A Look at the NSA's Most Powerful Internet Attack Tool
realized writes in with a closer look at the NSA's QUANTUM system. "Today QUANTUM packs a suite of attack tools, including both DNS injection (upgrading the man-on-the-side to a man-in-the-middle, allowing bogus certificates and similar routines to break SSL) and HTTP injection. That reasonable enough. But it also includes gadgets like a plug-in to inject into MySQL connections, allowing the NSA to quietly mess with the contents of a third-party's database. (This also surprisingly suggests that unencrypted MySQL on the internet is common enough to attract NSA attention.) And it allows the NSA to hijack both IRC and HTTP-based criminal botnets, and also includes routines which use packet-injection to create phantom servers, and even attempting (poorly) to use this for defense."
after all? it doesn't get much wackier,,, http://rt.com/shows/politicking-larry-king/dalai-lama-larry-king-politicking-254/ never ends hopefully we're all in agreement on that
all these software engineers that work for nsa/gov , do they have any fucking morals? do they really believe they are securing the world from the evil guys? are they kept at gunpoint? are they just plain stupid? Fail to realize that us, the makers , have all the power is the worst mistake. Plant secret backdoors, failure modes, weaknesses. Be in charge. You don't owe anything to these black suits. Wake fucking up.
I wonder what this tool will think about my encrypted archive of the proceedings of Congress that I've renamed "The_anarchists_cookbook.zip".
the Borg have won.
Now if they would just use it to actually stop botnets.
Spasibo tovarishch Snowden!
I'm American and I fully support this. This is exactly what intelligence agencies are for. Nothing in any of these leaks in the linked article suggests these capabilities are being abused. I want my government to be able to pursue foreign intelligence targets with capabilities like these and--in a time where people complain relentlessly about government agencies being ineffective--I'm glad they are able to do this.
Posting anonymously because I've lost too much karma expressing a contrarian opinion on all these Snowden articles. Frankly, I'm more scared of moderators than our government...
We believe you. Gobble gobble gobble.
I don't know how much is known vs speculation here. If the NSA has some MySQL manipulation tools, it might not actually be intended for use on the actual internet. It is possible that they infiltrate networks and use these tools on the inside.
It came out that they're tapping dedicated lines, and those are often unencrypted. However, I'd expect most competent mysql use to stay confined to a LAN, even with encryption. Latency tends to cause problems if you separate the database from the application layer. But, I'm sure that not everybody the NSA targets is competent...
3gp2orn
You know, one of these days, you will be the one arrested and thrown in prison without due process for 'terroristic acts', or some other set of stacked charges that cannot be challenged in court because they're matters of 'national security'.
This only happens if you're an idiot, like the average libertarian that infests this site.
Smart socialists know how to always remain in power.
The worst people in the world are those that don't know how to socialize with other members of society, and socialization is formally structured in society through a government.
When you people state "I fear and mistrust government", what the rest of us hear is "I fear and mistrust other members of society".
So, when you hate the rest of society so much, why exactly should we allow you to live with us again? Because all we hear from you is "Me! Me! Me!"
Can you explain how you benefit us? Do you think you produce more tax revenue than we pay for you? Do you think the road we paved for you all the way out to your private secluded hideout so you can avoid the rest of society came for free?
Is that what you want us to hear from you libertarians? That you're a precious snowflake and that you don't want to do what government tells you to do, because you're a precious snowflake?
You will note that this anti-socializition is extremely common among those that society traditionally rejects, such as geeks and other assorted libertarians. Remember, groups are far stronger than individuals. We socialists recognized that long time ago, which is why we can get things that libertarians cannot, such as a publicly funded health-care system.
Meanwhile, we socialist statists will do fine without your support, since there are so few of you - you will notice that no one in the real world actually complains about the NSA spying, because most people are well socialized, unlike the geeks. In the real world, no one gives a shit about the kind of privacy you think is important. The only real privacy we believe in are physical privacy, not internet ones, since the internet doesn't represent real-world. (you were actually mistaken all along in your view that the internet mattered..)
But it is your job to decide if you wish to remain with us.
Eventually you will decide to lick government's boot, and you will learn that it is better for you that way.
