Printer-friendly copy Email this topic to a friend
Lobby General Discussion topic #12678824

Subject: "N.Korea unlikely souce (swipe from security blog)" Previous topic | Next topic
southphillyman
Member since Oct 22nd 2003
90059 posts
Thu Dec-18-14 09:24 AM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
49. "N.Korea unlikely souce (swipe from security blog)"
In response to In response to 0


  

          

honestly i don't know how stupid you have to be to take anything our government reports at face value in 2014 (re:international adversaries at least)



Everyone seems to be eager to pin the blame for the Sony hack on North Korea. However, I think it’s unlikely. Here’s why:1. The broken English looks deliberately bad and doesn’t exhibit any of the classic comprehension mistakes you actually expect to see in “Konglish”. i.e it reads to me like an English speaker pretending to be bad at writing English.
2. The fact that the code was written on a PC with Korean locale & language actually makes it less likely to be North Korea. Not least because they don’t speak traditional “Korean” in North Korea, they speak their own dialect and traditional Korean is forbidden. This is one of the key things that has made communication with North Korean refugees difficult. I would find the presence of Chinese far more plausible.See here – http://www.nytimes.com/2006/08/30/world/asia/30iht-dialect.2644361.html?_r=0

here – http://www.nknews.org/2014/08/north-korean-dialect-as-a-soviet-russian-translation/

and here – http://www.voanews.com/content/a-13-2009-03-16-voa49-68727402/409810.html

This change in language is also most pronounced when it comes to special words, such as technical terms. That’s possibly because in South Korea, many of these terms are “borrowed” from other languages, including English. For example, the Korean word for “Hellicopter” is: 헬리콥터 or hellikobteo. The North Koreans, on the other hand, use a literal translation of “vehicle that goes straight up after takeoff”. This is because such borrowed words are discouraged, if not outright forbidden, in North Korea – http://pinyin.info/news/2005/ban-loan-words-says-north-korea/

Lets not forget also that it is *trivial* to change the language/locale of a computer before compiling code on it.

3. It’s clear from the hard-coded paths and passwords in the malware that whoever wrote it had extensive knowledge of Sony’s internal architecture and access to key passwords. While it’s plausible that an attacker could have built up this knowledge over time and then used it to make the malware, Occam’s razor suggests the simpler explanation of an insider. It also fits with the pure revenge tact that this started out as.

4. Whoever did this is in it for revenge. The info and access they had could have easily been used to cash out, yet, instead, they are making every effort to burn Sony down. Just think what they could have done with passwords to all of Sony’s financial accounts? With the competitive intelligence in their business documents? From simple theft, to the sale of intellectual property, or even extortion – the attackers had many ways to become rich. Yet, instead, they chose to dump the data, rendering it useless. Likewise, I find it hard to believe that a “Nation State” which lives by propaganda would be so willing to just throw away such an unprecedented level of access to the beating heart of Hollywood itself.

5. The attackers only latched onto “The Interview” after the media did – the film was never mentioned by GOP right at the start of their campaign. It was only after a few people started speculating in the media that this and the communication from DPRK “might be linked” that suddenly it became linked. I think the attackers both saw this as an opportunity for “lulz” and as a way to misdirect everyone into thinking it was a nation state. After all, if everyone believes it’s a nation state, then the criminal investigation will likely die.

Wired has just covered this exact point – http://www.wired.com/2014/12/evidence-of-north-korea-hack-is-thin/

6. Whoever is doing this is VERY net and social media savvy. That, and the sophistication of the operation, do not match with the profile of DPRK up until now.

Grugq did an excellent analysis of this aspect his findings are here – http://0paste.com/6875#md

7. Finally, blaming North Korea is the easy way out for a number of folks, including the security vendors and Sony management who are under the microscope for this. Let’s face it – most of today’s so-called “cutting edge” security defenses are either so specific, or so brittle, that they really don’t offer much meaningful protection against a sophisticated attacker or group of attackers. That doesn’t mean that we should let them off and give up every time someone plays the “APT” or “Sophisticated Attacker” card though. This is a significant area of weakness in the security industry – the truth is we are TERRIBLE at protecting against bespoke, unique attacks, let alone true zero days. There is some promising technology out there, but it’s clear that it just isn’t ready yet.

