course isn't really a danger if you look at the numbers), nuclear Iran, cyber China, etc.
- at-fates-hands 13y agoTwo things. First, if its fear they're trying to spread, it's working. No way I'd ever use a Huawei device, ever. Secondly, do you think a nuclear arms race in the middle east would be a good thing??
- stephengillie 13y agoOne of the best ways to distract others from blaming you is to publicly accuse them of doing what evils you're secretly doing.
- ypeterholmes 13y ago
- paul 13y agoWhere there are security vulnerabilities, I'd rather it be the NSA exploiting them than someone else. The fact that Huawei support engineers have so much power is much more troubling.
- Nacraile 13y agoI think it's naive to assume that the NSA is the only entity that is likely to be able to exploit vulnerabilities. This is the crux of the controversy around NSA's attacks on web security. I only see a difference between an opaque, unaccountable organization in the USA and an opaque, unaccountable organization in China when I look through a nationalistic lens.
- deleted 13y ago[deleted]
- lukeschlather 13y agoQualitatively speaking, I think as opaque as the NSA and CIA are, they're more accountable to the average US Citizen than their Chinese equivalents are to the average Chinese citizen. They're less accountable than I would like, but they are accountable for their actions.
- insuffi 13y agoCan you point to that quantitative evidence and where NSA has been held accountable? I smell propaganda in the air.
- JumpCrisscross 13y agoFISA Courts. Senate Intelligence Committee. Yes, sometimes they have been ignored, and yes, sometimes they have been rubber-stampers. But presently both are, in some capacity, rebelling and, in some capacity, angling to reign in the intelligence bureaus. Nothing similar exists in, for example, France, Russia, China, or India.
- RankingMember 13y agoIt's scary to think that a third of the internet relies on any one company's backbone products, regardless of the country that company calls home. Way too many eggs in one basket, but much easier for the humans involved compared to having a ton of different manufacturers who would have their own individual issues. Find an exploit once, employ it (most) everywhere (appropriation of old Java tagline).
- italophil 13y agoIt's one thing getting spied on by the US government, but one would hope they'd use something more sophisticated than Hotmail to move the information around.
- makomk 13y agoTrouble with that is, the more sophisticated and unusual the mechanism you use, the more likely it is that someone will (a) notice you, and (b) be able to identify you based on it.
- robertgraham 13y agoThat's my theory. Any monitoring of outgoing information would just see a typical attachment to a hotmail address.
- diminoten 13y agoWell, it was encrypted, and they can't exactly send it to "nsa.gov", can they?
- dantiberian 13y agoHotmail seems like a reasonable first link in the chain to extract the information. I assume they would log in through Tor or another anonymous method before extracting it to its final location. They're not going to email it to joe.spy@nsa.gov directly.
- pkinsky 13y agoIt's a dead drop. If this was cold war era Moscow, they'd use a drainage ditch or a loose brick. Hotmail is just the digital equivalent.
- brown9-2 13y agoA backdoor or 0day for a Huawei router would be of limited use to the NSA, because the control ports are behind firewalls. Hacking behind firewalls would likely give full access to the target network anyway, making any backdoors/0days in routers superfluous. But embedding themselves inside the support infrastructure would give the NSA nearly unlimited access to much of the world. Huawei claims that a third of the Internet is running their devices. Almost all of it is under support contract. These means a Huawei support engineer, or a spy, can at any time reach out through cyberspace and take control of a third of the Internet hardware, located in data centers behind firewalls. So the companies that use Huawei's products put the control ports behind their firewalls, but somehow are allowing unrestricted access through that firewall to/for Huawei's support mechanism? Is that common?
- ds9 13y agoI was skeptical of that too - however, another part of the article implied another scenario, leaving it unclear whether the writer confused them or refers to both. The second scenario is, company may control its own gear well enough, but relies on a service provider that uses Huawei devices, and the Huawei support people can access comms thru the latter. Which begs questions about encryption, so the implications are murky.
