Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft and industry partners seize key domain used in SolarWinds hack
ZDNET ^ | 12/15/2020 | Catalin Cimpanu

Posted on 12/19/2020 10:13:01 AM PST by linMcHlp

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-62 next last
To: RBW in PA

“I thought there was an international governing body that controlled domain names? How does a private company like Microsoft seize the name?”

A group of companies did it. If hackers can do it, a consortium of software companies would have no problem.

DNS servers direct the name to the IP address. An address may look like 151.101.129.121. Much easier to remember MyWebSite.com.


21 posted on 12/19/2020 10:49:19 AM PST by TexasGator (Z1z)
[ Post Reply | Private Reply | To 5 | View Replies]

To: GOPJ

‘Seems like Bill Gates and friends could loan us their best people or form a work group and protect the United States from world class hackers.”

You can’t protect from stupidity.


22 posted on 12/19/2020 10:50:54 AM PST by TexasGator (Z1z)
[ Post Reply | Private Reply | To 20 | View Replies]

To: TexasGator

I understand how IP Addresses work. My question is what legal authority do private companies have to do this?


23 posted on 12/19/2020 10:51:18 AM PST by RBW in PA
[ Post Reply | Private Reply | To 21 | View Replies]

To: Dave Wright
They were able to inject malware into a digitally signed DLL within the SolarWinds download without triggering any key mismatch alerts.

Don't think that's the case. Over a year ago Solarwinds was warned about lax securirty on their dev system and they ignored the warning. Someone went in and simply added the backdoor to their software as part of the normal dev and distribution process.

They placed code in memory that used the actual admin credentials to traverse servers

Yes, once they were in, their actions and movements were very sophisticated incliuding stealing passwords (not difficutl) and bypassing second factor authentication (difficult). It shows how truly worthless all the security theatre is like "complex" passwords, constantly updating passwords, second factor, etc. It's all unscientific crap.

24 posted on 12/19/2020 10:52:14 AM PST by palmer (Democracy Dies Six Ways from Sunday)
[ Post Reply | Private Reply | To 16 | View Replies]

To: proust

“Did Gina Haspel” honestly tell President Trump who the actual hacker is?

Not “honestly” as she would define it.

Not “actual” as she would define it.

Not “hacker” as she would define it.

Or the left and John Brennan would define words (and John Roberts, and Chris Christie, and Mitt Romney, and the MSDNC).


25 posted on 12/19/2020 11:04:56 AM PST by linMcHlp
[ Post Reply | Private Reply | To 4 | View Replies]

To: Whenifhow; null and void; aragorn; EnigmaticAnomaly; kalee; Kale; AZ .44 MAG; Baynative; bgill; ...

p


26 posted on 12/19/2020 11:13:28 AM PST by bitt ( Let every child of the Republic LEARN TO LIVE FOR HIS GOD, his land and Union.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: RBW in PA

“What legal authority do private companies have to” seize some domain?

I have the same question.

Especially Microsoft and Unknown-Company-B, and Unknown-Company-C, and . . . Unknown-Company-Z. None of which company names seem to be available, but the liberals are so urgent that Russia must be the hacker.

Despite the hacker being the definite unknown at this time.


27 posted on 12/19/2020 11:46:20 AM PST by linMcHlp
[ Post Reply | Private Reply | To 23 | View Replies]

To: RBW in PA

“I understand how IP Addresses work. My question is what legal authority do private companies have to do this?”

Private ompanies sinkhole their domain all the time. I am sure the involved were more than have to sink their domain to Microsoft to clean up and hopefully catch the bad actors.


28 posted on 12/19/2020 11:47:49 AM PST by TexasGator (Z1z)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Dave Wright

Didn’t Microsoft give China it’s source code a while back.🤔


29 posted on 12/19/2020 11:55:50 AM PST by BiteYourSelf ( Earth first we'll strip mine the other planets later.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: RBW in PA
I thought there was an international governing body that controlled domain names? How does a private company like Microsoft seize the name?

There are processes in place for legal seizure, such as what they've done. Microsoft's legal army likely fast tracked the documentation to the IANA.

30 posted on 12/19/2020 12:17:15 PM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: RBW in PA
I thought there was an international governing body that controlled domain names? How does a private company like Microsoft seize the name?

Kinda gives you warm fuzzies to know that our corporate lords and masters can seize any domain they find problematic doesn't it?