While we are on the subject, and ignoring the inability of traditional AntiVirus to detect bespoke malware, just how did whatever Data Loss Prevention (DLP) solution that Sony uses miss terabytes of data flying out of their network? How did their sophisticated on-premise perimeter security appliances miss such huge anomalies in network traffic, machine usage or host relationships? How did they miss Sony’s own edge being hijacked and used as public bittorrent servers aiding the exfiltration of their data?

8. It probably also suits a number of political agendas to have something that justifies sabre-rattling at North Korea, which is why I’m not that surprised to see politicians starting to point their fingers at the DPRK also.

9. It’s clear from the leaked data that Sony has a culture which doesn’t take security very seriously. From plaintext password files, to using “password” as the password in business critical certificates, through to just the shear volume of aging unclassified yet highly sensitive data left out in the open. This isn’t a simple slip-up or a “weak link in the chain” – this is a serious organization-wide failure to implement anything like a reasonable security architecture.

The reality is, as things stand, Sony has little choice but to burn everything down and start again. Every password, every key, every certificate is tainted now and that’s a terrifying place for an organization to find itself. This hack should be used as the definitive lesson in why security matters and just how bad things can get if you don’t take it seriously.

10. Who do I think is behind this? My money is on a disgruntled (possibly ex) employee of Sony.

Finally for an EXCELLENT blow by blow analysis of the breach and the events that followed, read the following post by my friends from Risk Based Security – https://www.riskbasedsecurity.com/2014/12/a-breakdown-and-analysis-of-the-december-2014-sony-hack

~~~~~~

  

Printer-friendly copy | Reply | Reply with quote


The Cyberterrorists Have Saved Us From A Bad Movie (swipe) [View all] , Melanism, Wed Dec-17-14 05:17 PM
 
Subject Author Message Date ID
i wanted to see it before i defn wanna see it now nm
Dec 17th 2014
1
i didn't care before but i wanna pay money to see it now
Dec 17th 2014
2
      sony = genius.
Dec 17th 2014
14
LOLZ. What a fucking nation of pussies (the US that is)
Dec 17th 2014
3
not risking families getting sprayed up is def pussy shit, yep
Dec 17th 2014
5
      Who are these North Korean uzi toting terrorists? This Red Dawn II?
Dec 17th 2014
8
      Red Dawn was on Esquire Network last night and this
Dec 17th 2014
9
      What if
Dec 17th 2014
11
           i just want to know what people think they are capable of
Dec 17th 2014
15
                Lol we can't! She's hacked too!
Dec 17th 2014
17
                     well i think we know whos behind this
Dec 17th 2014
20
                          Well played
Dec 18th 2014
51
if they drop it on dvd im copping. fuck it.
Dec 17th 2014
4
The biggest FU would be to stream it for free.
Dec 17th 2014
6
*body rolls*
Dec 17th 2014
7
lol.
Dec 17th 2014
10
Color me tickled. I was waiting for this alias.
Dec 18th 2014
48
Bush wouldn't have let this happen, for what it's worth.
Dec 17th 2014
12
Propaganda 101
Dec 17th 2014
13
it aint about the movie or North Korea
Dec 17th 2014
16
      RE: Everyones blaming North Korea becuz the media told you to blame'um
Dec 17th 2014
18
           Theater chains pulled it bc they feared ppl are stupid enough
Dec 17th 2014
19
           RE: Theater chains pulled it bc they feared ppl are stupid enough
Dec 17th 2014
22
           RE: Theater chains pulled it bc they feared ppl are stupid enough
Dec 17th 2014
23
           So taking a full loss on it is better?
Dec 17th 2014
25
           RE: So taking a full loss on it is better?
Dec 17th 2014
27
           Again you only think its North Korea becuz thats what they told you
Dec 17th 2014
31
                U.S. Links North Korea to Sony Hacking (NYTimes swipe)
Dec 17th 2014
32
                     THATS WHAT THEY TOLD YOU...do you not think for yourself?
Dec 17th 2014
34
                     "Senior administration officials, who would not speak on the record"
Dec 19th 2014
95
           yes.
Dec 17th 2014
30
                Explain.
Dec 17th 2014
33
                     no.
Dec 17th 2014
35
                          Thanks for the dialog.
Dec 17th 2014
36
                               i hope it was as good for you as it was for me.
Dec 17th 2014
37
