'Vigilante Hackers' Strike Routers In Russia and Iran, Reports Motherboard (vice.com)
An anonymous reader quotes Motherboard:
On Friday, a group of hackers targeted computer infrastructure in Russia and Iran, impacting internet service providers, data centres, and in turn some websites. "We were tired of attacks from government-backed hackers on the United States and other countries," someone in control of an email address left in the note told Motherboard Saturday... "We simply wanted to send a message...." In addition to disabling the equipment, the hackers left a note on affected machines, according to screenshots and photographs shared on social media: "Don't mess with our elections," along with an image of an American flag...
In a blog post Friday, cybersecurity firm Kaspersky said the attack was exploiting a vulnerability in a piece of software called Cisco Smart Install Client. Using computer search engine Shodan, Talos (which is part of Cisco) said in its own blog post on Thursday it found 168,000 systems potentially exposed by the software. Talos also wrote it observed hackers exploiting the vulnerability to target critical infrastructure, and that some of the attacks are believed to be from nation-state actors...
Reuters reported that Iran's IT Minister Mohammad Javad Azari-Jahromi said the attack mainly impacted Europe, India, and the U.S.... The hackers said they did scan many countries for the vulnerable systems, including the U.K., U.S., and Canada, but only "attacked" Russia and Iran, perhaps referring to the post of an American flag and their message. They claimed to have fixed the Cisco issue on exposed devices in the US and UK "to prevent further attacks... As a result of our efforts, there are almost no vulnerable devices left in many major countries," they claimed in an email.
Their image of the American flag was a black-and-white drawing done with ASCII art.
In a blog post Friday, cybersecurity firm Kaspersky said the attack was exploiting a vulnerability in a piece of software called Cisco Smart Install Client. Using computer search engine Shodan, Talos (which is part of Cisco) said in its own blog post on Thursday it found 168,000 systems potentially exposed by the software. Talos also wrote it observed hackers exploiting the vulnerability to target critical infrastructure, and that some of the attacks are believed to be from nation-state actors...
Reuters reported that Iran's IT Minister Mohammad Javad Azari-Jahromi said the attack mainly impacted Europe, India, and the U.S.... The hackers said they did scan many countries for the vulnerable systems, including the U.K., U.S., and Canada, but only "attacked" Russia and Iran, perhaps referring to the post of an American flag and their message. They claimed to have fixed the Cisco issue on exposed devices in the US and UK "to prevent further attacks... As a result of our efforts, there are almost no vulnerable devices left in many major countries," they claimed in an email.
Their image of the American flag was a black-and-white drawing done with ASCII art.
Part of me wants to cheer and the other part says things like this aren't helping.
This little circle-jerk just closed off viable attack vectors that could have been used in a real defense situation.
Retaliation in 3...2....1.....
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.
Don't kid yourselves, the baddest motherfuckers in the world of computers are employed by governments.
Why ?
Because they are often given the option of employment or imprisonment when they are caught fucking around.
Anyone who thinks the shit has been pulled by some Cheeto-gobbling guy in a basement is naive as hell.
obviously you aren't one of the hackers as any hacker with half a brain knows you can't "test" this shit first as testing it results in a concerted effort worldwide to fix the hole and just reduces the possibility of a larger attack being successful. You are just some idiot kid that likes to take credit for things you don't understand.
Alright! Thatâ(TM)ll show em.
hope russia targets them for execution they are now valid combatants
These are vigilantes, not state actors claiming to be vigilantes.
Only when Western infrastructure is hacked, state actors are to blame.
Was there a corresponding dip in the number of comments on Slashdot (and every other online forum which touches on politics)?
I expect the troll architecture is sufficiently distributed to cope with outages like this but it would be useful to look for a drop in bot posts if ever a major link to Russia, Iran etc goes down.
Ehhh, not entirely true. You could burn one set of exploits to to test response patterns, especially if you had other unknown hooks in both the systems you hit and at least some of the systems doing the cleanup. That requires you to have an entirely unrelated chain ready to go for part 2 of course. Course, this is relatively unlikely to be the case if a bunch of amateurs are behind it.
Attacking two politically sensitive countries? There are no air quotes big enough....
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
yeah because the bragging child from the OP appears to be a professional with well planned analysis...NOT. this has been done by a bunch a kids, could you use such a tactic to measure response, sure, but that is so unlikely in this case as to be laughable. Secondly the risk of such a method is it raises awareness of your targets, they update/patch/replace old equipment as they become paranoid.
