{"id":4670,"date":"2020-12-29T15:56:47","date_gmt":"2020-12-29T13:56:47","guid":{"rendered":"https:\/\/www.laurentmarot.fr\/wordpress\/?p=4670"},"modified":"2021-02-01T11:25:16","modified_gmt":"2021-02-01T09:25:16","slug":"solar-winds","status":"publish","type":"post","link":"https:\/\/www.laurentmarot.fr\/wordpress\/?p=4670","title":{"rendered":"Solarwinds (solorigate, sunburst)"},"content":{"rendered":"<div id=\"attachment_4677\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/1000x-1.jpg\" rel=\"lightbox[4670]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4677\" class=\"size-medium wp-image-4677\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/1000x-1-300x200.jpg\" alt=\"SolarWinds - Photographer: TRIPPLAAR KRISTOFFER\/SIPA\/AP\" width=\"300\" height=\"200\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/1000x-1-300x200.jpg 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/1000x-1-768x511.jpg 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/1000x-1.jpg 1000w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-4677\" class=\"wp-caption-text\">SolarWinds &#8211; Photographer: TRIPPLAAR KRISTOFFER\/SIPA\/AP<\/p><\/div>\n<p><strong>\u00a0Le sujet :<\/strong><\/p>\n<p>Voir page <a href=\"https:\/\/fr.wikipedia.org\/wiki\/SolarWinds\" target=\"_blank\" rel=\"noopener noreferrer\">Wikipedia FR<\/a> ou mieux <a href=\"https:\/\/en.wikipedia.org\/wiki\/SolarWinds?oldid=994993587\" target=\"_blank\" rel=\"noopener noreferrer\">Wikipedia EN<\/a><\/p>\n<p><strong>Raccourci :<\/strong><\/p>\n<p>Un vulgarisation du sujet gr\u00e2ce \u00e0 <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:6751468956579586049\/?commentUrn=urn%3Ali%3Acomment%3A(activity%3A6751468956579586049%2C6751588132615000064)\" target=\"_blank\" rel=\"noopener noreferrer\">une vid\u00e9o de 5mn<\/a> de Romain du Marais<\/p>\n<p><strong>Les faits :<\/strong> \u00ab\u00a0<em>In an operation that cybersecurity experts have described as exceedingly sophisticated and hard to detect, the hackers installed malicious code in updates to SolarWinds\u2019s widely used Orion software, which was sent to as many as 18,000 customers.<\/em><\/p>\n<p><em>The malicious code provided the hackers access to the customers\u2019 computer networks and, as clients around the world continue to comb their systems for signs of the Russian hackers, the list of victims is expected to grow.\u00a0\u00bb<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Chronologie :<\/strong><\/p>\n<p>Octobre 2019 : premiers essais \u00e0 blanc de la m\u00e9thode de distribution du malware<\/p>\n<p>Mars 2020 : distribution de la backdoor<\/p>\n<p>8 d\u00e9cembre 2020 : FireEye, par le biais d&rsquo;un <a href=\"https:\/\/www.fireeye.com\/blog\/products-and-services\/2020\/12\/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html\" target=\"_blank\" rel=\"noopener noreferrer\">article de blog de son CEO<\/a> Kevin Mandia communique sur le hack dont elle vient d&rsquo;\u00eatre victime avec pour cons\u00e9quence le vol d&rsquo;une partie des outils utilis\u00e9s par ses Red Teams.<\/p>\n<p>Reuters et les agences de presse g\u00e9n\u00e9ralistes relaient l&rsquo;information : <a href=\"https:\/\/www.reuters.com\/article\/fireeye-cyber-idUSL1N2IO2EI\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. cybersecurity firm FireEye discloses breach, theft of internal hacking tools<\/a><\/p>\n<p>13 d\u00e9cembre 2020 : <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/us-govt-fireeye-breached-after-solarwinds-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">communication coordonn\u00e9e<\/a> de FireEye, solarwinds, Microsoft et du gouvernement am\u00e9ricain.