                                    I wasn't trying to snark (initially), btw.
Dec 17th 2014
38
                                         you'll live.
Dec 17th 2014
39
                                              Cool. Your argument doesnt take into account VOD, which I asked abt.
Dec 17th 2014
40
                                                   right on.
Dec 17th 2014
41
           Theatres pulled it bc N. Korea is making good on ALL their promises
Dec 19th 2014
80
           Sony says they have no plans to release it ever, on any platform.
Dec 17th 2014
21
                RE: Sony says they have no plans to release it ever, on any platform.
Dec 17th 2014
24
                     hmmmmmm
Dec 18th 2014
50
Next up, they're going to demand Franco fuck a pig on a live webcast
Dec 17th 2014
26
https://i.imgflip.com/fg0o4.jpg
Dec 17th 2014
28
soooo....where was Anonymous in all of this?
Dec 17th 2014
29
Theater will show Team America for free instead #Texas (link)
Dec 17th 2014
42
LOL. i like it.
Dec 17th 2014
43
Alamo Drafthouse is a fantastic place to watch a movie
Dec 17th 2014
44
ya that place is really nice
Dec 17th 2014
45
NOAP:
Dec 18th 2014
55
      What the entire fuck is going on here?
Dec 18th 2014
56
           either straight up blackmail or they are afraid of the lawsuits
Dec 18th 2014
57
                Is it just North Korea related stuff though?
Dec 18th 2014
58
                if its an inside job, like i feel it is
Dec 18th 2014
61
                afraid of the lawsuits. ANd Paramount/Viacom of getting freshly hacked
Dec 19th 2014
65
So wait, is Kim Jong Un's gf dead or nah?
Dec 18th 2014
46
here to also say
Dec 18th 2014
47
I believe (well don't believe) it.
Dec 18th 2014
52
You're talking about a guy who spends his time collecting Bentleys
Dec 18th 2014
62
All of that is irrelevant if they hired someone.
Dec 18th 2014
54
and on the same front its way sneakier and harder to trace
Dec 18th 2014
60
#7 and #9 are key
Dec 19th 2014
69
"dont believe me just watch"
Dec 18th 2014
53
but the hack actually exposes the corruption
Dec 18th 2014
59
      if you cant see it then you cant see it
Dec 19th 2014
64
           it just seems counter productive to expose their own collusion
Dec 19th 2014
66
                i understand your skepticism
Dec 19th 2014
68
                     my bad sorry for harping
Dec 19th 2014
72
Niggas are really believing this "they could attack theaters" shit.
Dec 18th 2014
63
I don't even think "they" (whoever "they" really is) could attack theate...
Dec 19th 2014
67
      this
Dec 19th 2014
70
           if someone's gonna shoot a theater, they're gonna shoot a theater
Dec 19th 2014
73
                This and this.
Dec 19th 2014
74
                that's such horseshit
Dec 19th 2014
75
                     i find it funny that people like Sorkin
Dec 19th 2014
78
                     This isn't a Regular Joes vs. Hollywood Elites issue.
Dec 19th 2014
84
                          I'm not making that the primary issue
Dec 19th 2014
85
                               Again, why would they "admonish the media" for doing its job?
Dec 19th 2014
86
                                    I guess I wasn't clear
Dec 19th 2014
91
                     The it practices were solid. The attack was sophisticated enough
Dec 19th 2014
79
                          No, every IT pundit on TV & web has said that shit was sloppy
Dec 19th 2014
87
Clooney comments
Dec 19th 2014
71
I am grateful
Dec 19th 2014
76
North Korea was responsible for Sony computer hack, US official says
Dec 19th 2014
77
What do you naysayers know about North Korea the CIA
Dec 19th 2014
81
      their silence
Dec 19th 2014
82
           They haven't been silent. Senior officials told the ny times wed.
Dec 19th 2014
83
                . . .
Dec 19th 2014
90
I'm having a real hard time believing NK has that much tech prowess/inte...
Dec 19th 2014
88
Sony's pals at the NYT explain their side and pass blame onto Rogen:
Dec 19th 2014
89
That's laughable
Dec 19th 2014
92
Yup. Particularly since there's email chains of him talking to the exec...
Dec 19th 2014
94
This line is gold considering the leak showed the opposite
Dec 19th 2014
93
SIIIIIIIIKE!! They gon run with it in indie theaters & VOD (swipe)
Dec 23rd 2014
96
this is so silly.
Dec 23rd 2014
97
I don't know, If I were Rogan and Franco I might be happy with all of th...
Dec 23rd 2014
98
Now available on Youtube and Google Play.
Dec 24th 2014
99

Lobby General Discussion topic #12678824 Previous topic | Next topic
Powered by DCForum+ Version 1.25
Copyright © DCScripts.com