'Russia hacking code' found on Vermont utility computer

The Burlington Electric Department said it had taken "immediate action to isolate" the computer, which was not connected to the electrical grid.
The government alerted them to the "Grizzly Steppe" code on Thursday.
The same day, the US expelled 35 Russian diplomats over alleged Russian interference in November's election.
Moscow has denied any involvement in the hacking of the Democratic party and Hillary Clinton's presidential campaign.
On Friday, US President-elect Donald Trump praised Russian President Vladimir Putin for not expelling American diplomats in a tit-for-tat response.

archive.fo/Y1tax

Other urls found in this thread:

archive.fo/93bSk
theverge.com/2016/12/13/13940514/dnc-email-hack-typo-john-podesta-clinton-russia
twitter.com/NSFWRedditVideo

Sure it was

Wow, the section I pasted from the article is useless. forgive my faggotry.

The TL;DR is The Governor of Vermont is accusing Russia of trying to hack the US power grid.

And the sad part is people will buy this drivel.

Literally false news.

...

Is this code for phishing email link?

I'm not convinced it's upfront lying as much as I assume whoever was issued the laptop just watched too much porn on the job.

Hello, yes, where is the proofs? :DDDD

Alright this smells like bullshit, again.

This. It doesn't even make sense.

It has to have been completely made up.

This is about as close to evidence as we're gonna get.


I assume the awkward wording and choppy nature of the article is due to it being "written" by an automated system.

This, no code released, nothing.

Just hearsay.

That is not a good enough news post for national security sensitive material.

You need discrete direct evidence, such as part of the code, the signature used, the ips traced, etc.
This is a total fabrication.

Especially for info that affects diplomatic ties with other nations

Has America's first Jewish President, Rebbe Trump tweeted his approval of the Zionist Commie Putin regarding his latest "smart" move yet?

As long as we do it for our puppet master its completely fine.

You think we'd be able to wrench out some transparency from this "Mike Kanarick" guy?

His email and cell are shown in pic related

Epic post user.

I'm bumping because the shills aren't just out in full force today they don't fucking GET what we want to obtain.

If there's a war? We don't care. We want happening.

If there's not? We get to keep on keeping on.
You can't make us suddenly love Obongo and Shillary and hate Russia…for fuck sake I'm making an anti-shill thread.

Dont worry, Vermont.
We will continue to provide you with Quebec electricity whatever happens to your computers.

keep showing pictures of the power grid and meme'ing how vulnerable it is you mainstream media kikes. nobody realizes how easy it is to bring the grid down and now your redpilling people about it, whatever plans you have can easily go down the drain when the lights go out….fucking idiots how did they survive this long

i did a bit of research (looked up "grizzly steppe" and clicked the first link by a .gov site). I think i found the code they're referring to.

Not on this computer. I need a new home and computer.

That's an antivirus signature. It isn't a program or "code" of any kind.

More specifically, it looks like a script to be run on a compromised server.

The signature of a script, that is. Again, it's not a program, just a set of signatures to allow an antivirus to determine if a given program is a virus.

What book should I read to become elite hackur…?
(btw I don't think that is as bad as they claim)

We're reaching absolutely absurd levels of propaganda

Any tips for plebian anons like myself to what shows that?

No only that but look at

The "code" might be harmless.

Fair enough. But it seems reasonable enough that this signature is what they relied on to determine the computer was compromised. Yes or no?

Qualified software engineer here.

I read their "Grizzly Steppe" article, which spoke in detail about it being a phishing attack.

As a result I find it quite remarkable that there is suddenly some magic code found on the computer, given that none would have been involve in the original alleged russian government hack by their own report. Seems a pretty fucking obvious point - but I guess they didn't expect anybody to read the nonsense, or perhaps they simply forgot their own bullshit?

More remarkable, that the government "alerted" them to the code, and yet the computer itself "was not connected" to the electrical grid. You'd find it surprising it was checked by "the government" at all.

Fake news.

The worst part is no actual evidence is given. It's purely hearsay.

At least give us some code to check. Oh, but they don't want us to check, because it's fucking nothing.

software being on the computer is actually consistent with how they say the whole deal works

There's something very propaganda like about this whole image. Propaganda in the past used to be about ideals and had art of people but this new propaganda has this simple design to it and focuses on "information" and nothing about ideals or anything like that. It's unsettling, man.

It makes a simple phishing scam look like a big deal and implies it was does by some Russian Intelligence Services member who is wearing a hoodie because he is such a leet hacker

The best propaganda has artistry. Simple schematics like this for laymen are best reserved for being exploitable and spreading disinformation.

Here's the whole document if you're curious (archive.is didn't save the pictures. I'll post them individually on request).

archive.fo/93bSk

Ah but here is where you are wrong. The image describes the creation of an internal zombie net of sorts based on a successful phish.

The image explains that it works like this:
- hacker constructs dodgy email, sends it to recipient, who then has their credentials returned to hacker.
- hacker uses credentials to access computer and install dodgy files, stealing data of interest.


Now, we know categorically the DNC link happened because John or whatever was Phished in the first half. Then they simply used his password to log into his emails, that is how the leak happened.

The latter never occurred - nobody installed shit on a PC.

Ergo
There was no malicious software on a pc, and there cannot be an instance of similar software left on the system to compare, since there was no system, only credentials taken and email stolen

lmao

What the image seems to indicate is the information was gathered by the software.

Torposter please, learn your history.

also note they are blaming Ukrainian blackouts on Russia too.

Let me clarify this, by saying that all the DNC leaks were John Podesta, his email address was a gmail.com account.

theverge.com/2016/12/13/13940514/dnc-email-hack-typo-john-podesta-clinton-russia

Now unless gmail are somehow being fucking hosted within a private system, requiring the fucking malware that they're talking about deployed on a system ( a traditional phishing and zombie net spread)

Then the entire report is complete and utter shit, and as a direct result of that lie, the OP information is also a complete lie

Story doesn't add up.

t. Software Engineer

Is that how easy it is?

wew lads, not many people are ready for 2017 methinks.

I'm surprised we didn't talk about how full retard leftists would go to disprove that Trump won the election

why would you connect the power grid to the internet?

Libshits think Watch Dogs is real life.

You're probably right about the email thing. But again: they're blaming Ukrainian blackouts on Russian hackers. That could easily be the source of an "instance of similar software left on the system to compare."

Remember lads, to beat the witch:
You must say the truth in red.

What I don't understand is that phishing scams have been going on for decades. Most people with half a brain can recognize them by the address of the links they give, or just the fact that something is asking for your login info. The fact that a power grid employee, let alone a governement agency, would fall for one is fucking laughable.

So, wait, the RUSSIAN HACKERS write shitty PHP scripts that replace certain strings?

What's next, Chinese hackers using CSS to destroy the White House?

I bet someone takes this laptop home and uses it there to look at shady porn sites

The salesman said it was the future.

I agree, how fucking dumb would a person be to give credentials of the electricity grid to a phishing email.

All they found was:
>aimed at any credentials

i.e. probably some small time phishing scam.
Highly unlikely to be "russian hackers"
Ridiculous.

That image is VERY generic. That's how pretty much every phishing attack ever works. That image reveals nothing unique about any "grizzly steppe" if such a thing even exists and isn't just a propaganda creation.

I bet tons of government databases are are using SQL. If a real attack were to occur, that's probably what it would leverage.

How did they clarify the origin of the script?

..

Any good books on SQL?

watchdogs 2 was not bad,better than 1

...

sudo apt-get trumpvictory

Go here and take up the free course as a start.
http s://www.cybrary.it/course/ethical-hacking/

My pet interest is microcontroller embedded systems so my knowledge of SQL is pretty limited. Got to play around with it for like two days in an introductory CIS course.

vid related seems like a good starting point from the minute and a half i watched just now.

Because your population is nothing but tame puppies that don't understand wolves.

About 15 years ago, I had a job working with SQL and ColdFusion. My boss/teacher was always careful to disguise the fact that he was coding in that shit because there was nothing resembling security going on. If you need a team of the fabled Russian hackers to get access to a SQL database, you are a gigantic failure as a saboteur and should feel bad.

What we're witnessing here is the lame propaganda efforts of media and political establishment types to imagineer a Russian coup via advanced hax0rz skillz, as envisioned through the myopic eyes of a middle aged Hollywood kike screenwriter. Remember in the '90s, when hackers made Sandra Bullock's car explode? Or in the '80s, when they almost triggered WWIII with a game? That's the comprehension level we're up against.

The good news is that this level of cluelessness should be easily memeable. Go forth, my fellow Spetznaz autists, and meme the humor in this onto every platform. Let us make a laughingstock out of the Jews and their impudent fabrications!

So they better start playing nice, or angry people might learn how to annoy them.

Not me I'm a good goy :^)

maybe that was the purpose of this, because they know we're inquisitive now

At the top where it says "Yara signature." That indicates that it is a signature for the Yara antivirus engine, which is a very popular open source AV.

Also it can't be any kind of compiled or bytecode program (those programs compile to strings of bytes, not words), and it doesn't look like any kind of scripting language.


Not necessarily. The top of the image says it's an indicator of compromise for the "RIS" group, but that doesn't mean it's a program they made. It could just be a script they borrowed from someone else. It also doesn't mean it was a script that was found on the compromised computer. Many groups have a wide variety of programs and just because a program is associated with them doesn't mean they use it every time they compromise a computer.

The signature is probably just one of thousands of signatures for that particular group. Seriously, if you don't believe me you can look up Yara signatures on github. There's hundreds of thousands of them.

Also it's unlikely that a Yara detection, or any antivirus detection really, is what alerted them to the problem. 75% of malware isn't detected by antivirus programs, but by system administrators noticing something odd (why is the computer pinging a random IP address every five minutes?).

