TECHNOLOGY
The Hacking Team roadmap given below shows us the different ongoing projects that Hacking Team was working on at the time of the hack. The information was translated directly from a Hacking Team email and gives great insight into the working of the organization. The information is detailed and gives information on the various attack surfaces and attack vectors exploited by the company to attack the targets security.
The Hacking Team roadmap given below shows us the different ongoing projects that Hacking Team was working on at the time of the hack. The information was translated directly from a Hacking Team email and gives great insight into the working of the organization. The information is detailed and gives information on the various attack surfaces and attack vectors exploited by the company to attack the targets security.
The translated version of the unchanged text -
CARRIERS
· Tactical Active / Passive interception (Marcov et alia)
or increase the number of supported App
or include 'also active attack SMB
or it may also include a password sniffer "traditional"
§ The pictures of facebook are downloaded straight from CDN
§ Some apps that do not verify the SSL certificate to send sensitive data
Two or mode 'attack WiFi
§ Standard TNI (insertion into an existing network)
§ FakeAP (Broadcast network notes)
· Automatic addition of network requests from clients
Two or mode 'of Injection
§ Passive (While browsing web)
§ Enable (Captive / AppLink Injection)
· Fuzzing libraries on Android (Luca)
o Analysis of the crash "eligible candidates" found by the system on fuzzing libraries XML2 and XSLT
· Preparation of a POC of sniffer for Bluetooth keyboard (Andrea)
or We are waiting to receive the necessary dongle
or After viewing the POC we will decide whether and how to add it in the tactical device
· Exploit VLC (Eugene)
or The video can go to play?
or works with the browser plugin?
DESKTOP
· Windows:
o Creation of a new elite (Ivan + MarcoF to v10.1)
§ A version "AV friendly" could replace the soldier
§ Encryption module linked to key device
§ Introduction of technical anti-memory scan
o Support for UniversalApp
§ In v10, and easy to implement, and very popular, otherwise v10.1
o Support OneDrive (Marco)
· Monitor the spread of Skype Web (which will 'default on Windows10?)
· Insert Windows 10 machines in RITE
Here instead the features that will be developed for RCS10. The release and 'expected in a neighborhood of ISS USA (October):
- Support for Offline infection on Win10
- Support "social" browser Edge
- New set of certificates that expired after the release of RCS10
- Bugfix for Android
· OSX:
Parsing or local backups of Itunes [Done]
Capture or token iCloud (Giovanna)
or capture images from Photos (Giovanna)
MOBILE
· Android:
or Voice calls on WhatsApp, Line, wechat, Facebook and Hangout! [Done]
or extension of functionality '"SMS invisible" [Done]
Persistence Melted or application even after deleting the [Done]
or Mode '"Fake Off" (Emanuele Fabrizio +)
§ Adding a module that enables / disablita and a related event (when it enters this mode ')
or Create a scout / elite (verrra 'inserted in a 10.x)
New method of infection or Offline (+ Diego Emanuele)
§ Significant Features:
· Bypass PIN
· Auto Root
· IOS:
Capturing or iMessage [Done]
or New Agent iOS (+ Alberto Massimo)
§ No Jailbreak Required
§ Resistant to reboot the phone
§ Invisible in springboard
§ Infection remote one-click (no on iOS9 beta)
§ Capturing Microphone and Screenshot (screenshot of iOS9 beta)
§ If the device and 'jailbroken and / or there' it from cooperating with those who have in hand:
· Hiding more 'high
· Greater quantitiativo data collected
· In v10 will be two separate agents, then eventually will be integrated
§ By the end of July will have 'functionality including' base agent (Massimo)
· BlackBerry:
o Support OS10 (Fabrizio)
§ Almost ready ...
· Check whether you can use the Facebook API and Google to make scraping from iOS / Android spoofando application permitted (Fabrizio + Marcov)
or The problem remains of multiple URL schemes (proxy?)
§ The cinesei responded?
· Testing iOS Jailbroken iOS 8.4 (Massimo)
VECTORS
· Offline:
or infection UEFI keys bootable (Antonio)
§ The key infected will drop 'to turn a scout
§ It may also be inserted in the old "Infection Agent"!
Infecting or USB device that looks like boot disk (+ Giovanni Antonio)
§ will drop 'the scout and then will carry out' a wipe
Infection or Tails USB UEFI (Antonio)
§ The infection will occur 'at runtime
§ Can be combined with the infection of the boot from "Infection Agent"
or New NTFS driver for UEFI infection (Antonio)
persistent infection or even on OSX and UEFI signed (Antonio)
· Network Injector:
or New set of external antennas for the TNI [Done]
or decrease in the consumption of resources of the TNI (Andrea)
o Creation of a mini-TNI (Andrea)
§ Ruggedized
§ Transportable by a drone (!)
§ Without constraints due to melting
o Creation of a micro-TNI (Andrea)
§ HW of a cabinet
§ Avra a subset of the functionality'
BACKEND
· GUI:
or New graphics
or "Touch Friendly" to be tested on tablet Windows10, when they come out (Eros)
or Mode '"light" to use the console in mobility' or in the presence of networks with very low bandwidth (Eros)
or function in the search tab filesystem [Done]
or interface for sending "SMS invisible" [Done]
· Server:
o Integration Module for the management of the GSM modem [Done]
Installer or one that will update 'automatically all components [Done]
Compliant or 'system to the ISO 27001 [Done]
o Support for Windows Server 2012 [Done]
· CMS:
or The 3 systems (ticketing, licensing and donwload) can expect hosted by separate machines
§ Each machine must 'mount a system of HIPS
or systems that are to be published on the internet (ticekting and download) will use a range of IP addresses and a domain linked to HT
or Licensing:
§ Dovra 'expose an API that returns all encryption keys installer not revoked
· When you create a new client will 'automatically assign one of the encryption keys taken from the pool "spare"
§ Dovra 'have a function of "withdrawal" of a customer or user
· Removes the encryption key for the installer
· Withdrawal of the certificate of the client (on all servers)
· Disable one or more 'user account
or Download:
§ Dovra 'use client certificates to-customer (Apache)
§ The link to download the license will perform 'a script that provides the proper license under the CN of the certificate
· The license will go 'generated on-the-fly
§ Depending on the CN of the certificate each customer access to the latest version that can 'see
· In a separate area you must 'but can also have access to the old installer and licenses
§ The download of the manual will carry out 'a watermarking on-the-fly
§ Access must be possible only by entering the per-user credentials (which are NOT saved locally):
· With an authentication server shared between Ticketing and Downloads
· By enabling access to downloads only through support (with eg a token passed via URL)
or Ticekting:
§ Dovra 'use client certificates to-customer (Apache)
§ The system will support 'to a separate machine to send email notifications: only this machine will know' the real email addresses of customers
§ Having three templates of news to be sent to customers (Major, Minor, Urgent) no sensitive information or version numbers
§ The notifications of tickets to customers do not contain 'body it' title of the ticket
Diljit Dosanjh slams his fans who trolled women crying at his concert: 'Only those who...'
Mukesh Ambani's CHEAPEST offer for Jio users: Get 10 GB of 4G data for Rs 11, but there is a catch
International Space Station 'leak' worsens, Astronauts at risk as NASA cites safety concerns
Arjun Kapoor diagnosed with Hashimoto's Thyroiditis: 'I have something...'
Jhansi hospital fire: PM Modi condoles loss of lives, CM Yogi announces ex gratia for victims
Mike Tyson vs Jake Paul fight winner: YouTube star beats GOAT
Shillong Teer Result November 16, 2024: Know updates on lucky winning numbers
Mike Tyson vs Jake Paul fight fixed? Script 'leaked' showing exact round of knockout
Mukesh Ambani and Isha Ambani’s Tira Beauty: All you need to know about their luxury beauty venture
Vodafone Idea may soon serve its customers with bad news, here's what the company is planning
Narayana Murthy points out India's need to revive scientific innovations citing Israel's progress
Delhi-NCR air pollution in 'severe' category for third straight day, AQI crosses 436 in Anand Vihar
Mike Tyson vs Jake Paul: India's Neeraj Goyat beats Whindersson Nunes in super-middleweight bout
Rohit Sharma and Ritika Sajdeh blessed with baby boy
Jake Paul vs Mike Tyson: Know how much money they're paid to fight
UP: 10 infants dead after massive fire erupts at Jhansi Medical College
Meet woman, daughter of a labourer with Rs 8,000 family income, topped NEET with AIR...
Meet IITian, who left high-paying job at Goldman Sachs to prepare for UPSC, cracked exam with AIR...
AUS vs PAK Live Streaming: When and where to watch Australia vs Pakistan 2nd T20I live in India?
Viral video: Girl's sizzling dance to 'Dil Luteya' sets fire on internet, watch
Know why beer is usually stored in green or brown glass bottles, reason will surprise you
Viral video: Little girl's adorable dance to 'Ishq Vishk Pyaar Vyaar' wins hearts, watch
IND vs SA: Sanju Samson, Tilak Varma create history, India become first full-member team to....
IND vs SA, 4th T20I: Sanju Samson scripts history, becomes first player to achieve THIS massive feat
Dating Trends 2025: Micro-mance, DWM, male-casting and more to dominate the year
Navjot Singh Sidhu breaks silence on his exit from The Kapil Sharma Show: 'There were political...'
A true fashionista in Kennedy family: Who was the saree-loving aunt of Robert F. Kennedy Jr.?
PROBA-3 ABOARD ISRO’S PSLV : India to Launch Europe’s Sun Mission in December
An Indian village where frogs are married off, the reason is...
Studd Muffyn Life Presents Berberine: A Natural Powerhouse Tackling India's Metabolic Health Crisis
Jake Paul vs Mike Tyson: What is the prize money for this iconic fight?
What happened to Laika, first dog to ever travel in space?
Tara Sutaria REACTS amid dating rumours with Arunoday Singh: 'To be in love…'
CEO Kunal Shah to compete with Zerodha, Groww? CRED's subsidiary applies for stock broking license
Delhi air pollution: CM Atishi announces staggered working hours for govt workers amid 'severe' AQI
CBSE Date sheet 2025 to be released at...; when and how to check class 10, 12 timetable
This is world's most expensive nail polish costs more than 3 Mercedes, it's price is...
This Indian favourite has made it to the list of "50 best bean dishes" in the world
UPPSC prelims 2024 exam date announced, examination to happen in two shifts, check details here
SA vs IND: Arshdeep Singh eyes Yuzvendra Chahal's all-time India record in T20Is
Isha Ambani stuns in Giorgio Armani suit at Tira store launch in Mumbai
Mukesh Ambani's SUPERHIT affordable packs for Jio users: Get 10 GB data for just Rs...
'We have redone...': Shraddha Kapoor's Naagin to go on floors in 2025, producer reveals new details
'Those whom no one cares for, Modi worships them': PM Modi in Bihar rally