"How I hacked DStv" - Security researcher

If you compromised a system you compromised a system.

tumblr_nndyzkJzpk1ryvclko1_250.gif
tumblr_nndyzkJzpk1ryvclko2_250.gif

tenor.gif

source.gif
 
Article name change... from clickbait to boring

Despite my better judgement, I'll take the bait:
  1. None of the comments in this thread or Disqus caused the headline change.
  2. Under what circumstances would you consider a serious security breach a "hack". How hard must you have worked for the password? If I call a company and convince the person on the other end of the call to give me their password, is that a hack?
 
Despite my better judgement, I'll take the bait:
  1. None of the comments in this thread or Disqus caused the headline change.
Here fishy....

What caused the name change?

“I discovered a breach” is far better than “I hacked” if you didn’t actually hack... unless he did and he’s not telling?
 
What caused the name change?

I'm not sure I can say anything without making Bright's life difficult. <-- Except this.

“I discovered a breach” is far better than “I hacked” if you didn’t actually hack... unless he did and he’s not telling?

He certainly tested the credentials to make sure it was an actual threat, if that's what you mean. Further down the article he makes clear that he was able to access live SuperSport systems with the creds.
 
Hacking is obtaining access (not necessarily a password) through unauthorised means. E.g. sending commands through a port that are intended to do something else, tricking someone into giving out their credentials, impersonating someone. Technically giving out all info in a public directory is a security breach. It's no more hacking than me forgetting that my password is in the clipboard and accidentally pasting it to a website would be.
 
Technically giving out all info in a public directory is a security breach. It's no more hacking than me forgetting that my password is in the clipboard and accidentally pasting it to a website would be.

It's not like they posted the creds onto their website, though.

Anyway... I'm not here to argue semantics. I posted a question and you gave an answer — thanks!
 
It's not like they posted the creds onto their website, though.

Anyway... I'm not here to argue semantics. I posted a question and you gave an answer — thanks!
But at some point they must have, else how was it indexed? Or they posted it somewhere else.
 
Approve of new title

My own 2c on the Article title naming,scraping from one of my favourite sites with similar news:


"Hack"
A contractor for the Russian Federal Security Service (FSB) has been hacked and secret projects that were being developed for the intelligence agency were leaked to Russian Media. These projects detail Russia's attempt to de-anonymize users on the Tor network, collect data from social networks, and how to isolate the Russian portion of the Internet from the rest of the world.

On July 13th, 2019, a contactor for the Russia FSB named "Sytech" was claimed to be hacked by a hacking group named 0v1ru$. As part of this hack, the group defaced the contactor's site to show an image of "Yoba-face", which they posted an image of on their Twitter feed.
A botnet is currently scanning the internet in search of poorly protected Windows machines with Remote Desktop Protocol (RDP) connection enabled.

Called GoldBrute, of the malware compiled a list of over 1.5 million unique systems and systematically tests access on them with brute-force or credential stuffing attacks.
Over the weekend, StockX announced that their sneaker and streetwear buying platform had been hacked and an unauthorized user was able to gain access to customer data. This hack was what led to the password reset emails being sent out to all customers last week.

vs

"Expose"
Data belonging to 32 million customers of SKY Brasil has been exposed online long enough to make their theft very likely, an independent security researcher discovered.

Fábio Castro found that the data cache could be reached by anyone that knew where to look on the internet.
An unsecured database has exposed the personal information of 8 million people from the U.S. who participated in online surveys, sweepstakes, and requests for free product samples.

The way these types of sites work is you are offered free product samples, a chance to enter a sweepstake, or a prize for filling out a survey. In order to take advantage of these offers, though, you will be required to provide your personal information, which will then be used in later marketing campaigns or for lead generation.

Sanyam Jain, an independent security researcher and member of the GDI Foundation, discovered an unsecured Elasticsearch database that exposed the personal information of 8 million people who submitted entries to these types of sites.
18 MongoDB databases with information generated by accounts on several online social services in China have been sitting on the web ready for plucking by anyone knowing where to look.

It appears that they are part of a country-wide surveillance program that collects profile-related data (names, ID numbers, and photos) along with GPS locations, network info, public and private conversations, and file exchanges.

Huge amounts of profile data processed daily
According to Victor Gevers, a security researcher for the non-profit GDI Foundation, the program vacuums into one large database the account information from six social platforms in China and links it to a real person or ID.
 
  • Like
Reactions: Jan
But at some point they must have, else how was it indexed? Or they posted it somewhere else.

A lot of Google Dorking comes down to exploiting configuration errors. In this case, the directory on the web server was probably exposed as a basic website.

Here's an example: https://azaforum.com/download/

705223

To get results like this you would search something like `allintitle:index of`.