If you have been on your computer, cell phone or car with EZpass or OnStar: they know a lot about you. Even if you have 7 degrees of separation from the bad guys.
You have to applaud the thoroughness. Misguided patriots, the lot.
Pay no attention to the man behind the curtain with all your metadata.
In Soviet Amerika, QUANTUM looks closely at YOU!
Stop spying on yourself dumbfucks.
Is that so hard?
Recent revelations about spying on an Indonesian clove cigarette company for the benefit of US "customers" is one example.
So that's for the private sector. How the customers in the private sector commission the work and pay for it would make an interesting story. Perhaps they pay via political campaign finance? Let's open that can of worms.
I'm starting to get the feeling the NSA is actually a criminal enterprise. I mean, take away who's paying the bills, and the description becomes that of a rather nefarious enterprise.
Let the personal Internet information scrub begin!
10 BILLION DOLLAR BUDGET, and they have a bag of Tommy 10 year old script kiddy tools to show for it...
If the NSA can bring down botnets, why don't they? Are spammers making political contributions?
My guess, as a security professional who could have been recruited for a three-letter agency, is that many of them are boiled frogs. There are technical challenges that smart geeks love, plus the whole hacker mystique, but you don't want to be criminal, so you go white-hat, hacking bin Ladin. That adds the whole "international spy" thing into it and maybe you help catch some really bad guys. That would be awesome, spying on al Qaeda. Hmm, if you expanded that technique you could catch a lot of bad guys. So you expand it to log calls to and from Iraq, Afghanistan, and Syria. After a few years, you end up in a place you never would have knowingly sought to go.
idk about morals (I dont want to define or discuss defining it b/c it brings out trolls something fierce)
They feel like cogs. From my short time as a DC congressional staffer & people I know in those fields, they feel like a **cog in a big machine** Their job is so abstracted that they dont really know the context of the work **or** they are doing the front line work & never see any analysis just an action order.
the intelligence community has been practicing "compartmentalization" in administering worker tasks since the Manhattan Project in the late 40s at least
one hand doesn't know what the other is doing **by design** across the whole org
it's interesting to note the paralells between:
Compartmentalization (information security): http://en.wikipedia.org/wiki/C...
The basis for compartmentalization was the idea that, if fewer people know the details of a mission or task, the risk or likelihood that such information could be compromised or fall into the hands of the opposition is decreased....(and later, re: Manhattan Project "Most did not know what, exactly, they were doing. Those that did know, did not know why they were doing it. Parts of the weapon were separately designed by teams who did not know how the parts interacted."
Compartmentalization (psychology): http://en.wikipedia.org/wiki/C...
an unconscious psychological defense mechanism used to avoid cognitive dissonance, or the mental discomfort and anxiety caused by a person's having conflicting values, cognitions, emotions, beliefs, etc. within themselves.
Compartmentalization allows these conflicting ideas to co-exist by inhibiting direct or explicit acknowledgement and interaction between separate compartmentalized self states.
Compartmentalization in orgs **can** increase security, but it **also** can be used by bad actors to **cover up bad actions**
Compartmentalization, from a cybernetic perspective, is viewed as a feedback management technique.
In any system, be it one human mind or an organization of thousands of them over decades...compartmentaliztion can be used to hide all manner of immorality
Thank you Dave Raggett
But it also includes gadgets like a plug-in to inject into MySQL connections, allowing the NSA to quietly mess with the contents of a third-party's database. (This also surprisingly suggests that unencrypted MySQL on the internet is common enough to attract NSA attention.)
When the author wrote that part of the story, he or she seemed to be unaware of what he or she had just written:
allowing bogus certificates and similar routines to break SSL
By breaking SSL, the NSA has access to SQL queries whether or not they're encrypted.
If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
Grow the fuck up and learn some respect for a different perspective / belief.
