Again, compromise is certain (extra consoles on ttyAMA0, new systemd slices that sandbox users and leave some system components unconfigurable, nfs mounts on machines with no net hardware, funny kernel modules you can’t touch, and oh so much more fun), just need to explain how.
-
-
Replying to @dragosr @Tatzelbrumm and
“Trivial” heh. See earlier posts about flash controllers. This is how advanced malware spreads. IT guy takes his favourite memory stick with his OS install and puts it a compromised machine to reinstall. Instead now it becomes the way every new computer in the company gets owned.
2 replies 0 retweets 1 like -
Replying to @dragosr @Tatzelbrumm and
So... use something else? Dump the filesystem over the network? XMODEM it out the serial port? There are endless ways to gather evidence safely; it's nigh impossible to "cover everything" for the malware. No implant, no matter how sophisticated, magically counters everything.
1 reply 0 retweets 3 likes -
If there are as many indicators of compromise as you claim (and it's not just you misinterpreting totally normal stuff), then the malware is shoddy and clearly not designed for stealth. So show us some of them.
1 reply 0 retweets 3 likes -
FWIW: if I were a three-letter agency designing a Raspberry Pi implant, it would live in the VideoCore firmware blob that rules the system from the shadows and be completely invisible to Linux. And I wouldn't be leaving behind "systemd slices that sandbox users".
4 replies 0 retweets 16 likes -
Replying to @marcan42 @Tatzelbrumm and
and yet paradoxically, this attacker seems to have dispensed with stealth altogether here. I have so many IOCs it’s not funny, so I get the impression this is more about stopping extraction of the samples I do have.
1 reply 0 retweets 1 like -
Replying to @dragosr @Tatzelbrumm and
If you have so many IOCs, why not show them to us? You might get some people excited and less likely to call BS on you. Take a video of what you see that isn't normal. Even the most advanced NSA implant can't plug the analog hole.
3 replies 0 retweets 3 likes -
Replying to @marcan42 @Tatzelbrumm and
What analog hole? Are you suggesting I get out my film camera?
1 reply 0 retweets 0 likes -
Replying to @dragosr @Tatzelbrumm and
Are you suggesting your digital camera is compromised too? It's analog until it hits the sensor.
1 reply 0 retweets 3 likes -
Replying to @marcan42 @Tatzelbrumm and
No but what do you use to post? Or communicate? All the fun data I get, always encounters issues. So I’m just going to talk through my analysis with folks... feel free not to listen if you think I’m deranged.
2 replies 1 retweet 1 like
Use the same device you're using to tweet text. Just take a photo and post it.
-
-
Replying to @marcan42 @Tatzelbrumm and
Ok here you go. Funny kernel sysctls on a raspi2 running freebsd.pic.twitter.com/NFh95qtpwH
3 replies 2 retweets 1 like -
2 replies 1 retweet 1 like - Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.