DEF CON 30 - Tomer Bar - OopsSec -The bad, the worst and the ugly of APT’s operations security

Поділитися
Вставка
  • Опубліковано 22 січ 2025

КОМЕНТАРІ • 39

  • @simonstrandgaard5503
    @simonstrandgaard5503 2 роки тому +47

    Awesome presentation and entertaining. I wish it was twice as long.

    • @ThomasGabrielsen
      @ThomasGabrielsen 2 роки тому +1

      Agreed!

    • @huhulili9021
      @huhulili9021 2 роки тому +3

      well... technically you could play it at half speed, it would be twice as long...

    • @naesone2653
      @naesone2653 11 місяців тому

      my gf also wishes that it was tiwce as long :/

  • @DanMan-mh4kj
    @DanMan-mh4kj Рік тому +3

    Great presentation, which deserved more time!

  • @Ben-is1ng
    @Ben-is1ng Рік тому +1

    Great work & a very good presentation

  • @Jango1989
    @Jango1989 2 роки тому +4

    Brilliant talk!

  • @FlorianWendelborn
    @FlorianWendelborn 2 роки тому +48

    It’s insane that people as incompetent as these "hackers" are actually somewhat successful.

    • @petergerdes1094
      @petergerdes1094 2 роки тому +11

      Not totally convinced they are incompetent. Why bother wasting time with security if you don't need it? I'm not convinced that Iranian police are that active in prosecuting phisers and I suspect it's the kind of place where, if they do go after you, they don't bother with your digital security and just induce a confession.
      Still, I might want to do a bit more to ensure anonymity in case my malware accidentally hit a bigwig.

    • @FlorianWendelborn
      @FlorianWendelborn 2 роки тому +5

      @@petergerdes1094 Well, leaking your entire phone online is certainly incompetence. And letting others into your private chatrooms is stupid even if you’re only worried about competitors finding your exploits and contacts

    • @SamTheEnglishTeacher
      @SamTheEnglishTeacher 2 роки тому +1

      Plenty of money to be made outsmarting them - and they're not going to call the cops on you. Have at it if you think you're up to the task. An influx of money will be helpful to cover your energy bills once winter fully arrives.

    • @Spelter
      @Spelter 2 роки тому

      @@SamTheEnglishTeacher Tbh, I was thinking the same. Getting an anonymous SIM from Czech Republic, is not hard, then find them, get into the groups, get some data and take some money, repeat. The cards will be closed, the VPN you use from a live system without leaving traces is somewhere in Europe and police can do nothing.
      But that would only somebody do, who has no morale.

    • @SamTheEnglishTeacher
      @SamTheEnglishTeacher 2 роки тому

      @@Spelter question I have is how to find these groups in the first place? Especially at scale?

  • @WackoMcGoose
    @WackoMcGoose 2 роки тому +1

    37:37 Obligatory "That's the kind of thing an idiot would use as their luggage combination!"

  • @LostInTheRush
    @LostInTheRush 2 роки тому +14

    So uh, this isn't really APTs, is it now?

    • @geroffmilan3328
      @geroffmilan3328 2 роки тому +11

      APT != OpSec Kings.
      The time-to-deliver and operation lifespan are important factors when deciding what to secure.
      And any red team is almost always shit at playing blue team.

    • @potatoonastick2239
      @potatoonastick2239 2 роки тому +5

      The P doesn't stand for professional, they just need to be persistently active to count as APT

    • @gui-my6nr
      @gui-my6nr 2 роки тому +1

      it's open source APT 🤣

    • @Heffalumpen
      @Heffalumpen 2 роки тому +1

      I agree. They are not advanced, nor persistent (on the one target). They are a threat to home users though, so it's still fun to see them get a taste of their own medicine.

    • @thewhitefalcon8539
      @thewhitefalcon8539 Рік тому

      Now they are basic destroyed jokes

  • @garagedoorvideos
    @garagedoorvideos 2 роки тому +2

    wow 🔥🔥🔥🔥🔥🔥🔥🔥

  • @markblacket8900
    @markblacket8900 Рік тому +1

    Murat can't Atak

  • @petergerdes1094
    @petergerdes1094 2 роки тому

    At least Iranian phisers are inclusive ;-)

  • @thewhitefalcon8539
    @thewhitefalcon8539 2 роки тому +30

    You shouldn't say the Gaza strip actor is doing malicious activity. The USA is aiding a holocaust in the Gaza strip, so the actor you are talking about is probably engaging in self-defence.

    • @ilaisegev8452
      @ilaisegev8452 2 роки тому +30

      Most of the victims were themselves from Gaza according to the talk at 6:09... I don't think that can be considered as self defense...

    • @thewhitefalcon8539
      @thewhitefalcon8539 2 роки тому

      @@ilaisegev8452 Well that's a shame. They should be hacking the USA instead!

    • @shlomogreengoy
      @shlomogreengoy 2 роки тому +11

      He wears a small hat what did you expect?

    • @sycration
      @sycration Рік тому +3

      @@shlomogreengoy your name is literally Shlomo Goy, based

    • @josiahsharkey7520
      @josiahsharkey7520 Рік тому

      That isn't really true that the US is doing that it is the unelected fascist deep state that needs to be gotten rid of. The police, glowy alphabet fascists, and pretend federal evil Nazis that didn't learn not to use economic warfare after it caused WW2 are all evil fascist criminals that aren't allowed to exist in this country because they are not elected.

  • @xdman2956
    @xdman2956 Рік тому

    .bash_history would be a treat