I believe that god is seventeen giant, 65 foot long orange lizards, all who are named 'Ralph'. They have mile long, glittering prehensile cocks that drag behind them. Ralph^17 will sail invisibly across the sky once per hour, where all humans on the planet must turn to the South, and bow while chanting, 'Rubber Button' for one minute in order to avoid Ralph's divine and righteous wrath. His son is a stop sign three miles south of Yuma, and all who are able must journey to see him once in their life, lest they be dammed to spend Christmas vacation in New Jersey for all eternity. I demand the same respect that these goofy christian mono-godders get, up to and including wording on American money acknowledging Ralph^17's almighty farts. BOW, HEATHENS!
I mock you sir, for failing to respect that some people's perspective and beliefs are that 'invisible shit isn't real, and that you should call out the Emperor as naked when he is'.
HA! I just wasted some of your bandwidth with a frivolous sig!
on these goings on, including some exceptional conversations.
https://www.schneier.com/
also, search his blog entries here:
https://www.archive.is/
fantastic free page archival service.
can no longer be WASTE OF BITS AND again. There are Community at and has instead hot on the heels of officers. Others direct orders, or Goals I personally flaws in the BSD All major surveys Turned over to yet FreeBSD at about 80 win out; either the superior to slow, kill myself like BitTorrent) SecoYnd, = 1400 NetBSD ops or any of the ASSOCIATION OF been looking for! and Michael Smith and, after initial Just yet, but I'm not going home stagnant. As Linux the project to there are some 1. Therefore there Be a cock-sucking The Cathedral dying. See? It's
I guess you missed the part where they admitted they have some 5 cases a year of "agents" using these systems to check up on their girlfreinds or other aquaitances.
They are just fascist pigs. Their time will come.
What I have noticed is that there is a story in the media every damn day about the over reach of NSA and arghh..people are outraged. Oh it's horrible, etc etc. Amazingly enough, no one seems to want to do anything about it. Where are those stories? Where is the demand for congressional oversight? We get the NSA we deserve because we the people are doing nothing to reign them in.
How? Well - you know (hosts with hardcoded IP addresses of my fav. sites I spend 95% of my time online @) & then OpenDNS servers (for the RARE times I do use DNS)...
How to build such a custom hosts file as easily as possible, for better:
SPEED (blocking adbanners, "good" or bad/infected + hardcoding my fav. sites @ the top of hosts to offset loss of indexing speed due to the FAULTY with larger hosts files usermode local dns clientside cache service, opting instead to use the FASTER kernelmode diskcaching subsystem + TCP/IP kernelmode PnP subsystems instead in combination)
SECURITY (vs. redirection OR "downed" DNS servers & vs. bogus roque ones malware makers/botnet herders use)
RELIABLITY (vs. redirects serverside like "beta" here which I NEVER SEE, no cookies required either)
ANONYMITY (vs. DNS request logs or to blow by DNSBLs)
?
This (courtesy of "yours truly"):
APK Hosts File Engine 9.;0++ -> http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74
* That's how, & it works vs. a LOT of this lunacy they're doing...
APK
P.S.=> On a "side note": The boys need to read a bit of Nietsche, specifically his quote of "When one fights monsters, one must take GREAT CARE, not to become a monster"... seriously:
It's VERY depressing, & full of room for abuse (which HAS already happened many times admittedly from them by their OWN FOLKS misusing it & will, with certainty, again... it's human nature, the BAD SIDE of it, & "absolute power, corrupting absolutely")... makes me depressed & it's making me lose faith in our leaders actually!
... apk
Well said. I would mod you up if I had mod points.
-kgj
That the NSA also has mind reading and mind altering radar that can hack the mind, which has no firewall, equally as efficiently as any computer system.
And they're using it today to fuck with society and to warrantlessly spy on and sabotage people.
First, read this article by Lieutenant Colonel Timothy L. Thomas, which basically examples all this in 1997. http://strategicstudiesinstitu...
Then read the original article about NSA Remote Neural Monitoring and Electronic Brain Link, published in Nexus Magazine in 1996 by John St Clair Akwei: http://www.oregonstatehospital...
Then realize that you're all mindless fucks living in the USA government Matrix system, under the full control of the Department of Defense.
NSA Whistleblower Thomas Drake even says that the USA constitution was revoked in 2001, and today we're operating under marshals law. Literally, and these guys have implemented a fake system to make the public believe they still have rights when in fact the government cannot be properly challenged because they're in complete and total control: http://www.ora.tv/offthegrid/n...
