Table of Contents

Hackedteam
hacking-team.jpg
organizer: niekt0
date/time: 9.7.2015 19:00
place: brmlab
stream: jen ten neoficiální

Drazi supi, internetove more nam vyplavilo obzvlaste velkou a smrdutou zdechlinu. Nuze hodujme.

K dispozici by meli byt kompletni leaknute data (400G), mozna i zaindexovane jestli se to stihne. Cilem je najit co nejvic informaci relevantnich pro nasi malou cz-sk gubernii.

http://www.csoonline.com/article/2943968/data-breach/hacking-team-hacked-attackers-claim-400gb-in-dumped-data.html https://www.reddit.com/r/HackedTeam

Data processing

Support database

It seems that most exploits are created semi-automatically as one-time droppers to prevent misuse. This means that every exploit has been processed as a support ticket.

Extraction script: http://nat.brmlab.cz/ht-cherrypick/getcz.sh

Extracted tickets by Czech police: http://nat.brmlab.cz/ht-cherrypick/supcz.tar.gz and http://nat.brmlab.cz/ht-cherrypick/supczold.tar.gz

Currently the following techniques were identified as being used by the Czech police:

General spyware info

It looks like the Hackingteam spyware won't install inside virtual machine or when one of the following processes is running: