(Ed: Please pardon me for the wall of text, but that last entry annoyed the heck out of me.)
You know how in your teenage and college fantasy where you played Dustin Hoffman in All The Presidents Men? Remember when you dreamed of getting that one little lead and following breadcrumbs from point A to Pulitzer Prize? Yeah, network security and audits are a lot like that. Your problem is that you’ve had eight years of getting used to reading gov’t reports and taking for granted that they tell the story. Stenographers ‘R Us, in a nutshell.
When you talk about IT or whether to ‘believe’ intelligence reports about it, do better than read a 13pp PDF directed to network admins. You should really look at the data supplied too.
This page released by CERT (that’s important) is the Joint Analysis Report released by the FBI and DHS. At the bottom is the link to the 13 page PDF that they released. What the author of the Rolling Stone article linked to in the last entry failed to do is look at the other file on that page. It’s available in a handy CSV file format if you don’t grok STIX XML. The CSV is utterly redundant. CERT only needs to distribute the STIX format as that’s what admins will use to harden their networks. The CSV is there for reporters.
Back to CERT, which is one of the most trusted of information disseminating entities in the world of IT. For the most part, they send out weekly bulletins about security related patches for firmware, OS’s, services, and applications. Occasionally they’ll send out flashes of things, but that is rare and a big deal when they do.
To say yesterdays publication via CERT is unprecedented may be accurate, but to question the make up of a document that is light on ‘facts’ misreads the purpose of the document. It was aimed at security and network professionals on the front-lines. It wasn’t written for reporters. If every administrator of machines and networks followed the recommended security setups and procedures in that document no one would ever be talking about hacking.
Now, rather than write an article complaining how not enough data was spoon-fed to you, you could look at the actual data files, contact some of the owners of the IP addresses and maybe figure out why the intelligence services are confident in their claim.
Email spam is already well-known. Targeted email is a different beast. If the target is a hunter then the crafted email they get looks like an email from Cabela’s. The hit ratio goes way up. Most people would just think that google sold their search info instead of them being the target of a malicious attack. In actuality the website the email links to goes to one of the domains below and hosts a malicious website made to look like Cabela’s site. It has javascript in it that infects your computer. Even worse, the link in the email is a shortened form link. ‘bty.com/276dfgr, ‘tco.com/erfgh’ or ‘ln.com/badlink’ so the target can’t verify the end point by looking at it. Anyone can make these.
These domains were used in targeted email spoofs.
www.cderlearn.com – 209.236.67.159 – WestHost, Inc. – Providence UT, USA
ritsoperrol.ru – dead domain name
littjohnwilhap.ru – dead domain name
wilcarobbe.com – dead domain name
one2shoppee.com – dead domain name
insta.reduct.ru – 146.185.161.126 – Digital Ocean, Inc., New York, NY
editprod.waterfilter.in.ua – 176.114.0.120 – FOP Sedinkin Olexandr Valeriyovuch – Boyarka, Ukraine
mymodule.waterfilter.in.ua – dead domain name
efax.pfdregistry.net – dead domain name
Of the 249 identified IP addresses, these are Canadian: (Any CDN reporters wanna call McGill? For kicks, maybe?)
167.114.35.70 – OVH Hosting – Montreal – McGill College
198.50.177.202 – OVH Hosting – Montreal – McGill College
142.10.38.212 – Ontario Hydro
69.70.199.50 – Videotron Ltee – Montreal
207.176.226.8 – Rigstar Communications Inc – Calgary
66.158.142.2 – MORGAN SCHAFFER INC. – Lasalle, Quebec
See below the fold for a numerical count of IP’s by country.
