Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
How Did Snowden Do It?
Newest First  |  Oldest First  |  Threaded View
math scandals
50%
50%
math scandals,
User Rank: Apprentice
12/11/2013 | 2:49:40 AM
re: How Did Snowden Do It?
Watching hearings between NSA and congress, saw Director of NSA either lie 3 times or was reciting a script. Reportedly, when first appointed told NSA "I
don't know math, u figure it out". Heard congress parrot stuff i.e. -have been doing
"metadata long time". If u asked "what do u mean by metadata? What is it like ?/
functions vs say 'metadata in a word doc?" Clueless.

If I asked congress or NSA director if agency using DPI, what is that, what info does
it reveal?, doubt either could answer in intelligible fashion. They need to pay competent security consultant for hearings. Consultant would ask right questions,
know if NSA hedging, lying etc. Security could explain program in english.

Those phd 'pure mathematicians' that code crack are so out there. Few know that
math. Totally not math used by engineers, cpas etc.Mad at how math taught in school, some try to write books to make it kool for us.Typically they lose one after symmetry of pine cones and fibinachi numbers. LOL

Those code crackers get blamed for much global mischief. Has led to some strange
"conspiracy notions" among supposed allies. Guess congress needs to know bout
them too.

Get EZ-some in NSA that don't like snooping. Went thru channels. 2 rumors early
1) they loaded drive for him, 2)cia tip or both. Al quada changed phone, email codes before al alaki got droned., not after snowdon as director said. Some reg folks changed behavior tho.
Kevin Bocek
50%
50%
Kevin Bocek,
User Rank: Apprentice
11/18/2013 | 8:43:54 AM
re: How Did Snowden Do It?
Self-signed certs are being used to exfiltrate data even when paper organization policy does not allow it. Security bulletin from Cisco provides example background http://tools.cisco.com/securit...
Kevin Bocek
50%
50%
Kevin Bocek,
User Rank: Apprentice
11/18/2013 | 8:40:08 AM
re: How Did Snowden Do It?
Snowden's root access would have been limited to the systems he had access to. The 10,000+ pages of docs and other reports indicate he gained access to many more systems than he had admin privileges. SSH provides both the means for elevated privileged and also encryption to evade detection. Attackers have been known to take SSH keys or insert their own as trusted and gain access thereafter. Self-signed certs here are about exfiltrating data not accessing. Mandiant, Cisco, and others have reported on increased used of self-signed certs. Admins (or attackers) can generate self-signed certs at will even if paper policy doesn't allow for it.
marioa315
50%
50%
marioa315,
User Rank: Apprentice
11/14/2013 | 8:51:02 PM
re: How Did Snowden Do It?
Have to agree with Charlie on this one. I was asking myself all the same questions. Why would the NSA of all people allow self signed certs? Why would he need others credentials if he had root? And just because you can sign on as someone else does not mean that you suddenly have in your possesion their cert for later use. If implemented properly, it should only be available for use while logged into that account. But then again, the NSA could have been set up poorly to begin with. I am just assuming that they had better sense than that.
CharlieW848
50%
50%
CharlieW848,
User Rank: Apprentice
11/14/2013 | 7:55:53 PM
re: How Did Snowden Do It?
Whoever fed you this information is full of crap. But I guess if I was to point the finger at someone, I would come up something very technical so everyone would believe it.

So, why would someone with root level access, need other credentials with user level access to get to data? And....since when does govt systems (even at the lowest level) trust self-signed certificates? Ah..they don't because if they did, there would be a major hole in the security of gov't networks.
rjones2818
50%
50%
rjones2818,
User Rank: Strategist
11/14/2013 | 7:55:48 PM
re: How Did Snowden Do It?
Hire the man! :)
Don Gray
50%
50%
Don Gray,
User Rank: Apprentice
11/13/2013 | 9:09:52 PM
re: How Did Snowden Do It?
And that boys and girls is why we advocate 24x7 log / alert monitoring using contextual enrichment!

The NSA obviously didn't:

- Perform monitoring on anything approaching a real-time basis
- Didn't have the ability to tie user context into the security policies and controls
- Didn't have Intranet "normal usage" thresholds in place

Detecting technically authorized yet out-of-defined-role access is nearly impossible without these capabilities available and the people and process to execute.


HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11565
PUBLISHED: 2020-04-06
An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa.
CVE-2020-11558
PUBLISHED: 2020-04-05
An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_m...
CVE-2020-11547
PUBLISHED: 2020-04-05
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.
CVE-2020-11548
PUBLISHED: 2020-04-05
The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.
CVE-2020-11542
PUBLISHED: 2020-04-04
3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.