I agree. Also, if you infected a patch that they haven't installed yet, and you wanted to force them to update to install your exploit, hacking them like some punk script kiddie will probably do the trick. I mean, infecting updates would be difficult, but if you had that kind of exploit, this might be one way to execute it.
... they'd know the claims being made against Russia are bollocks.
Americans should stop blaming someone else for the result of their elections. Even if the Russians might have given a small attempt at it, to not accept that so many Americans willingly voted for the current president is hiding the head in the sand.
The reality is that the current president acts and behaves like the stereotypical average American. Stop complaining and make work for a change!
"Patriotism is the last refuge of a scoundrel.", Samuel Johnson, 1775.
While revenge and 'might is right' appeals to our underdog sensibilities, it must be remembered that the USA (and Russia) are the bullies on this planet; they do not have more rights because someone smacked them when they weren't looking. While we should all help to enforce the law, such self-righteous lone-wolf action results in the pizza-gate gunman. In this case, the crackers/hackers attacked the hardware directly. What happens when such vigilantes create a worm like StuxNet? Or worse, bio-hack a real virus and release it untested?
I might take it to create a cool MOTD. Although, democrats will consider it a hate crime to have it pop-up when logging in.
Collusion with intent to aide a foreign government in election meddling is a fucking federal offense.
trump republicans are the dumbest people in the world. I will enjoy watching the welfare collecting red state trailer trash drool and cry when trump is dressed in an orange jumpsuit and perp walked out of the white house.
Does the US really have 67 states now?
It sounds like they accomplished very little, other than some petty vandalism and flag-waving.
If they actually wanted to do something, why not sit quietly, collecting data, until something actionable comes along? I bet there are enough plain text protocols that they could pick something up in a few months. Or occasionally man-in-the-middle traffic from a source they'd really like to see, and see how well people respond to crappy SSL violations? Or use it as a jumping off point to compromise more machines?
They actually probably worsened things, since any U.S. intelligence gathering agency that was already on those systems, sitting quietly and observing, now has to contend with additional security due to them digitally chanting USA! USA! USA! and throwing bricks around.
There is no proof of elections fraud from Russia
False flag operation from CIA/NSA most likely.
So, somebody broke the routers in 2 countries. We all know you know the holes used. We all know you aren't the only ones who know the holes used.
Wouldn't it be nice if you could be pro-active for once and tell the router makers about all the holes you exploit?
My bad. I understand your job is to fuck the other guy, even if the other guy can fuck us the same way.
ShanghaiBill, what you said seems reasonable to me. For example, I recently had a very helpful discussion with a Russian immigrant here in the U.S. about the main Russian culture. I've had many discussions with Iranian immigrants. So I think I may have some basic understanding of those cultures.
I'm surprised that other responses to your comment were so negative and so hostile.
Hostile people: Be leaders. Don't be destructive. Use logic, not anger.
that card :|
[($)]
Did anybody else get bothered by the one semi-colon in the ASCII flag? Noticed it immediately.
This is what Lenin called "useful idiots". People who believe propaganda and do dirty work for its creators. Were it the other way round, it would be considered hostile and criminal attack. If people just realized that there is no substantial difference from what they are doing, there would be much less warfare (probably).
The only proof we have of government-sponsored large scale cyber terrorism is that of NSA and CIA on the rest of the world. If the U.S. government gives its citizens the go-ahead to freely attack the rest of the world without repercussions, it will only escalate.
After all, why should the countries of the world tolerate when you attack them? Of course they have to respond.
What really troubles me about this is the choice of image format used to save the screenshot of the ASCII art. Why are people still using JPEG for non-photographic images in 2018?
#DeleteFacebook
Yeah Hillary, these deplorables should have their right to vote removed. Then you and your soviet of billionaires could finally bring eternal peace and happiness!!!!!!
"We were tired of attacks from government-backed hackers on the United States and other countries," someone in control of an email address left in the note told Motherboard Saturday"
vegas odds please?
Troll!
Wow! The near universal support here for the DNC is very impressive, just like in all those dystopian novels and movies! Pretty scary! You fuckers just might win in November! God! I hope not! To see us sink back into that would be most tragic!
After reviewing the ASCII-in-a-jpeg, I have to ask:
Can anyone list the 17 states that were added to the union?
Considering all the controls and export bans, I'm a bit surprised. Especially with Iran. I didn't think they were allowed to buy such devices.
Vigilante hackers (or nation-state in disguise, with famed reputation of being behind the vast majority of cyberhacks of nation-states.)