45 China
44 the United States
19 the Netherlands
14 Germany
11 France
8 Sweden
8 South Korea
6 Thailand
6 Japan
6 Canada
5 Denmark
4 Romania
3 Vietnam
3 Turkey
3 the United Kingdom
3 Taiwan
3 Swaziland
3 Spain
3 Puerto Rico
3 Mexico
3 Italy
3 Indonesia
3 Bulgaria
2 Russia
2 Luxembourg
2 Lithuania
2 Iraq
2 Iran
2 India
2 Greece
2 Finland
2 Estonia
2 Czech Republic
2 Brazil
1 Venezuela
1 United Kingdom
1 Ukraine
1 the Slovakia
1 Singapore
1 Serbia
1 Poland
1 Mongolia
1 Malaysia
1 Kenya
1 Kazakhstan
1 Hungary
1 Ghana
1 Egypt
1 Cambodia
1 Belgium
1 Bangladesh
1 Austria

Dammit, Lance, you really make me appreciate that I quit being neck deep in state-of-the-art computer stuff in the seventies.
The problem is that many of the IPs in question trace back to rent-a-server farms all over the world. Short of accessing the server hosting company’s billing records (and assuming that the servers weren’t rented with preloaded or stolen credit cards or Bitcoin in the first place) there’s still no information here one way or the other to indicate whether Russia was responsible.
So the Obama-Nation™ got it wrong and should have expelled the Chinese…
The Russian IP addresses are right up there with LUXEMBOURG!
Thus with a large helping of Rossiysky we find the Obama-Nation™ has managed to ‘cheese off’ the Russians.
Amateur hour foreign policy cooked up over a ‘hot server’.
Going out with a whimper, and no bang for the New Year!
As Bugs Bunny would say: “Nah, what a maroon!”
Why have nuclear war when the Obama-Nation™ needs to have his swan song…?
Bugs Rules
https://www.youtube.com/watch?v=BX1ljYx3g3k
Cheers
Hans Rupprecht, Commander in Chief
1st Saint Nicolaas Army
Army Group ‘True North’
Captcha hilarity: PARTY Blvd
Hans.
Google ‘misdirection’.
Let’s for the sake of argument assume network admin competence are a constant across the world.
144M in RU.
30M in CDN.
Logically, if this were a disinterested 3rd party the RU IP’s would be in the range of 30.
This stuff is all Hillary-bumf. The whole idea of starting a diplomatic row because one is a computer illiterate is beyond surreal.
Nothing said about a really serious hack, that of Victoria Nuland (https://en.wikipedia.org/wiki/Victoria_Nuland) with the US Ambassador to the Ukraine. But that didn’t matter because it didn’t affect Hillary’s chances of being elected.
I, along with many others I am sure, understood very little of this post 🙂
That being said, I can switch my VPN to a Russian server. Does that mean, if I decide to “hack” something Putin will be blamed?
Check this analysis out: https://www.wordfence.com/blog/2016/12/russia-malware-ip-hack/?utm_source=list&utm_campaign=123016&utm_medium=email
It might not have been Russia
The fact the malware was an OnionDuke variant and they admit it means this is a nothing burger. They’ve got ZERO on russia here. It’s still possible that russia did it but I doubt it. Not with an OnionDuke variant I mean that’s just sloppy. Maybe that’s the intent who knows but either way this report is just bunk.
This is just bafflegab. The 13 page PDF may be accurate, but it is not proof, just an expose. I disagree it was written for security types. It was written via CERT to bypass US controls, I suspect, and for purely propaganda purposes.
What proof is there of a hack of Podesta’s email, or the DNC server? And of course the Demons want to conflate these two things with the election, to confuse the low-information non-voter.
Come on Lance it’s obvious these so-called Canadian IP addresses are really Russian.
OVH Hosting – Montreal – McGill College
Obviously OVH stands for Outer Vladisvostok Holdings
142.10.38.212 – Ontario Hydro —- Well, this one’s obvious:)
69.70.199.50 – Videotron Ltee – Montreal
Simply change the first and last letters and you have Nideotrov. Very Russian sounding.
207.176.226.8 – Rigstar Communications Inc – Calgary — really Redstar.
