WikiLeaks Unveils CIA Implants That Steal SSH Credentials From Windows, Linux PCs (thehackernews.com)
An anonymous reader quotes a report from The Hacker News: WikiLeaks has today published the 15th batch of its ongoing Vault 7 leak, this time detailing two alleged CIA implants that allowed the agency to intercept and exfiltrate SSH (Secure Shell) credentials from targeted Windows and Linux operating systems using different attack vectors. Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely over an unsecured network. Dubbed BothanSpy -- implant for Microsoft Windows Xshell client, and Gyrfalcon -- targets the OpenSSH client on various distributions of Linux OS, including CentOS, Debian, RHEL (Red Hat), openSUSE and Ubuntu. Both implants steal user credentials for all active SSH sessions and then sends them to a CIA-controlled server.
I thought hacking was illegal under the computer crimes and abuse act?
Silicone Sister and her manager mister got what it takes!
I want Assange to rape my ass like he did those two groupie whores.
FTA
BothanSpy is installed as a Shellterm 3.x extension on the target machine and only works if Xshell is running on it with active sessions.
The user manual for Gyrfalcon v2.0 says that the implant is consist of "two compiled binaries that should be uploaded to the target platform along with the encrypted configuration file."
You need an attack vector to implant the malware.
I think I remember seeing this very tool in the "NSA catalog" type thing from the big ES leak.
Just more proof; if it's on a computer, its insecure.
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.
The manual says, "Upload the files to the target using whatever means available."
This is something an agent puts on an already-compromised machine.
But I thought Linux was secure because all eyes make bugs shallow! At least that's what a certain segment has been saying since forever. It's bullshit.
Your code and your utilities suck because they're overly complicated, too all-encompassing, and you use tricky shit that normal people don't understand.
Make your software simple, easy to audit by others. Reduce complexity. That's the only way to fight against this kind of stuff.
This type of shit should stop! What else is hidden from public by those goons?
Do they have any decency? Probably not, needs a certain character to feel superior and protect the country....
But NOT macOS.
Tee Hee.
This is just another proof of Russian hacking.
while still hiding the guns
I knew Python would eventually slither in and undermine my security with it's whitespace of doom!
The POSIX Shell Script Master Race prevails again! ;)
Anons need not reply. Questions end with a question mark.
"(S//NF) Many Bothan spies will die to bring you this information, remember their
sacrifice"
This sentence was classified Secret//No Foreign? Good grief, somebody sic Disney on the CIA.
Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely over an unsecured network.
[ The restraint exhibited in explaining SSH, on a tech site, but *not* "cryptographic" is amazing. /sarcasm ]
It must have been something you assimilated. . . .
Does this mean that SELinux, properly configured to reduce root privileges, would in fact result in the logging and/or defeat of the gyrfalcon payload, without further kernel-level exploits regaining them permissions?
while true ; do killall bothanspy ; done
"America bad, see everybody all the same!!!" -Julez and every other knuckledragger
This is disgusting... Vault 7 leaks just get better and better.
Why doesn't Wikileaks just say it has proof of these hacks and the tools used for the hacks. No, they release the tools for nefarious criminals to use, and then blame it on....? Seriously, I hope Assange rots in that Ecuadorian embassy until he's too old to walk.
For this to work on a Linux system they must first get root password then take control of groups and make install from root. So they need root password for this to work and they need to alter authorisation log file which gives the time and date in which the root password was used authorisation at blah blah date and blah blah time.
So how do they ( get ) the root password and how do they alter the authorisation log.
pam_unix(sudo:session): session opened for user root by ( Hazelnut Hidetsugu Yoshikawa )
Just use Telnet instead.
So it seems the CIA has their own rootkit. Backdoored SSH clients are absolutely nothing new at all. I remember seeing crap like that in the early 2000s. What next, are they going to tell me about their SUPER AWESOME tty snooper too?
Just change your password to . Passwords are a form of control; be free!
-IOVAR Web Dev Platform
When you misuse technical terms. Repeatedly.
I'm sure the general public will be impressed by all these previously known things, Mr. Assange.
So true...
Its time for the rest of the world to force the United States to disarm. This is clearly an unstable regime and a constant source of military aggression.
those evil North Koreans....wait...Chinese...wait...Russians...wait....damn!
Fedora is noticeably absent from the list. Pre-compromised? It would not surprise me. However, I would be very disappointed. If Fedora is compromised, it's likely in the form of a kernel patch.
as soon as these reveals are over, Slashdot will be back to implying that anyone who suggests the American Deep State is involved in Full Spectrum Dominance collection and processing of the planet's entire electronic communications, in partnership with Google, is a "tin foil hat wearing, Trump supporting, conspiracy theory moron".
It is a standard propaganda psy-op to allow for 'dull' 'uninteresting' 'saturation' coverage of inconvenient truths in places the sheeple neither goes nor understands. Then when that particular news cycle is done, the shills who work for the Deep State act as if the truths were never revealed in the first place- and go back to their favourite lie- that the 'government' is 'too incompetent' to every spy on the populice 'efficiently'.
9/11 was a Deep State False Flag used to move police state and aggressive warmaking policies into top gear, as promised by PNAC. If you track popular media coverage of the Twin Towers from construction to demolition, you'll notice a curious phenomenon where the references to the twin towers peaked in 2001 BEFORE the 'event'. Indeed the then new Spiderman movie had its first promo with Peter Parker weaving a web between the towers to catch a helicopter full of bad guys.
The drawing of attention to the WTC before the false flag was part of the plot- the essential part. Fox even had an episode of their show plot an aircraft strike on one of the towers the same year.
The NSA/GCHQ/CIA hacking/spying on the entire planet is mostly about understanding the minset of populations, to see how various potential 'plays' might work out- from false-flags like 9/11 or the british tube 'bombings' to wars in Libya and Syria. That actions cause shifs in opinions gives us a feedback loop, of course.
The sophistication of the crimes of the Deep State knows no bounds- and certainly incorporates the message shilling on Slashdot (Israel and Saudi Arabia good, Syria, Iran and Russia bad- at this time). Trump is a spanner in the works, since the braindead neo-liberal idiots were supposed to be influnecial enough to get the infinitely evil Clinton elected. And now Trump doesn't get why he isn't allowed to attack N Korea since he believes the propaganda as well (N Korea exists only to keep Korea divided so Japan can remian the no.2 power in the region).
You Slashdot dribblers who believe the official narrative (from the same people who engaged in the worst lying in Human History to give us the Iraq War) are going to cost the Human Race everything. Next in line, after the 'speed bump' of Trump is overcome, is US nuclear strikes on Iran- and then the big one- US nuclear war with Russia. You Slashdot dribblers are like the neighbours of the worst serial killer- who love the guy and attend his garden parties because of his 'winning' personality. You are so stupid, your shallowness is all that matters, and the scum that you follow politically only has to wear a similar shallow mask to win your support.
I'm disappointed in you, CIA. And Wikileaks, too - what the hell is Russia paying you for?
We are the third party AVG tech support provider. Activate and install your AVG Antivirus just by visiting our website http://avgretail.co.uk/. AVG Support provide instant AVG technical support service for AVG technical issues. AVG Support provides - 1. AVG Support is one of the best and the most reliable AVG antivirus technical support team which offers quick solutions for any type of antivirus support. 2. AVG Support help in installing with full version of antivirus 3. Sometimes due to technical flaws you are unable to use your antivirus and even run it, you can contact us in this aspect. 4. AVG Support is available with our quick solutions 24*7. 5. To give quick solutions to the users according to their needs and requirements AVG support is the best team. 6. AVG Support help users onremote access and live chat.