31 posted on 12/19/2020 12:19:52 PM PST by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 5 | View Replies]

I would also point out that MS-Windows itself is a virus that is constant contact with its Borg masters.


32 posted on 12/19/2020 12:26:17 PM PST by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: linMcHlp

1. How was the bad actor able to bundle the DLL as part of a SolarWinds / Orion update?

2. How was the bad actor able to get a valid certificate to sign the DLL?

3. The bad actor seemed to know a lot about the inner workings of SolarWinds / Orion.

Am I the only person that suspects an insider agent was or is working for SolarWinds?


33 posted on 12/19/2020 12:32:18 PM PST by LuxAerterna
[ Post Reply | Private Reply | To 2 | View Replies]

To: linMcHlp

Microsoft strives to be the sole issuer of malware while making holes for other malware.


34 posted on 12/19/2020 12:44:59 PM PST by familyop
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dave Wright; bitt; little jeremiah

Anybody that can do this is an expert at exploiting Microsoft’s core. Could this be an insider hack that is supporting a foreign agency?

xxxxxxxxxxxxxxxxxxxxxx

will be waiting for the answer


35 posted on 12/19/2020 12:56:44 PM PST by thinden
[ Post Reply | Private Reply | To 16 | View Replies]

To: RBW in PA

I bet this was the start of the plan to rig elections and block critics.

obama turned over internet control to the icann company.
https://www.bbc.com/news/technology-37527719

It’s a move being breathlessly described by some as the US “giving up the internet” to the likes of China, Russia and the Middle East.”

“As of Saturday 1 October 2016, Icann will no longer be under US government oversight.

Instead, it’s now a fully “multi-stakeholder” non-profit that will take on board the views of companies, experts, academics and, yes, nation states, in how the naming system of the web is run.”

“Opponents of the plan, the likes of which include presidential candidate Donald Trump and his former rival Ted Cruz, say giving up the power amounts to handing it over to countries like China and Russia.”

In one hearing, Senator Cruz asked if Icann - an international organisation - was bound by the First Amendment to the US constitution defending freedom of speech.

No, came the reply from Icann’s chief executive, Goran Marby.
Senator Ted Cruz has spoken out strongly against the handover plan.

Evidence enough, the senator argued, that by giving Icann complete control over the internet’s naming system, it could use that power to disrupt and censor communications online.


36 posted on 12/19/2020 1:33:23 PM PST by minnesota_bound (I need more money. )
[ Post Reply | Private Reply | To 5 | View Replies]

To: proust

Has Gina H. received a blood transfusion?


37 posted on 12/19/2020 3:43:49 PM PST by ptsal (Vote R.E.D. >>>Remove Every Democrat ***)
[ Post Reply | Private Reply | To 4 | View Replies]

To: linMcHlp
This technique, known as sinkholing, is allowing Microsoft and its partners to build a list of all infected victims, which the organizations plan to use to notify all affected companies and government agencies.

But if I just own a computer, not a company or organization, that may not really help me. It might indirectly help by protecting my ISP.

38 posted on 12/19/2020 4:55:08 PM PST by ding_dong_daddy_from_dumas (Re-imagine the media!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ding_dong_daddy_from_dumas

Assuming for the moment, the existance - IF ANY - of the SolarWinds package installed, unbeknownst to you . . .

To get a detailed report of what is installed on your Windows OS based machine, in the command line, type:

msinfo32 /report %USERPROFILE%\Desktop\sys_info_bkup.txt

After the reporting completes, locate the file (sys_info_bkup.txt) on your Desktop and change that file’s name to:

20201219_Saturday_System_Information_bkup_computername.txt

for your convenience.

The report should show SolarWinds installed - IF IT IS INSTALLED.

If not installed, worry less, and continue to keep an eye on your machine’s security.

IF INSTALLED, then try the following webpage that provides the SolarWinds steps for detecting the “SolarWinds.Orion.Core.BusinessLayer.dll” library file:

https://lifars.com/2020/12/guide-to-check-for-sunburst-vulnerability-in-solarwinds/

Or, you might start there, first.


39 posted on 12/19/2020 5:30:14 PM PST by linMcHlp
[ Post Reply | Private Reply | To 38 | View Replies]

Ping


40 posted on 12/19/2020 7:13:19 PM PST by Bob Ireland (The Democrap Party is the enemy of freedom.They use all the seductions and deceits of the Bolshevics)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-62 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson