The Shadow Brokers (TSB) is a hacker group who first appeared in the summer of 2016.[1][2] They published several leaks containing hacking tools, including several zero-day exploits,[1] from the "Equation Group" who are widely suspected to be a branch of the National Security Agency (NSA) of the United States.[3][4] Specifically, these exploits and vulnerabilities[5][6] targeted enterprise firewalls, antivirus software, and Microsoft products.[7] The Shadow Brokers originally attributed the leaks to the Equation Group threat actor, who have been tied to the NSA's Tailored Access Operations unit.[8][9][10][4]
Several news sources noted that the group's name was likely in reference to a character from the Mass Effect video game series.[11][12] Matt Suiche quoted the following description of that character: "The Shadow Broker is an individual at the head of an expansive organization which trades in information, always selling to the highest bidder. The Shadow Broker appears to be highly competent at its trade: all secrets that are bought and sold never allow one customer of the Broker to gain a significant advantage, forcing the customers to continue trading information to avoid becoming disadvantaged, allowing the Broker to remain in business."[13]
While the exact date is unclear, reports suggested that the preparation of the leak started at least in the beginning of August,[14] and that the initial publication occurred August 13, 2016 with a Tweet from a Twitter account "@shadowbrokerss" announcing a Pastebin page[6] and a GitHub repository containing references and instructions for obtaining and decrypting the content of a file supposedly containing tools and exploits used by the Equation Group. The initial response to the publication was met with some uncertainty about its authenticity.[15]
On October 31, 2016, The Shadow Brokers published a list of servers supposedly compromised by the Equation Group, as well as references to seven supposedly undisclosed tools (DEWDROP, INCISION, JACKLADDER, ORANGUTAN, PATCHICILLIN, RETICULUM, SIDETRACK AND STOICSURGEON) also used by the threat actor.[16]
On April 8, 2017, the Medium account used by The Shadow Brokers posted a new update.[17] The post revealed the password to encrypted files released the previous year, which allegedly had more NSA hacking tools.[18] This posting explicitly stated that the post was partially in response to President Trump's attack against a Syrian airfield, which was also used by Russian forces.
On April 14, 2017, The Shadow Brokers released, amongst other things, the tools and exploits codenamed: DANDERSPRITZ, ODDJOB, FUZZBUNCH, DARKPULSAR, ETERNALSYNERGY, ETERNALROMANCE, ETERNALBLUE, EXPLODINGCAN and EWOKFRENZY.[19][20][21]
Some of the exploits targeting the Windows operating system had been patched in a Microsoft Security Bulletin on March 14, 2017, one month before the leak occurred.[23][24] Some speculated that Microsoft may have been tipped off about the release of the exploits.[25]
Over 200,000 machines were infected with tools from this leak within the first two weeks,[26] and in May 2017, the major WannaCry ransomware attack used the ETERNALBLUE exploit on Server Message Block (SMB) to spread itself.[27] The exploit was also used to help carry out the 2017 Petya cyberattack on June 27, 2017.[28]
ETERNALBLUE contains kernel shellcode to load the non-persistent DoublePulsar backdoor.[29] This allows for the installation of the PEDDLECHEAP payload which would then be accessed by the attacker using the DanderSpritz Listening Post (LP) software.[30][31]
James Bamford along with Matt Suiche speculated[32] that an insider, "possibly someone assigned to the [NSA's] highly sensitive Tailored Access Operations", stole the hacking tools.[33][34] In October 2016, The Washington Post reported that Harold T. Martin III, a former contractor for Booz Allen Hamilton accused of stealing approximately 50 terabytes of data from the National Security Agency (NSA), was the lead suspect. Martin had worked with the NSA's Tailored Access Operations from 2012 to 2015 in a support role. He pleaded guilty to retaining national defense information in 2019, but it is not clear whether the Shadow Brokers obtained their material from him. The Shadow Brokers continued posting messages that were cryptographically-signed and were interviewed by media while Martin was detained.[35]
Edward Snowden stated on Twitter on August 16, 2016 that "circumstantial evidence and conventional wisdom indicates Russian responsibility"[36] and that the leak "is likely a warning that someone can prove responsibility for any attacks that originated from this malware server"[37] summarizing that it looks like "somebody sending a message that an escalation in the attribution game could get messy fast".[38][39]
The New York Times put the incident in the context of the Democratic National Committee cyber attacks and hacking of the Podesta emails. As US intelligence agencies were contemplating counter-attacks, the Shadow Brokers code release was to be seen as a warning: "Retaliate for the D.N.C., and there are a lot more secrets, from the hackings of the State Department, the White House and the Pentagon, that might be spilled as well. One senior official compared it to the scene in The Godfather where the head of a favorite horse is left in a bed, as a warning."[40]
In 2019, David Aitel, a computer scientist formerly employed by the NSA, summarized the situation with: "I don't know if anybody knows other than the Russians. And we don't even know if it's the Russians. We don't know at this point; anything could be true."[41]
I am reading a book on ethical hacking, and it has some examples in Python which I won't post here unless asked since this isn't Stack Overflow. But, I was wondering, if a hacker was trying to access passwords in /etc/shadow, how do they do that without root access? They can't copy it, open it; etc. Is there some brute force method?