Nowadays you'll usually make sure that any access that doesn't result in a web page being served instead redirects to a Forbidden page.

For the kind of Google Dorking that Bright was talking about here, you would use search queries like `allintext:username filetype:txt`.

For those interested in reading more about Google Dorking, this page was pretty useful: https://securitytrails.com/blog/google-hacking-techniques
 
Last edited:
Approve of new title

...

"Hack"
...
vs
...
"Expose"

Thanks for the input. Also love Bleeping Computer.

I would argue that this lies somewhere in the middle of that spectrum. While this was the similar kind of carelessness that causes millions of people's private data to be exposed when a database is left unsecured, the story is not the exposed data itself. It's about what that exposed data gave the hacker access to.

In this case it wasn't personal data being exposed, it was corporate credentials that a hacker was able to use to log into MultiChoice's VPN.

From a different perspective: I can leave a passwords.txt on a websever somewhere, but it doesn't mean you'll know what to do with those creds if you find them. Some level of knowledge on the part of the hacker is needed to actually exploit the credentials they find.
 
A lot of Google Dorking comes down to exploiting configuration errors. In this case, the directory on the web server was probably exposed as a basic website.

Here's an example: https://azaforum.com/download/

View attachment 705223

To get results like this you would search something like `allintitle:index of`.

Nowadays you'll usually make sure that any access that doesn't result in a web page being served instead redirects to a Forbidden page.

For the kind of Google Dorking that Bright was talking about here, you would use search queries like `allintext:username filetype:txt`.

For those interested in reading more about Google Dorking, this page was pretty useful: https://securitytrails.com/blog/google-hacking-techniques

He found passwords, using a technique that isn't new, been around since 2002, Johnny Long's book was published in 2004. That's over 17 years old.

If you find a coin on the street, can you claim to have robbed a bank?
 
He found passwords, using a technique that isn't new, been around since 2002, Johnny Long's book was published in 2004. That's over 17 years old.

If you find a coin on the street, can you claim to have robbed a bank?

That's a disingenuous argument and you know it. You don't have to invent a novel technique to say you've hacked someone.

He found passwords *and* knew what they were for.

I accept that some people won't consider that hacking, but there's no need to strawman this.
 
Thanks for the input. Also love Bleeping Computer.

I would argue that this lies somewhere in the middle of that spectrum. While this was the similar kind of carelessness that causes millions of people's private data to be exposed when a database is left unsecured, the story is not the exposed data itself. It's about what that exposed data gave the hacker access to.

In this case it wasn't personal data being exposed, it was corporate credentials that a hacker was able to use to log into MultiChoice's VPN.

From a different perspective: I can leave a passwords.txt on a websever somewhere, but it doesn't mean you'll know what to do with those creds if you find them. Some level of knowledge on the part of the hacker is needed to actually exploit the credentials they find.
Indeed,there is a bit of a grey area,but i'd say the spirit of it is where information is stumbled upon in the open (relatively low hanging fruit) i'd rather have the title highlight that,than the more original nomenclature of a "hacker" - being one who intrudes beyond the public domain. Once you cross that perimeter intentionally you've earned the stripes (Disregarding the original division between hackers/crackers/phreakers which is pretty dead these days)

This guy accidentally got the keys to the castle,using no more advanced tools than a browser and some syntax. Some skill and nuance sure,but not beyond what could be (as he did) stumbled upon by accident. Even researchers finding unprotected Databases or data blobs in cloud storage are not coined to be "hacking",even if they used some skill or tools like Shodan to probe for these types of issues


Again,it's cool he found stuff,and I enjoyed the read,but the original thread title left me dreading if it'd be more affectionately termed "Clickbait" - ooooh scary hacker guy,oh,he found a notepad with passwords,um I guess thats cool man

I've been involved with plenty of opsec incidents in my lifetime,where some spaz left info exposed somewhere that could do damage in the wrong hands. It happens
 
  • Like
Reactions: Jan
That's a disingenuous argument and you know it. You don't have to invent a novel technique to say you've hacked someone.

He found passwords *and* knew what they were for.

I accept that some people won't consider that hacking, but there's no need to strawman this.
Great, I certainly don't.
I'm not saying that DSTV are any less to blame, and their cyber incident response was pretty shocking, that's really the only takeaway.
 
Indeed,there is a bit of a grey area,but i'd say the spirit of it is where information is stumbled upon in the open (relatively low hanging fruit) i'd rather have the title highlight that,than the more original nomenclature of a "hacker" - being one who intrudes beyond the public domain.

That's a useful (and interesting) perspective, thanks.

