Hacking team hacked

For discussions about security.
Post Reply
Message
Author
Scooby
Posts: 599
Joined: Sat 03 Mar 2012, 09:04

Hacking team hacked

#1 Post by Scooby »

info:
http://www.theregister.co.uk/2015/07/06 ... _password/

Countries buying spyware to spy on their citizens:
( from db in dump )

Code: Select all

Africa: Egypt Ethiopia Morocco Nigeria Sudan 
America: Chile Colombia Ecuador Honduras Mexico Panama United_States
Asia: Acerbaijan Kazakhstan Malaysia Mongolia Singapore South_Korea Thailand Uzbekistan Vietnam Australia
Europe: Cyprus Czech_Republic Germany Hungary Italy Luxemburg Poland Russia Spain Switzerland
Middle_East: Bahrain Oman Saudi_Arabia UAE
Anyone checked out dumped source of the hack:
http://hacking.technology/Hacked%20Team/

The Guy leading the company claims to be able to decipher Tor/Dark Net
but it is not verified.
http://motherboard.vice.com/read/hackin ... qus_thread



Since there is some linux references, might be interesting to research if they
have any exploits on linux

"We're always referring to the first stage of the agent (Scout),
using a silent installer. Remember that silent installer should
never be sent to the target as is, but one of your field operators
must run it directly on the target computer:"
*edit*
After a quick read It might be that the linux references is due to the fact that
the C&C server is a running linux

There is a list of features for linux but not much info
http://hacking.technology/Hacked%20Team ... oduct.html

Checkout detection assesment for different AV products
http://hacking.technology/Hacked%20Team ... oduct.html


Offline infections:

You can infect only the following operating systems:

Windows XP, Vista, 7, 8, 8.1;
OS X 10.5, 10.6, 10.7, 10.8, 10.9 e 10.10;
Linux Debian, Ubuntu, Mint, CentOS, Fedora, OpenSuse e Mageia.


Agent (Linux)

9.0
Support for the top5 distributions from DistroWatch.com.
Support for INJECT-HTML-FLASH infection vector.
9.1
New module: Mic recordings.
9.2
New module: Money.
9.3
Improved key logger module.
9.4
New Offline installation method.
9.5
Support for Ubuntu 14.10.
Password module supports latest Firefox.

Scooby
Posts: 599
Joined: Sat 03 Mar 2012, 09:04

#2 Post by Scooby »

How about this statement of Hacking Teams CEO

Image


Also people working with malware for breaking into other
peoples computers using passwords like "passw0rd"
http://hacking.technology/Hacked%20Team ... refox_pass

Scooby
Posts: 599
Joined: Sat 03 Mar 2012, 09:04

#3 Post by Scooby »

In the millions of emails hacked during breach of hacking team
one was found containing Vulnerabilities Brokerage International's 'Assets Portfolio'.

https://wikileaks.org/hackingteam/email ... 5441/20892

A list of vulnerabilities for sale from October 6 2014.

Some Unix/linux/BSD included

Noted

Multiple BSD Jail Local Jail Escape and Privileged Command Execution

Mozilla Firefox Client-side Remote Code Execution

Oracle Solaris SunSSHD Remote Privileged Command Execution .
And this one was marked already sold!

For windows:
Malicious Portable Executable Detection Bypass

The utility provided with the vulnerability materials can modify any known-malicious Portable Executable
(PE) file into a format that will bypass anti-virus and anti-malware detection while retaining it’s executable
capability.

With many AV tested

Post Reply