To that end, someone could gain access to a daemon which may have root privileges, and then induce this daemon to read the contents of the /etc/shadow file. I've seen many examples throughout my career where developers or unknowledgeable sysadmins have run applications such as Tomcat or Apache as root.
These same methods can be used to augment the permissions on files as well, though a good hacker would not do something so obvious as to be detected, safer to read the contents of these files and stash them somewhere else or retrieve them from the box.
Its been about 3 years since I last released this, now for some of you who have played this before you probably wont feel like much has changed since the last release but there has been quite a few additions and a lot of bug fixes that I will list towards the end of the hack description.
Now on to the additions from last release; to speed up the game the hack now uses the Sonic 3 and Knuckles object manager, every act (besides the first) has a beginning cutscene and every end of act has a cutscene (this is to make the zone changes make a little more sense), every level now has background scrolling, there is a new boss in Massacre Temple (wont say what it is), Tidal Tempest good future is now using the right art instead of a recolored present, Wacky Workbench now has enemies, a cycling palette for the bounching floors and some platforms that bounce on them, super sonic stars load once the time travel timer starts, hyper sonic and super sonic stars now load, Tails has working flickies when hyper, Shadow now has his own special stage sprites, Shadows in game sprites no longer have inconsistencies, his skating animation now doesnt speed up when increasing speed, and some new music and updated music. Now for the bug fixes; the hack has been played will all the characters and does not crash (tested on Regen and Kega) like the previous version, the bubble bounce now bounces Sonic off objects correctly (no longer act like they were deleted), if you get hurt during a bubble bounce it wont crash the game now, FMZ/FCZ Sol now has the ice spike balls using the right colors, the ice block is also using the right colors and palette line, and the breakable floors art is no longer glitched, Yardin in TTZ is no longer glitched, Mt Inferno's earthquake event now working, MDZ's moving platform now using correct art, the orbs in ACZ now loading correctly, some others I have forgotten (there were a lot which I apologize for, from the previous version).. there are three new ones though, in Kega Fusion sidekick will try to keep going to the left, reseting the level, returing from a big ring, or checkpoint will sometimes cause the background to no longer be centered correctly, the first catapult in MCZ can appear glitched but it will fix itself if you go off screen and go back to it.
A couple Notes: The water ripple effect is disabled if you are playing a player mode with a sidekick, having super birds can lag the game pretty badly, and if you get stuck or want to reset the level for any reason pause and press the C (D key) button. The HPZ shrine is incomplete, but you only need to repeat one of the special stages to unlock Hyper.
Okay note from the hacker here, if you do make it to the HPZ shrine I goffed and beating one of the special stages does not unlock hyper and a crash or soft lock can occur when returning from the ring, forgot to clear the flag used to play a cutscene, when returning from the HPZ shrine.
I beat wacky workbench in the present as Sonic & Tails. Then the game softlocked me in wacky workbench, but when I died due to time over and beat the boss again, it progressed properly to Dystopia Zone. What could have caused that?
Something similar happened with after beating Mt. Inferno as Shadow. I beat the stage, then the automatic cutscene got stuck with shadow being unable to use that loop in said cutscene, softlocking the game.
I remembered playing this back in 2015, and I don't really recall much from playing it aside from the slowdown and bugs, though I will say that this verison is a lot less buggy and laggy from previous verisons. I liked the level design for the most part, but I honestly felt there were some gimmicks that didn't really serve too much of a purpose, for instance the Time Travel gimmick. I also loved the smps ports, but I'm not too surprised since I already know you are an expert at music =P
03c5feb9e7