124
posted ago by Paratrooper82 ago by Paratrooper82 +125 / -1

This article is only the tip of the ICEBERG....

The attackers, whom CISA said began their operation no later than March, managed to remain undetected until last week when security firm FireEye reported that hackers backed by a nation-state had penetrated deep into its network. Early this week, FireEye said that the hackers were infecting targets using Orion, a widely used network management tool from SolarWinds. After taking control of the Orion update mechanism, the attackers were using it to install a backdoor that FireEye researchers are calling Sunburst.”>

When you read this article (link posted below) you will understand just why I’m saying this and the writing is on the wall.

FIRST: Trump has already won! Almost 100% sure on this.

As you will read in the article, ORION/SolarWinds has been compromised. It’s been known for a couple days now. It’s far more serious than initially expected.

Why does this matter: Well pedes, SolarWinds powered the dominion/tabulation machines. It has now been proven that we have been under attack for months.

This means that the entire election will have to be thrown out*

That means that neither candidate will have 270 electoral votes, which means that the HOUSE will vote. 1 vote per state. Do the math it’s over.

I’m actually sad right now while writing this, not because we’re not going to get the outcome we’ve so desired, but more so because this will change the world.

We will undoubtedly go to war over this. Many people will die. This won’t be like Iraq or Afghanistan. This will be a near peer actor. Most likely China although I’ve seen Russia mentioned as well.

I am OVERJOYED that Trump will stay in office. Unfortunately there will likely not be much time for celebration.

These actors are inside of our network. They can shut off our power grid, our water supply, our food supply.

This is some scary ass shit!

Please READ THE ARTICLE so that you can see I’m not overplaying this at all.

Start making preparations. I fear the next time we see POTUS it will be a prime time event and what we hear will not be good for our way of life.

I pray to God that I am wrong!

https://arstechnica.com/information-technology/2020/12/feds-warn-that-solarwinds-hackers-likely-used-other-ways-to-breach-networks/?fbclid=IwAR2mwb2A0Uw5jS9SdQu6n_y8gBCSXC3v6sYtOFFvLKxSsrnSlcBUDBL-Jd8

Comments (72)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
2
Paratrooper82 [S] 2 points ago +2 / -0

Well that briefed well... but what box does that Orion SolarWinds sit on smart ass?

$100,000,000 says it’s not on a standalone.

If you installed the update on your box and they pivot then they have root access to your OS and box. Are you starting to see the bigger picture yet? Good

You can always tell who monitors green and red nodes on a map and who actually configures and secures the network and assets that allow you to monitor said network.

Here’s an idea, instead of us having a pissing contest, let’s work together towards a logical solution.

CISA is investigating incidents that exhibit adversary TTPs consistent with this activity, including some where victims either do not leverage SolarWinds Orion or where SolarWinds Orion was present but where there was no SolarWinds exploitation activity observed. Volexity has also reported publicly that they observed the APT using a secret key that the APT previously stole in order to generate a cookie to bypass the Duo multi-factor authentication protecting access to Outlook Web App (OWA).[1] Volexity attributes this intrusion to the same activity as the SolarWinds Orion supply chain compromise, and the TTPs are consistent between the two. This observation indicates that there are other initial access vectors beyond SolarWinds Orion, and there may still be others that are not yet known.>

Link from quote pay attention to the URL:

https://us-cert.cisa.gov/ncas/alerts/aa20-352a

1
maleitch 1 point ago +1 / -0

So the hacker has root access to the orion system. Now what does that gain them to a device with snmp read only community string?

It is not a pissing match...I am trying to temper you Bigfoot pedes who fucking post on here every second that this time you have finally found the smoking gun when it is never true.

I expect actual results not this drama. I know your intentions are good, but when you are wrong you will just pretend you never said it and post more garbage for that dopamine fix. This kind of shit discredits the movement.

2
Paratrooper82 [S] 2 points ago +2 / -0

@maleitch

You’re stuck on the entry point and you’re missing it completely.

Windows was compromised, OWA was compromised. All in the link

1
dataonly 1 point ago +1 / -0

Bit off the subject but, Windows is garbage w/ great marketing.

In the early ISP days everything of vital importance seemed to run on FREE BSD!

1
maleitch 1 point ago +1 / -0

No I am not. I am stuck on the end point. What exact sw product interfaces with the dominion machines and how? Until that is answered none of what you say can be considered accurate.