Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
grugq
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
grugq
2mo ago
Bulk reply to all the people replying. bink is correct. The people who buy exploits are governments. There is very little interest in Wordpress or indeed any target that isn't a browser or a mobile. Browsers and mobiles are the only th
2.
▲
by
grugq
2mo ago
this is the most accurate summary.
3.
▲
by
grugq
2y ago
There has been some research done on this particular anonymous newsgroup. “Deanonymising alt anonymous messages” https://www.youtube.com/watch?v=l5JBMyxvuH8 The accompanying blog post is here: https://ritter.vg&#
4.
▲
by
grugq
2y ago
> Even minutiae should have a place in our collection, for things of a seemingly trifling nature, when enjoined with others of a more serious cast, may lead to valuable conclusion. — George Washington.
5.
▲
by
grugq
2y ago
In retrospect I really should have included the title with the link.
6.
▲
by
grugq
2y ago
And you can detect when you are being ptrace()d because a process cannot be ptrace()d twice. Unless they changed Linux again. There are also timing issues that show up, and you can do any number of anti-debugging tricks which would reveal t
7.
▲
by
grugq
2y ago
Author here. The context of this post is somewhat important. It is a direct response to a post titled: Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat Userland rootkits are not “ nearly-impossible-to-detect
8.
▲
by
grugq
2y ago
Bringing your own static linked busybox will still evade that rootkit. If the attacker has modified the environment to present a specific view of system state, bringing your own environment defeats it. There are tricks which are better than
9.
▲
by
grugq
2y ago
"Prabhakar Raghavan is killing Google" "Google's Death from Within: Prabhakar Raghavan" "Blame Prabhakar Raghavan for Google's Crappy Search" "Google Sucks. Because of Prabhakar Raghavan" &q
10.
▲
by
grugq
3y ago
Oh, it’s far far worse than that. Just the core operation would be: open() — network round trip fstat() — network round trip brk() — network round trip read() — network round trip Shuffle data over network read() — network round trip
11.
▲
by
grugq
3y ago
Merry OPSEC, and a happy OPSEC Year!
12.
▲
by
grugq
3y ago
Yup, probably the more robust approach.
13.
▲
by
grugq
3y ago
Syscall proxying was very old even when I wrote that article. The problem with syscall proxying is that it is slow. Take any process and imagine adding network latency to every single syscall. On a local network is incredibly slow, but over
14.
▲
by
grugq
3y ago
Ah, so, in 2005 I wrote about that when I implemented rexec() — remote exec() — which takes a binary and then copies it over an arbitrary text only link (like ssh) and executes it completely in memory without touching disk. http:/
15.
▲
by
grugq
3y ago
The history actually goes back quite a bit further. Exactly 20 years ago I wrote and released userland exec(). https://seclists.org/bugtraq/2004/Jan/2 Good to see that the technique is still viable after two
16.
▲
by
grugq
3y ago
he was more specific, but I (a) don't remember the name off the top of my head, and (b) don't think it is beneficial to put them on blast. It isn't their fault they got hacked 20 years ago.
17.
▲
by
grugq
3y ago
What is there to say about the hack? Like everything back then it was probably accomplished by exploiting trust relationships. I can ask him, but it is not at interesting 20 years later.
18.
▲
by
grugq
3y ago
the hacker. I interviewed the sysadmins about it.
19.
▲
by
grugq
3y ago
Am I missing something? That seems to link to a Linux backdoor, not a backdoor in Linux.
20.
▲
by
grugq
3y ago
I have the full story on that incident. It is actually really funny. If the guy who did it wants to come forward, that is his decision. [edit: I won't name names.] He did provided me the full story. He told me with the understanding th
21.
▲
by
grugq
3y ago
It didn’t exist when I wrote this.
22.
▲
by
grugq
3y ago
The original date for this is actually 2004. Maybe 2003, but I can’t find an archival link. I wrote the code because someone asked how to do this and it was easier to implement it than to explain it in detail. The whole thing is based on wh
23.
▲
by
grugq
3y ago
It is actually from 2004. :)
24.
▲
by
grugq
3y ago
I invented it, as far as I know. There was no publicly available code on doing this and so I wrote it. I’m not sure what the terminology is these days, but I called it userland exec() because it was an implementation of execve in userland…
25.
▲
by
grugq
4y ago
What they’re talking about is called “apparent cover.” That is, a cover story which you don’t have to tell anyone, they make it up in their head from the clues you provide. For example, if you see someone at dawn on the docks with a tackle
26.
▲
by
grugq
4y ago
It used to be worse under Pierre. His personal mission in life was to make sure no one dodgy ever got a license and to hunt down every possible source of a cracked copy. My manager had purchased a license for me because it was cheap enough
27.
▲
by
grugq
4y ago
Related. Here is a good lecture on project modul, the initial work looking at sound propagation in the atmosphere. https://www.youtube.com/watch?v=k4ygiQHSNDc
28.
▲
by
grugq
5y ago
Creating a long fake is riskier than a short fake. Making mistakes is a risk, and so the more content the more risk. As for the “reality” of working as an analyst in FSB it seems pretty accurate. Even if not true, it carries a certain truth
29.
▲
by
grugq
5y ago
This is the closest to correct. There are some other valuable things state level threat actors have at their disposal.
30.
▲
by
grugq
5y ago
Everything she writes is great.
More ›