- robertgraham 13y agoExtremely common. It's the norm today that companies have firewall/VPN holes allowing support engineers from other companies to have access to their networks, to manage things as simple as the HVAC system, or things as complex as their entire routing infrastructure. Throughout the world, most Huawei routers come with such support contracts.
- eropple 13y ago> to manage things as simple as the HVAC system Hello, Target breach. =)
- sliverstorm 13y agoI'm guessing what that means is something like this: 1. Huawei has support contracts 2. Huawei needs to be able to interact with their hardware to execute those support contracts 3. Companies don't want to expose routers 4. Huawei routers "phone home" (i.e. query Huawei) and in this fashion allow Huawei support to establish a connection
- diminoten 13y agoI'm not sure if this is in any way useful, but consider that Ed Snowden himself was in a "support"/administrator role and that's what gave him access to the documents he later then leaked.
- jontas 13y agoI dont understand why this level of access (if it is accurately described in the article) would only be of use to American intelligence, and "would['t] interest other intelligence services -- except to pass it on to the Americans." It seems like something that powerful would be of interest to any intelligence service (or group of any sort), anywhere.
- sliverstorm 13y agoYou misunderstand. The author is saying that the particular SQL query they saw executed, would only return data interesting to Americans
- danielweber 13y agoThat's leaving a lot to his interpretation. Chinese intelligence might be interested in something simply because they (correctly or not) deduce that American intelligence will be interested in it.
- sliverstorm 13y agoObviously, but I'm just clarifying here.
- vampirechicken 13y agoHow does the support login have the privileges to delete all of the activity log files, and why is a login with enough privilege to delete logs allowed to perform SQL queries?
- malandrew 13y agoWhat we really need is a new agency just like the NSA except for it's only mandate is closing holes everywhere even if those holes are actively being exploited by the NSA and CIA. Such an agency would actively discover holes, patch them when possible or disclosing the vulnerabilities to the engineers responsible for the software or hardware in question. Furthermore, the NSA and CIA would need to be barred from trying to get any access to this organization for its own use.
- danielweber 13y agoThis blog post is trying to say something tremendously important but it also is not giving us any information to evaluate it. Apparently everything is on fire but they can't tell us how.
- eli 13y agoI don't understand why there's a sharp distinction between installing a backdoor and using stolen support access as a backdoor.
- tzs 13y agoTAO? Edit: finally found it, with some Googling. There are a lot of things with TAO as their TLA leading to a lot of false leads. TAO in this story means "Total Access Operations". Edit 2: "tailored", not "total".
- mikecb 13y agoTailored.
- MatthiasP 13y agoTailored Access.
- tptacek 13y agoAmong vulnerability research people, TAO is practically slang for "the branch of NSA that hacks into Chinese computers". Robert Graham comes from those circles. I think that's what he's trying to evoke by referencing TAO.
- throwaway7767 13y agoI was not aware that the NSA had decided to restrict TAO's operations to China. That must be a very recent thing if so. Can you provide any references to that?
- sgt101 13y agoWitnessing in this way runs counter to my experience of system management. How can you see (in real time) a query, the encryption, the email and the log deletion? I have run sql monitors and I see queries appear and then disappear... but my brain doesn't allow me to understand what the user is "up to" without lots of investigation and so on.
- peterkelly 13y agoOne of the biggest ironies of the Huawei hacking case is that now every time someone detects an attack from a Huawei device or the company itself, they can never be sure if it's China or the US that's behind it.
- einhverfr 13y agoThis sort of thing is significant. It puts remote support for systems in a very different light. At Efficito, we have plans to release on-premise appliances as well as our cloud hosting options. This sort of story makes me think about how to avoid this sort of problem. Here are rules I am suggesting. 1. The on-premise appliance should not be directly accessed from the network unless folks at the local environment enable contact. 2. Everything else, regarding services, should be loosely coupled and designed not to give significant access to either party over the other. This sort of thing strikes me as an area where the industry is going to have to evolve. The danger of "we can connect to your systems" is becoming clearer to a larger section of the market.