TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sleuths Trace New Zero-Day Attacks to Hackers Who Hit Google

38 pointsby jpdusover 12 years ago

3 comments

vectorbunnyover 12 years ago
A pdf of the Symantec report 'The Elderwood Project' can be downloaded from <a href="http://bit.ly/Q07MpB" rel="nofollow">http://bit.ly/Q07MpB</a><p>(not a Symantec employee, just following the links)
评论 #4488684 未加载
wrekkuhover 12 years ago
Leveraging the 'watering hole' technique to penetrate into one network in order to gain entry into another more compelling system (the actual target), is clever but nothing new. The recon work represented by Semantec's technical report, however, is fascinating to me. It's a great summary of the attacker's methods; reusing code, quality of code used, and statements (albeit brief) about comparing the techniques used in what would normally seem as unrelated attacks.<p>I also found it no surprise that 0days in this case were routinely wrapped in shockwave to deliver payloads for guaranteed execution.<p>AV companies may be snake oil salesmen, but i hope they at least fund research like this a bit more aggressively.
评论 #4489478 未加载
tytsoover 12 years ago
...and if this doesn't scare you away from using Windows (or allowing Windows to be used anywhere within your company), I'm not sure what will...
评论 #4488753 未加载
评论 #4489636 未加载
评论 #4489071 未加载