66.158.142.2 – MORGAN SCHAFFER INC. — Morgan Şaffer in Kazak.
So there. It was the Russians!!
Dint obammy throw a monkey wrench into the works with givin up the “interweb thingy”?
Monkey wrench? Hey what, for real? Now that’s jus pure raciss!!
Now I know where the term shitload comes from.
Hacking or Spying. What’s the diff?
They do it. We do it.
They know. We know.
It is all the fault of George Bush. If that guy that invented the internet had been president, this would of never happened!
@Lance: Absolute bafflgab. Get to your point in plan English or stop ranting. Yeah, no one’s arguing that you know a lot about computer security but no one has the time nor patience for this. I have no idea what you are trying to say other than you somehow think the Rolling Stone reporter is incompetent…. or something like that.
Lance…..that list MUST be wrong!!!! Nowhere do I see an Israeli IP. Where was the Mossad??
Perfect captcha…stop stop
And these CERT links prove what, exactly? That OnionDuke APT variants were used? Everyone who puts a server on the internet gets attacked with these or others similar to it.
Some of them are Russian criminals, some are Russia or other eastern freelancers and some presumably are Russian intelligence services hiding their activities in the cloud of others.
So what? How does that even disagree with anything in the Rolling Stone article?
Courtesy of David Burge @iowahawkblog a thorough dismantling of the media driven ‘Russian narrative’…
https://twitter.com/iowahawkblog/status/814910688443465728
1/ John Podesta, like 100% of everyone who has ever had a email account, received a password phishing email. He fell for it.
2/ According to some accounts, the phishing email had Russian fingerprints/ characteristics in its metadata.
3/ whatever the case, the password purloiners downloaded his emails, which eventually got into the hands of Wikileaks, who made them public.
4/ The emails were mildly embarrassing, revealing frequent circle jerking between the DNC and journalists. Mostly embarrassing to media.
5/ At the time of their release (Oct) they were hardly covered by any media, and largely dismissed as a big fat nothingburger.
6/ Not one of the people whose emails were revealed has ever disputed their authenticity or provenance.
7/ Fast forward to December. The October nothingburger has now magically transformed into “vote hacking” and “election hacking.”
8/ new narrative: treasonous Trump operatives conspired with Putin to hypnotically mesmerize Clinton voters into pulling the wrong lever.
9/ This is not Alex Jones or angry conspiracy kook Facebook uncles, it’s the NYTs, the WaPo, our beloved State Radio.
10/ how effective has this been? If polls are to be believed, 50%+ of Democrats believe the Russians literally modified vote tallies.
11/ none of this is a defense of Trump, or his kleptocrat pal Putin. It’s an indictment of our garbage narrative-driven media.
12/ it shouldn’t have to take a drunk internet nobody to point any of this out, but hey, here we are.
Maybe John Podesta could ask the Russian embassy chef, before he leaves, for some more wholesome recipes than his recent ‘spirit cooking’ exercises.
It would be useful not to have to counter a ridiculous narrative other than the DNC and its operatives ran a completely shambolic campaign replete with Foval/Creamer NSDAP tactics. Furthermore, the only Demonstrably Numbskull Computer (DNC) was owned by one Hillary R. Clinton who couldn’t secure a server from a roving band of lemmings.
Russian hackers my eye…the DNC couldn’t lock down a server anymore than they could keep the toilet seat down in one of their vaunted transgender bathrooms.
The Russian hacker narrative in the cold light of a New Years morning, holds about as much as the drained contents of a champagne bottle.
Nazdrovje!
Hans Rupprecht, Commander in Chief
1st Saint Nicolaas Army
Army Group ‘True North’
I have to agree with you there David. I don’t see what the point of Lance’s rant is, other than to give him an excuse to sound off about how big his brain is.
Another plausible explanation is maybe, just maybe, the Rolling Stone author was trying to write an article that would hold the interest of a broad spectrum of readers, including the technically unsophisticated, and not a bloody white paper on computer security!