Ever tried to train an MD in information systems? The biggest reason that the integrated healthcare systems initiatives are failing is doctors (followed closely by poo programmers). A large number of them are entitled dipshits who are nearly impossible to train.
After week long courses they abandon basic infosec for minor convenience without hesitating for an instant. Then get pissed at techs when they are compromised. They hire "scribes" to do their record keeping which not only defeats the purpose but actually nets worse results then when nurses and assistants (who at least have some medical training) had to do it. Now your medical records are being entered by liberal arts majors.
Don't be surprised when grandpa is shitting himself and rambling about 'nam because they have him on 27 meds. Half of them redundant and the other half completely unneeded.

I just think this situation is ripe for piss-taking. Computer-illiterate semi-autists are trying to put over the idea that a phishing scam – that their guys are retarded enough to fall for every time – are some sinister hack that takes the resources of the KGB to pull off. I picture an audience of over-50s watching the news and believing every dishonest word of it. Even funnier, I think the equally retarded presstitutes spreading the lies are also totally taken in. Nobody is calling a single software engineer for an opinion; they just expect us to trust them again.

Remember fam, we're having fun right now, but soon it will be deadly serious. Have your laughs, but don't forget where you keep the rope.

Tell me user, do you have Flash installed in your browser?

Are you the hacker known as putin?

Several years ago, I went to a tour of the local power grid IT sector. They had the whole county connected online, with giant servers that kept track of everything.

The issue with the story, though, is this: the servers have no control over the power grid. If you want to shut it down, you do it by going there and shutting of switches. There is no remote kill switch like there's in movies.

So what are the servers for? See, the servers monitor how much electricity goes somewhere, and record it. The servers keep a database which contains how much you have to pay your electricity bill, which power plant is producing electricity at what cost (basically, you want to calculate the electricity bill by multiplying how much the electricity cost with how much electricity was used, and then calculate the best profit you can earn while not looking like you're ripping people off).

So it's impossible to mess with the grid via hacking it. What it is possible, though, is to get insight into how the power plants perform or how the locals are spending electricity (which might be useful for something, I guess).


The government power plant servers were using SQL last time I checked. You would be surprised by how stingy the government is when it comes to software solutions - they want the cheapest and the fastest solution that gets the job done, because they're expecting people who're working there to be smart and secure. Except everyone knows that these people are fucking idiots who get bored and to incredibly stupid shit.

We even had a case where the local power plant had lost access to the entire administrative network because the guy in charge was downloading porn, and caught a virus when it asked him to "register". It's incredible how uneducated the people are about internet security.

Exactly, the image isn't the usual spartan diagram map made by an engineer, its obviously made by some tumblr graphic designer.

The terminology is also completely made up also.

omg the Russians are hacking our power bills! They're going to lower them so our power companies go out of business and our infrastructure collapses!

HAHAHA the brilliant Obama administration has ruined your evil little scheme, legendary hacker known as XxXVlAdPuTiNViRuSOnUrCoMpUtErXxX420. It's over, fire the nukes! They'll be there in four minutes, Hillary said so on national TV!

Thank you Obama, your legacy is intact!

...

...

Aren't Ukrainian "blackouts" because they kind of forgot the region where the rebels are was the one producing their energy? And that they have no money to buy coal elsewhere?
They're obvious brownouts not blackouts.

...

Source code ? Proofs ?

N/A

Getting crypto locked because of poor opsec != Russian government hacked power grid of random small town.

I can picture how the conversation went down:

I don't think Moly's tired of winning, either.

Da, tovarisch! With our Commodore 64s, ve are unstoppable!

I think they are further testing the waters to see just how much bullshit people will eat up when it comes to Russian hacking.
My prediction: sometime within the next two weeks there is going to be a mass internet outage for a decent chunk of time, 24 hours at least. During this period people will be entirely dependent on the television MSM; some important people will be suicided or they might get a Turkish bodyguard, some less important but still troublesome people will just disappear. Afterward, Obama will blame it all on the Russians and somehow implicate Trump.

Of course it was, goy, at the top of it was a comment signed by Ivan Ivanovich Slavovich saying, translated: "I am russia of hackings the US haha you stupids cyka blyat"
:^)


Also
Kill yourself.


Holy shit end your life. >>>/reddit/
Watch_Dogs 2 is a gay disgrace, even for an ubisoft game. It doesn't even deserve to have the same series name nor return of characters from the original.

AYO I AINT DINDU NUFFIN AN IMMA PROVE IT WIT MURDA N SHEIT
The biggest joke of this game is the muzzie girl from a rich family who wants to take down the man. She's a fucking foreign invader with no skills and she thinks the white man's patriarchy is oppressive and her religion of peace is beautiful. I'd like to see her pull her "tagging the wall/ veil for allah mini shorts for abdullah" in saudi arabia