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Premiers d\u00e9tails:<\/strong><\/p>\n<p>NextImpact &#8211; 23 d\u00e9cembre 2020<br \/>\n<a href=\"https:\/\/www.nextinpact.com\/lebrief\/45213\/piratage-solarwinds-ancien-salarie-avait-alerte-en-vain\">Piratage de SolarWinds : un ancien salari\u00e9 avait alert\u00e9, en vain<\/a><br \/>\nD&rsquo;apr\u00e8s le tr\u00e8s bon article original de Bloomberg du <time class=\"article-timestamp\" datetime=\"2020-12-21T16:01:33.025Z\" data-locale=\"en\">21 d\u00e9cembre 2020 \u00e0 17:01 UTC+1<\/time><br \/>\n<a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-12-21\/solarwinds-adviser-warned-of-lax-security-years-before-hack\" target=\"_blank\" rel=\"noopener noreferrer\">SolarWinds Adviser Warned of Lax Security Years Before Hack<\/a> by <a class=\"author-v2__byline\" href=\"https:\/\/www.bloomberg.com\/authors\/AUQ1T6adl6k\/ryan-gallagher\" rel=\"author\">Ryan Gallagher<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Communication de crise :<\/strong> SolarWinds spokesperson said in a statement, \u201cOur top priority is our work with our customers, our industry partners and government agencies to determine whether a foreign government orchestrated this attack, best understand its full scope, and to help address any customer needs that develop. We are doing this work as quickly and transparently as possible. There will be plenty of time to look back and we plan to do that in a similarly transparent way.\u201d<\/p>\n<p>In addition, the company said it is collaborating with law enforcement and \u201cwill continue gathering all relevant information to ensure an incident like this does not happen again.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Les acteurs :<\/strong><\/p>\n<p>Kevin Thompson, solarwinds\u2019s chief executive officer, former securty adviser at solarwid<\/p>\n<p>Ian Thornton-Trump, chief information security officer at threat intelligence firm <a title=\"link to website\" href=\"https:\/\/www.cyjax.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Cyjax Ltd<\/a><\/p>\n<p>Tim Brown former chief technology officer at Dell Security, current vice president of security architecture<\/p>\n<p><a href=\"https:\/\/twitter.com\/vinodsparrow\/\">Vinoth Kumar<\/a> Cybersecurity expert who<a href=\"https:\/\/savebreach.com\/solarwinds-credentials-exposure-led-to-us-government-fireye-breach\/\" target=\"_blank\" rel=\"noopener\"> discovered FTP server credential<\/a> on gitHub<\/p>\n<p>Former internal langue de pute, ex solarwind : A former SolarWinds employee, who worked as a software engineer at one of the company\u2019s U.S. offices, said SolarWinds appeared to p<strong>rioritize the development of new software products over internal cybersecurity defenses<\/strong>.<\/p>\n<p>Jake Williams, aka monsieur-je-sais-tout, a former hacker for the U.S. National Security Agency who is now president of cybersecurity firm <a title=\"link to company website\" href=\"https:\/\/www.renditioninfosec.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Rendition Infosec<\/a>, said technology companies such as SolarWinds that build and produce computer code <strong>often \u201cdon\u2019t do security well<\/strong>.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Les victimes :<\/strong><br \/>\nAt Least <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-12-19\/at-least-200-victims-identified-in-suspected-russian-hacking\" target=\"_blank\" rel=\"noopener noreferrer\">200 Victims Identified<\/a> in Suspected Russian Hacking, dont :<\/p>\n<ul>\n<li><a href=\"https:\/\/www.fireeye.com\/blog\/products-and-services\/2020\/12\/global-intrusion-campaign-leverages-software-supply-chain-compromise.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">FireEye<\/a><\/li>\n<li><a href=\"https:\/\/www.reuters.com\/article\/BigStory12\/idUSKBN28N0PG\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">U.S. Department of the Treasury<\/a><\/li>\n<li><a href=\"https:\/\/www.washingtonpost.com\/national-security\/russian-government-spies-are-behind-a-broad-hacking-campaign-that-has-breached-us-agencies-and-a-top-cyber-firm\/2020\/12\/13\/d5a53b88-3d7d-11eb-9453-fc36ba051781_story.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">U.S. National Telecommunications and Information Administration<\/a> (NTIA)<\/li>\n<li><a href=\"https:\/\/www.washingtonpost.com\/national-security\/dhs-is-third-federal-agency-hacked-in-major-russian-cyberespionage-campaign\/2020\/12\/14\/41f8fc98-3e3c-11eb-8bc0-ae155bee4aff_story.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">U.S. Department of State <\/a><\/li>\n<li><a href=\"https:\/\/www.washingtonpost.com\/national-security\/dhs-is-third-federal-agency-hacked-in-major-russian-cyberespionage-campaign\/2020\/12\/14\/41f8fc98-3e3c-11eb-8bc0-ae155bee4aff_story.