5 ms·
https://search.edwardsnowden.com/docs/IHuntSysAdmins20140320 https://search.edwardsnowden.com/docs/IHuntSysAdmins20140320 This reads like a reddit or HN post.
by robwormald 11y ago
https://search.edwardsnowden.com/docs/IHuntSysAdmins20140320 https://search.edwardsnowden.com/docs/IHuntSysAdmins20140320
This reads like a reddit or HN post.
"Yeah, that pretty much makes sense, but how are you 'just gonna get CNE access' on an admin?"
(S/SI//REL) Good question, thanks for asking. Most of the time I'm going to rely on QUANTUM to get
access to their account (yeah, you could try spam, but people have been getting smarter over
the last 5-10 years... it's not as reliable anymore). So, inorderto work our QUANTUM-magic on an
admin, we'll need some sort of webmail/facebook selector for them.
"You know, you could just look up the 'point of contact' in the registry information associated
with their IP space/domain names..."
(S/SI//REL) Yeah, you could do that. Personally, I haven't had a huge amount of luck with it,
because most of the time I end up running across their ♦official* e-mail address that's hosted on
their own network. That's generally not a recipe for success in the QUANTUM world, what we'd
really like is a personal webmail or facebook account to target. There's a couple ways you could
try' this: dumpster-dive for alternate selectors in the big SIGINT trash can, or pull out your wicked
Google-fu to see if they've posted on any forums and list both their official and non-official e-mails
in a signature block...but what if there was another way to do it?
(S/SI//REL) If a target that I care about is on a network that I don't have access to. in this post I
described that I will try to get access to that network by targeting the sys admin. In order to
target the sys admin, it's easiest if I know what their personal webmail/facebook username is so
that I can target it with QUANTUM. The hardest part is identifying that admin's personal account
to target in the first place.
Now, fade off with me into dream-land. Pretend that we had some master list. This master list
contained tons of networks around the world, and the personal accounts of admins for each of
those networks. And any time you wanted to target a new network, you could just find the admin
associated with it, queue his accounts up for QUANTUM, get access to his box and proceed to pwn
the network. Wouldn't that be swell?
- robwormald 11y agoQUANTUM https://search.edwardsnowden.com/docs/CaseStudiesofIntegratedCyberOperationTechniques20140312 https://search.edwardsnowden.com/docs/CaseStudiesofIntegrate...
- unreal37 11y agoYes I reading this too. Very interesting. Earlier in the doc, he says: "...our ability to pull bits out of random places of the Internet, bring them back to the mother-base to evaluate and build intelligence off of is just plain awesome! (S/SI//REL) One of the coolest things about it is how much data we have at our fingertips. If we only collected the data we knew we wanted...yeah, we'd fill some of our requirements, but this is a whole world of possibilities we'd be missing! It would be like going on a road-trip, but wearing a blindfold the entire time, and only removing it when you're at one of your destinations...yeah, you'll still see stuff, but you'll be missing out on the entire journey!" They really do have a different view of privacy. Only being giving what you're specifically seeking is like going on a trip with a blindfold on! Well, yes, yes it is!
- dTal 11y agoThis, I think, is single most damning piece of evidence regarding NSA culture. From the horse's mouth: they collect as much data as they can, not because they need to, but because it's interesting.