Once you cross that perimeter intentionally you've earned the stripes (Disregarding the original division between hackers/crackers/phreakers which is pretty dead these days)

This guy accidentally got the keys to the castle,using no more advanced tools than a browser and some syntax. Some skill and nuance sure,but not beyond what could be (as he did) stumbled upon by accident.

Something I just want to make clear: Bright is the real deal. Just because the first time we've interviewed him in a context like this happens to be a "soft" hack shouldn't reflect on his skills at all.

I didn't want to spend a paragraph or more blowing smoke up his ass, but in hindisght, maybe that is necessary when I'm introducing y'all to someone new.

He's a professional, and highly qualified on top of that. He's also been arrested by Interpol, but I almost don't want to mention that because that was in his script-kiddie days.

I've been involved with plenty of opsec incidents in my lifetime,where some spaz left info exposed somewhere that could do damage in the wrong hands. It happens

Heh, this got a chuckle out me. As if it weren't enough of a problem that people will leave stuff on a webserver, let alone a poorly configured one, now there are improperly configured S3 buckets to contend with as well.
 
Indeed,there is a bit of a grey area,but i'd say the spirit of it is where information is stumbled upon in the open (relatively low hanging fruit) i'd rather have the title highlight that,than the more original nomenclature of a "hacker" - being one who intrudes beyond the public domain. Once you cross that perimeter intentionally you've earned the stripes (Disregarding the original division between hackers/crackers/phreakers which is pretty dead these days)

This guy accidentally got the keys to the castle,using no more advanced tools than a browser and some syntax. Some skill and nuance sure,but not beyond what could be (as he did) stumbled upon by accident. Even researchers finding unprotected Databases or data blobs in cloud storage are not coined to be "hacking",even if they used some skill or tools like Shodan to probe for these types of issues


Again,it's cool he found stuff,and I enjoyed the read,but the original thread title left me dreading if it'd be more affectionately termed "Clickbait" - ooooh scary hacker guy,oh,he found a notepad with passwords,um I guess thats cool man

I've been involved with plenty of opsec incidents in my lifetime,where some spaz left info exposed somewhere that could do damage in the wrong hands. It happens
This to me is the criteria. If there's a window and I insert a wire to hook the clip to open it I'd be breaking and entering. But not if someone left the window open with the keys to the house on the sill even if I went looking for such a house. That to me is the closest real world analogy one could get.
 
This to me is the criteria. If there's a window and I insert a wire to hook the clip to open it I'd be breaking and entering. But not if someone left the window open with the keys to the house on the sill even if I went looking for such a house. That to me is the closest real world analogy one could get.

These analogies are strawmen, though. This is more like the keys being hidden in an obscure location, but they've got some kind of magical beacon attached that can be searched for if you know how. This beacon also gives some hints as to where to look for a gate or door that might fit the key,

Then after you find the keys, you recognise the shape of it and know which kinds of gates they generally fit, so that's what you try first.
 
That's a useful (and interesting) perspective, thanks.



Something I just want to make clear: Bright is the real deal. Just because the first time we've interviewed him in a context like this happens to be a "soft" hack shouldn't reflect on his skills at all.

I didn't want to spend a paragraph or more blowing smoke up his ass, but in hindisght, maybe that is necessary when I'm introducing y'all to someone new.

He's a professional, and highly qualified on top of that. He's also been arrested by Interpol, but I almost don't want to mention that because that was in his script-kiddie days.



Heh, this got a chuckle out me. As if it weren't enough of a problem that people will leave stuff on a webserver, let alone a poorly configured one, now there are improperly configured S3 buckets to contend with as well.
On mobile so not snipping now apologies

I did research a bit,not discounting his skillset. The kind of people I hang out with when I get a chance

Literally what's got most people's bee in their bonnets was the title and content didn't connect well for some ;) otherwise pretty nifty,the presentation angle is a good one too
Kinda porn on the desktop while presenting type of funny
 
These analogies are strawmen, though. This is more like the keys being hidden in an obscure location, but they've got some kind of magical beacon attached that can be searched for if you know how. This beacon also gives some hints as to where to look for a gate or door that might fit the key,

Then after you find the keys, you recognise the shape of it and know which kinds of gates they generally fit, so that's what you try first.
Why? All it takes is knowing there are people who leave the keys out in the open. That doesn't mean I committed grand theft if I find such a place. It's the difference between having a specific target and looking for weak points and throwing a hand full of darts hoping one would stick.

I'm not trying to distract from his knowledge and achievements here. Just pointing out that it's not something I see as hacking. Editing a boot record with a hex editor would be more hacking for me. I see this trend of overusing words everywhere. Hacking, cloud storage, etc.
 
Top
Sign up to the MyBroadband newsletter
X