I think we can all agree that the “evidence” that the Russian government was behind hacking done around the election is rather wanting, and there are a number of ways to reach that conclusion, some technical, and others that are probably more to do with giving consideration to the whys and wherefores of social engineering and other sundry machinations.
Ha! McGill!
Eeeediots!
In October of 2014, following a cleanup of a site I support, I ran a Google search on the rather generic phase used on that hacked-for-spamvertising website. McGill turned up in that search. Prominently. Investigating, I determined rather quickly that the spam-hacked site was running on a very obsolete version of Joomla, and the site wasn’t being maintained. So I sent their abuse desk a quick email outlining my findings, along with … cheers! Here’s the response I received from their help desk:
It’s 2016, and obviously McGill still has their head up their ass re asserting proper security procedures. Perhaps it’s time they got themselves disconnected from the Interwebs, then they can be a nice big lan.
Wake up People
Obama is on the offensive because 1 Billion dollars worth of democrat donors money was blown on a crappy presidential campaign and because Obamas policies are gutting the American working and middle class.
The donors are screaming for answers, pounding their fists on the table.
Only the bobblehead voters in urban pockets voted democrat. As we all know Dems lost at every level of government.
WTF happened?
Obamas answer…. “its the Russians, they hacked the DNC. They stole the election for Trump”
Obama is playing to the donor elites, the media and as using wedge politics as it pleases him.
One thing about peoples memory, its short.
All the while HRC was Sec of State she maintained a private server allowing an unemployed taxi driver/low to mid level hacker named Marcel Lazar aka Guciffer access to Clintons email through Sidney Blumentals AOL account.
Remember, it was Guccifer who broke the news about HRC and Benghazi. He will serve 3 years in Romania and 5 years in the USA while HRC walks. Obama knew about the server, sent emails to Clinton and would be implicated as well.
https://en.wikipedia.org/wiki/Guccifer
In Lazars words
“As far as I remember, yes, there were … up to 10, like, IPs from other parts of the world,” he said.
With no formal computer training, he did most of his hacking from a small Romanian village.
Lazar said he chose to use “proxy servers in Russia,” describing them as the best, providing anonymity.
http://www.foxnews.com/politics/2016/05/04/romanian-hacker-guccifer-breached-clinton-server-it-was-easy.html
Only the bobblehead voters in urban pockets voted democrat
Clinton won the popular vote by about 2.3 million, but won California by 4.1 million; therefore outside of California, she even lost the popular vote by 1.6 million (roughly). What’s special about California … hmm?
The lame duck released a squirrel 🙂 and all the press puppies chased it
The rejection of Hillary Clinton as President of the USA is one of the most democratic exercises in many years. To think that perhaps the Russians were responsible is deliciously ironic.
Thanx for starting this thread Lance; I have a tiny grasp of the resulting “outbursts” but do appreciate the general theme the DemocRats are up to their Fecund Lying Asshat’s in trying to Save Face/Access to Tax-payer & Donor Funding.
Cheers & Happy New Year to all at SDA and we Who vist here.
Interesting. I found this in the comments section of the wordfence site.
Terry December 30, 2016 at 8:39 am • Reply
I’d like to know what exactly it was that was allegedly hacked.
If they are referring to the DNC emails that were published by WikiLeaks, that is disputed by Craig Murray, former British ambassador, who said that they were LEAKED to him directly by a ‘whistleblower’:
http://www.dailymail.co.uk/news/article-4034038/Ex-British-ambassador-WikiLeaks-operative-claims-Russia-did-NOT-provide-Clinton-emails-handed-D-C-park-intermediary-disgusted-Democratic-insiders.html
Spot on !
… and SHE is free to wander the woods of leftist enclaves
No question, the most awesome hack in the history of mankind. Not only did the Russkies deliver the electoral win to Trump, they covered their tracks by giving the popular vote to the Hildebeast. Brilliant!
Message from the DNC;
“There is nothing Lord Putin cannot do”
Bow before his magnificence.
The compulsive liars cannot stop themselves from lying,even when truth would serve their cause better.
The current “Russian Hacker”lie is too much even for the LIV’s.
Remember, Obama told Putin to “cut it out”; Putin did not obey the One and that is the real trouble here.
And this just in…
SECURITY EXPERTS: WHITE HOUSE FAILS TO MAKE HACKING CASE
‘Restates previous private-sector claims without providing any support for their validity’
http://arstechnica.com/security/2016/12/did-russia-tamper-with-the-2016-election-bitter-debate-likely-to-rage-on/
Talk about disappointments. The US government’s much-anticipated analysis of Russian-sponsored hacking operations provides almost none of the promised evidence linking them to breaches that the Obama administration claims were orchestrated in an attempt to interfere with the 2016 presidential election.
The 13-page report, which was jointly published Thursday by the Department of Homeland Security and the FBI, billed itself as an indictment of sorts that would finally lay out the intelligence community’s case that Russian government operatives carried out hacks on the Democratic National Committee, the Democratic Congressional Campaign Committee, and Clinton Campaign Chief John Podesta and leaked much of the resulting material. While security companies in the private sector have said for months the hacking campaign was the work of people working for the Russian government, anonymous people tied to the leaks have claimed they are lone wolves. Many independent security experts said there was little way to know the true origins of the alleged attacks.
Sadly, the JAR, as the Joint Analysis Report is called, does little to end the debate. Instead of providing smoking guns that the Russian government was behind specific hacks, it largely restates previous private-sector claims without providing any support for their validity. Even worse, it provides an effective bait and switch by promising newly declassified intelligence into Russian hackers’ “tradecraft and techniques” and instead delivering generic methods carried out by just about all state-sponsored hacking groups.
Translation: Ya got a whole lot of nothing but inconclusive.
Nazdrovje!
Hans Rupprecht, Commander in Chief
1st Saint Nicolaas Army
Army Group ‘True North’
At this point in the conversation. I can’t help myself, “what difference does it make”?. I mean that in a snarky way and seriously too. As someone else said, they spy, we spy we all spy. Let’s say for the sake of argument that the Russians did it. So What? The information that was leaked was not disputed. It wasn’t even a smoking gun it just showed what liars and how disgusting these people are even to each other. One of the main disqualifiers of illiry for any job in government should have been the private server. Her total disregard for proper computer security (placing no value on America’s secrets) should have been a deal breaker. She did it for greed. But that doesn’t matter either, the fact that she did it should have been all she wrote but it wasn’t. Not sure if the podesta dirt did her in but it had to rankle that he had to implore people to get her to shower and now we all knew that. What was said about her daughter probably wasn’t fun either. She didn’t care if America’s secrets were hacked but she sure didn’t like having some of hers put out there. The emails that could put her away are still missing. If the Russians have them it sure would restart relations with the USA on a great note if they would share.
Anyone get the sense that obummer is fighting hard like a cornered animal? Illiary looks worn out and exhausted in her defeat and they are still putting her out there. sora$$ isn’t even trying to be behind the scenes. These are desperate times for some desperate people and they are dangerous people..
Look up the report and read the disclaimer. It’s a scream — DHS is basically saying they don’t stand behind the report.
I’m still puzzling over the issue here. Real email messages sent by DNC and Clinton campaign operatives get into the hands of Wikileaks, who publish them to a reluctant MSM, that haltingly and with as much sugar coating and distraction possible, mumbles about their existence to a public whose impressions of Clinton and the Democrats are reinforced by what they read and hear from the emails.
And the story is not what failures the authors of the emails are, but rather who first obtained the emails and what their motivation was? Hmmmm………..
Still sounds to me like a ‘vast right wing conspiracy’ defence, thrown out to distract and deflect from owning up to the real problem.