Experts Closing In On Google Attack Coders
ancientribe writes "The targeted attacks out of China that hit Google, Adobe, and other US organizations are still ongoing and have affected many more companies than the original 20 to 30 reported. Security experts now say they are getting closer to identifying the author or authors of the malware used to breach Google and other organizations."
Google is a propaganda partner of US. It has blocked users from Syria and Iran since 2008 - http://www.pbs.org/mediashift/2008/10/google-blocks-chrome-browser-use-in-syria-iran287.html
The US media, however, is eager to twist the story. Why should I trust them to be any more honest in talking about China?
The largest prime factor of my UID is 263267.
Why on earth would I download and run the "inoculation" removal software from some unknown company? It might actually be installing more crap! Why not just give us a shell script if it's just wmi calls?
Possible links to Australia porn retaliation!
Mysterious "Anonymous group" still unavailable for comment.
Results 1 to 10 of 5,000,000,000 for "google wannabe hackers".
...
1. Some Script Kiddie
2. Wannabe h4xx0r
The Kai's Semi-Updated Website Thingy
Links to attack on Australian porn censorship! Mysterious group know as "Anonymous" still unavailable for comment!
As soon as the United States identifies the culprits in China...wow are they in trouble.
Weaselmancer
rediculous.
Do you really expect that they would say anything else? "Sorry guys, this one has us stumped, we've no idea who did it." There are 15 paragraphs in TFA, and they've used them to not say a damned thing. Why did they even put this press release out?
*runs*
...One finds them self hungry again in an hour.
I failed to do enough research. Is there a way I can delete the parent post?
The largest prime factor of my UID is 263267.
But I'm an anon coward, muhahaha. Trace that!
Probably a Kuang Grade Mark Eleven. Big mother.
Hoglund says HBGary was able to identify "markers" specific to the way the Aurora developer wrote the malware. But he says his firm did not include this in its new report. "This is not in the report because we don't want him to know what we know about his coding," he says. "[It] is algorithmic in nature."
Hah riiiight. So just give out hints in the press release? More like, "we don't want to share this information cause it's profitable."
that's teh shizzle bizzle
Your love is fading ...
I just made a giant masterpiece printed all over the greatest world newspaper nerds!
My brother is wearing the other one ...
Such a bitch. Everyone knows the other Google is dirty.
About 80 percent of APT attacks use custom malware, Mandia says. "We recently took over 1,800 programs we've collected since 2008 that are all part of APT ... and ran it through AV, and only 24 percent of the malware triggered antivirus," he says. "Over a year ago, none of it was triggering AV."
Signature-based anti-virus scanning isn't going to help. That model is broken and only useful for the "AOL mindset" of the general public. That is, the people who go "ohhhh, SHINY. [click]" and get infected by year-old malware.
Serious pressure on software vendors to make sure their app doesn't need admin rights to run on a Windows box would be a nice step.
Learning HOW to think is more important than learning WHAT to think.
Well that didn't last long. Nothing worked anymore.
To get my box back, I had to both make my Program Files folder writable, and I had to give my "Mike" account administrative priveliges.
That's just plain wrong.
Request your free CD of my piano music.
But these damn Chinese names all sound the same to a westener's ear.
Ya know that old joke, how do you choose the name for your Chinese child? Drop a silver spoon on a piece of Jade and the sound created is the name.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Is there a way (to) delete (a Slashdot) post?
That depends. Is your name Xenu?
an operating system Where i7 was when
I'm guessing the "hacker" responsible listed their name in the comment header. /*
* goofle -- program exploits vulnerabilities @ google.
*
* Author: Johnson "the tiger" Zhang
*
* Purpose: Repress dissidents and hack pron site passwords.
*
* Usage: goofle --help
*
*/
#include ...
Yeah I know comments don't make it through compilation.
In retaliation to the investigations and accusations, BAE Uk got a massive attack wave this weekend, much larger than anything Google saw. All the attacks came from proxys, but deeper probes showed all the traffic was from china.
BAE had all their systems crippled and apprently had shut the whole network down(we are talking about thousand upon thousands of machines), reset all passwords and wipe a lot of boxes. You wont hear this in the news though. It would be seriously bad for business if the US and Uk governments got wind of it.
China* wont go down without a fight.
*whoever is organising it.
Stupid american lady!
... everyone knows who did it. It was the CaoNiMa, or the grass-mud horses as you may know them. I really hate those mother f@#$%&s.
I can only imagine two outcomes to this: the perpetrators are found, and are found to be _not_ (in the pockets of) the Chinese government, and they are found precisely because of this: I mean, we're talking about *Google*, the *US* and *China* man ! To hell with ordinary malware creators and spamhouses that no law enforcement ever seems to be able to nail, this is important !
Or, they are (suspected to be) still of the Chinese government, in which case it likely dead-end somewhere.
Both outcomes would make me kind of cynical, but that's just me.
Religion is what happens when nature strikes and groupthink goes wrong.
What I meant was that I didn't permit regular users to write into Program Files. My problem was that quite a few of the applications I had installed expected to be able to write into their own installation folders. Even Microsoft is an offender - one has to be an Administrator to run the Visual Studio debugger. I don't see why that should be necessary, unless one is debugging a Service. If one is debugging a non-Administrative executable, Administrative priveliges shouldn't be necessary at all.
Request your free CD of my piano music.
Some states do use secret "Echelon" system to break into private and other states' communication systems. Yes, supposedly and by a self-proclamation these are the "good guys".
Is it a feasible international framework that if one feels himself to be a "good guy" he can eavesdrop on electronic systems? But if he looks like a bad guy, speaks in some exotic ethnic language, then it is a condemnable behavior.
But to Chinese and other Asian people we look like strange exotic humans. There is even a word for European-like people in Asia - "long-noses". And when one lives there it feels exactly this: being a "long nose" among normal people.
So they know that good guys eavesdrop on them with an "Echelon" and keep silence philosophically, but when they try to get some info via eavesdropping a commercial company "Google", it causes a global panic. Or do I get it wrongly?
Maybe it makes sense to lead by an example?
system("wget http://www.google.com/search?q=google");
Security experts now say they are getting closer to identifying the author or authors of the malware
Translated: They now have narrowed the list down to a hand full of people, and will soon decide who will be the best scapegoat. ;)
Any sufficiently advanced intelligence is indistinguishable from stupidity.
Come on baby...and OF AMERICA) is the were compouEnded
forget the authors, who paid them?
We have to find the villains who did this nefarious thing. Otherwise, we'd lack scapegoats and would have it admit to ourselves that:
- Adobe didn't learn a single damn lesson from Microsoft's Word Macro Virus debacles as to why allowing code to be embedded in what most users consider to be a static, non-code executing document is such a bad thing.
- A business that supposedly hires the Best And The Brightest and discards applicants due to bad SAT scores 15 years ago got pwned.
- Businesses were too dumb and shortsighted to update their browsers to something less obsolete and pay for a standard's compliant redesign of their web applications.
- That most of these massive attacks are caused by script kiddies in China trying to impress girls by exploiting corporate stupidity, as opposed to Neo's elite evil twin.
It was Col. Mustard, in the Dining room, with a Candle Stick.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Seems like a good reason to increase the defense budget for more cyber security.
More money spent, more jobs, and a safer America to boot!
Wonder who the lucky company is that will get the contracts?