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">The National Institutes of Health<\/a> (NIH) (Part of the U.S. Department of Health)<\/li>\n<li><a href=\"https:\/\/www.washingtonpost.com\/national-security\/dhs-is-third-federal-agency-hacked-in-major-russian-cyberespionage-campaign\/2020\/12\/14\/41f8fc98-3e3c-11eb-8bc0-ae155bee4aff_story.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">U.S. Department of Homeland Security<\/a> (DHS)<\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/solarwinds-hackers-breach-us-nuclear-weapons-agency\/\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. Department of Energy<\/a> (DOE)<\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/solarwinds-hackers-breach-us-nuclear-weapons-agency\/\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. National Nuclear Security Administration<\/a> (NNSA)<\/li>\n<li><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-12-17\/u-s-states-were-also-hacked-in-suspected-russian-attack\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Some US states<\/a> (Specific states are undisclosed)<\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-confirms-breach-in-solarwinds-hack-denies-infecting-others\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a><\/li>\n<li><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2020-12-18\/cisco-latest-victim-of-russian-cyber-attack-using-solarwinds\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Cisco<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Les affreux :<\/strong><\/p>\n<p>Alors, <a href=\"https:\/\/www.volexity.com\/blog\/2020\/12\/14\/dark-halo-leverages-solarwinds-compromise-to-breach-organizations\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-sk=\"tooltip_parent\" data-stringify-link=\"https:\/\/www.volexity.com\/blog\/2020\/12\/14\/dark-halo-leverages-solarwinds-compromise-to-breach-organizations\/\">Dark Halo<\/a> ou bien\u00a0 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/us-govt-fireeye-breached-after-solarwinds-supply-chain-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-sk=\"tooltip_parent\" data-stringify-link=\"https:\/\/www.bleepingcomputer.com\/news\/security\/us-govt-fireeye-breached-after-solarwinds-supply-chain-attack\/\">APT29 (aka Cozy Bear)<\/a>, un groupe de hackers li\u00e9 au SVR (<span class=\"lang-ru\" lang=\"ru\">\u0421\u043b\u0443\u0436\u0431\u0430 \u0432\u043d\u0435\u0448\u043d\u0435\u0439 \u0440\u0430\u0437\u0432\u0435\u0434\u043a\u0438 \u0420\u043e\u0441\u0441\u0438\u0439\u0441\u043a\u043e\u0439 \u0424\u0435\u0434\u0435\u0440\u0430\u0446\u0438\u0438<\/span>, retranscrit en <i>Sloujba vnechne\u00ef razvedki Rossisko\u00ef Federatsi<\/i><sup id=\"cite_ref-2\" class=\"reference\"><a href=\"https:\/\/fr.wikipedia.org\/wiki\/Service_des_renseignements_ext%C3%A9rieurs_de_la_f%C3%A9d%C3%A9ration_de_Russie#cite_note-2\">2<\/a><\/sup> &#8211; Service des renseignements ext\u00e9rieurs de la f\u00e9d\u00e9ration de Russie &#8211; Russian Foreign Intelligence Service) ?<\/p>\n<div id=\"attachment_4686\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-46-41.png\" rel=\"lightbox[4670]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4686\" class=\"size-medium wp-image-4686\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-46-41-300x52.png\" alt=\"Joe S\u0142owik &#x26c4; @jfslowik \u00b7 17 d\u00e9c.\" width=\"300\" height=\"52\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-46-41-300x52.png 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-46-41-768x132.png 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-46-41.png 836w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-4686\" class=\"wp-caption-text\">Joe S\u0142owik &#x26c4; @jfslowik &#8211; 17 d\u00e9c.<\/p><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Un peu de technique :<\/strong><\/p>\n<p>Tr\u00e8s bon article int\u00e9grant pas mal de d\u00e9tails techniques compr\u00e9hensibles par ma m\u00e8re sur l&rsquo;attaque dans l&rsquo;article <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/the-solarwinds-cyberattack-the-hack-the-victims-and-what-we-know\/\" target=\"_blank\" rel=\"noopener noreferrer\">The SolarWinds cyberattack: The hack, the victims, and what we know<\/a><\/p>\n<p>Pour aller, plus loin : le <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/12\/18\/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect\/\" target=\"_blank\" rel=\"noopener