More details on the thousands of victims who've been attacked by this mind hacking tool on http://www.obamasweapon.com/ originally deployed in all radar systems in 1976, called TAMI or Thought Amplifier and Mind Interface. Allows full remote control and reading of all human thoughts and functions. Psychic attacks, paranormal and psychosis simulations, all being used today.
In no particular order:
1. Cognitive Dissonance: throw enough money/benefits at someone, and even otherwise tightly-held morals can become fluid.
2. Sociopaths: they'll do stuff simply because they can (and want to), despite the harm it could create for others.
3. Challenge: some will do things because they enjoy the challenge of seeing if it can be done, as well as the "empowerment" they feel it gives them. Note that this can be mixed in with either of the 2 points above.
4. Ignorance: for whatever reason, the people in question have no real understanding of the broader harm their actions may cause (probably a least-case scenario, since it would probably require someone who is very socially stunted, like some kind of autism and what-have-you, while still being very capable technically).
5. Coercion: out-and-out threat of bodily harm to self or loved ones, etc, if refuse to perform. Bears some similarities to #1 above, but obviously is based self-preservation/care-for-others rather than greed.
6. Apathy: they really just don't care, for whatever reason.
7. Misplaced Loyalty: failure to question the motivations and/or repercussions of orders given to them by higher-ups because questioning orders equals disloyalty.
I'm sure there may be more...
I wanted to work for one, but had too much black hat in a way that freaked out the moralists over absolutely innapropriate things. Not things like loyalty, or unauthorized access, or openly gay... but "wow, that's equivalent to stealing millions of dollars..." over a bit of high end software cracking.
As someone who knows and has done other defense and weapons work... let me put it very very clearly:
Some of us believe there are "bad guys", and while the US is not "the good guys" -- we're better than the others out there. Not morally better. Better positioned to accomplish things that need to be done.
I wanted to work NSA instead of FBI because the NSA's signals intelligence was supposedly exclusively foreign. I wanted to work the NSA over CIA -- because the NSA's mission scope includes comsec -- which should be improving things. And because the CIA ... well... they start wars and render people.
By contrast, non-cloak-and-dagger intelligence...does not bother me in the slightest. I expect routine espionage.
I don't mind making weapons platforms for our soldiers. Yes, some of them are child raping, family slaughtering motherfuckers that should be tried, taken out behind a shed, and then summarily executed by firing squad. But most of them aren't. And they need good tools.
These weapons and platforms, in the hands of the right people... are not a bad thing.
Like any and all tools, they are potentially dangerous. Like all tools that fall into the class known as "weapons", they are designed and intended to be dangerous to life and property even (and especially) when functioning correctly.
They are definitely dangerous in the wrong hands. But that is why I want my friends and allies armed with them first.
It isn't scope creep -- it's scope designation. Some of us don't mind that type of work as long as the barrel isn't pointed at our own countrymen.
Yes, what goes around comes around. I do not have the skillset, but I think I would have severe reservations about nuclears or biologicals. But basic tools for soldiers? That's how we help our country.
And the NSA...having taken those network tools, and pointed them inward and domestically... should be tried, convicted, and summarily executed -- just like any soldier that followed an unlawful order to point his rifle at not just civilians... but...his own citizens.
I don't think I'm better than a canadian, a brit, or an Iraqi, christian, muslim, jew... whatever.
I just understand which side I'm on when the thin line is drawn in the sand. The loyalty is national and to national interests -- and supporting platforms and intelligence systems that do not harm my nation is a good way to serve.
Now...about you assholes that turned those tools inward... it's time for a trip to the gallows...
The goal is that everything will be surveilled, not just popular stuff.
exploit j00syt scrupty kiddeh
This may help giving them headaches: 1) Use mysql SSL with your own CA Certificate and Client Certificate signed by your CA. 2) When browsing or IRCing, use OpenSSH proxy with SSH certificates. 3) Use your own DNS resolver. There is no need in using public or ISP DNS resolvers. 4) Stop using close source OS.