noreferrer\">technical write-up<\/a> de Microsoft<\/p>\n<div id=\"attachment_4689\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-56-56.png\" rel=\"lightbox[4670]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4689\" class=\"size-medium wp-image-4689\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-56-56-300x212.png\" alt=\"SolarWinds supply chain attack Source: Microsoft\" width=\"300\" height=\"212\" srcset=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-56-56-300x212.png 300w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-56-56-1024x725.png 1024w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-56-56-768x544.png 768w, https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/Capture-du-2020-12-31-18-56-56.png 1119w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-4689\" class=\"wp-caption-text\">SolarWinds supply chain attack<br \/>Source: Microsoft<\/p><\/div>\n<p>&nbsp;<\/p>\n<p><strong>Conclusion de Costin Raiu<\/strong> (Kaspersky GREAT) :<\/p>\n<p>Even if SolarWinds had robust cybersecurity practices, however, it might not have deterred the alleged Russian hackers, who U.S. authorities described as highly skilled, patient and well resourced, demonstrating \u201ccomplex tradecraft\u201d in their attacks.<\/p>\n<p>\u201cThe reality is that sophisticated threat actors, no matter how good the defenses, will eventually succeed,\u201d said Costin Raiu, director of global research and analysis at the cybersecurity firm <a title=\"link to website\" href=\"https:\/\/usa.kaspersky.com\/v4\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Kaspersky<\/a>. \u201cIf the cost justifies the effort, the breach will happen.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Mises \u00e0 jour :<\/strong><\/p>\n<p>02\/01\/2020 : The New-York Times : <a href=\"https:\/\/www.nytimes.com\/2021\/01\/02\/us\/politics\/russian-hacking-government.html\" target=\"_blank\" rel=\"noopener\">As Understanding of Russian Hacking Grows, So Does Alarm<\/a><\/p>\n<p>04\/01\/2020 : <a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/detecting-supernova-malware-solarwinds-continued.html\" target=\"_blank\" rel=\"noopener\">Detecting Supernova Malware using Splunk<\/a><\/p>\n<p>05\/01\/2020 : SolarWinds Hit with Securities <a href=\"https:\/\/www.classaction.org\/news\/solarwinds-hit-with-securities-class-action-over-statements-in-run-up-to-cyberattack-on-fed.-government\" target=\"_blank\" rel=\"noopener\">Class Action<\/a> Over Statements in Run-Up to Cyberattack on Fed. Government<\/p>\n<p>05\/01\/2020 : <a href=\"https:\/\/thehackernews.com\/2021\/01\/fbi-cisa-nsa-officially-blames-russia.html\" target=\"_blank\" rel=\"noopener\">FBI, CISA, NSA Officially Blame Russia for SolarWinds Cyber Attack<\/a><\/p>\n<div id=\"attachment_4683\" style=\"width: 258px\" class=\"wp-caption alignleft\"><a href=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/langfr-248px-Solarwinds.svg_.png\" rel=\"lightbox[4670]\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4683\" class=\"size-full wp-image-4683\" src=\"https:\/\/www.laurentmarot.fr\/wordpress\/wp-content\/uploads\/2020\/12\/langfr-248px-Solarwinds.svg_.png\" alt=\"Russia loves solarwinds\" width=\"248\" height=\"56\" \/><\/a><p id=\"caption-attachment-4683\" class=\"wp-caption-text\">solarwinds<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>\u00a0Le sujet : Voir page Wikipedia FR ou mieux Wikipedia EN Raccourci : Un vulgarisation du sujet gr\u00e2ce \u00e0 une vid\u00e9o de 5mn de Romain du Marais Les faits : \u00ab\u00a0In an operation that cybersecurity experts have described as exceedingly sophisticated and hard to detect, the hackers installed malicious code in updates to SolarWinds\u2019s widely [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[],"_links":{"self":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/4670"}],"collection":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4670"}],"version-history":[{"count":25,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/4670\/revisions"}],"predecessor-version":[{"id":4723,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/4670\/revisions\/4723"}],"wp:attachment":[{"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.laurentmarot.fr\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}