الأربعاء، 24 يناير 2024

Learning Resources For Hacking And Pentesting


In this article, I'm going to provide you a list of resources which I have found very useful. I don't remember all of them from top of my head so I might miss some. This list will be updated on usual basis. Hope you'll find some good stuff to learn. If you have got suggestions leave them down below in the comments section.

Free Hands on Labs:

1. Hack The Box - live machines to hack your way around. Besides boxes they have awesome challenges and great labs to try out.
2. TryHackMe - great way to learn pentesting while doing it. Lots of machines to hack and lots of ground to cover.
3. Portswigger Web Security Academy - learn web application pentesting.

Free Training (Mostly Introductory stuff):

1. Tenable University - training and certification on Nessus etc.
2. Palo Alto Networks - Palo Alto Networks offers an abundance of resources to prepare for there certifications. The training is free but the exams cost.
3. Open P-TECH - has an introductory course on Cybersecurity Fundamentals.
4. IBM Security Learning Academy - has many courses but focused on IBM security services and 
products.
5. Cisco Networking Academy - not all courses are free but Introduction to Cybersecurity and Cybersecurity Essentials are free.
6. AWS Training and Certification - has some free cloud security training courses.
7. Metasploit Unleashed - Free Online Ethical Hacking Course - Offensive Security's free online course on metasploit.
8. Coursera and Edx - you already know about them.

Blogs:

1. HackTricks - This is simply an awesome blog just visit it and you'll fall in love.
2. pentestmonkey - I visit it most of the time for one-liner reverse shells they are awesome.

Writeups:

1. 0xdf

YouTube:

1. ippsec - an awesome YouTube channel with tons of information in every video. New video comes out weekly as soon as the machine on hackthebox expires. https://ippsec.rocks for video searching
2. xct - short walkthroughs on hackthebox machines.
3. Cristi Vlad - advice and content on pentesting and python.
4. LiveOverflow - reverse engineering on steroids.
5. SANS Pen Test Training - SANS institute webinars and talks.
6. VbScrub - great pentesting videos.
7. BinaryAdventure - great pentesting and reverse engineering videos.
8. GynvaelEN - great videos and talks about CTFs and pentesting.

GitHub Repos:

1. PayloadsAllTheThings - heaven of hackers.
2. Pentest Monkey - reverse shells and more.
Related articles
  1. Pentest Tools Alternative
  2. Hack Tool Apk
  3. Beginner Hacker Tools
  4. Hacking Tools Software
  5. Hack Tools Online
  6. Pentest Tools Tcp Port Scanner
  7. Hacker Tools Github
  8. Hack Tools For Ubuntu
  9. Pentest Tools
  10. Usb Pentest Tools
  11. Pentest Tools For Ubuntu
  12. Hack Tools Download
  13. Hack Website Online Tool
  14. Pentest Tools Apk
  15. Pentest Tools Framework
  16. Hacking Tools Free Download
  17. Hack Tools For Games
  18. Game Hacking
  19. Pentest Recon Tools
  20. Hacker Tools Free
  21. Hacker Tools Free
  22. Hack Tools Online
  23. Pentest Tools Bluekeep
  24. Hacker
  25. Hacker Tools List
  26. Hack App
  27. Pentest Tools Alternative
  28. Hacker Tools Windows
  29. Best Hacking Tools 2019
  30. Pentest Tools For Windows
  31. Hacking Tools Windows
  32. Bluetooth Hacking Tools Kali
  33. Hacker Tools For Windows
  34. Hack Apps
  35. Usb Pentest Tools
  36. Pentest Tools Download
  37. Hack Tool Apk No Root
  38. Hack Tools
  39. Pentest Tools Apk
  40. Hacker Tools Windows
  41. Hacking Tools Windows 10
  42. Hacking Tools For Windows
  43. Pentest Reporting Tools
  44. Growth Hacker Tools
  45. Hacker Hardware Tools
  46. Hacking Tools 2020
  47. Pentest Tools Url Fuzzer
  48. Pentest Tools
  49. Nsa Hack Tools
  50. Best Pentesting Tools 2018
  51. Beginner Hacker Tools
  52. Pentest Box Tools Download
  53. Hacker Tools Online
  54. Wifi Hacker Tools For Windows
  55. Hacking Tools Windows
  56. Install Pentest Tools Ubuntu
  57. Hacking Tools Online
  58. Pentest Tools Online
  59. Pentest Automation Tools

This Is The End - And The Beginning

This post is just to inform everyone that do not expect any new blog posts here, I am moving everything to Jekyll + Github pages. 

You can find the old posts and all the new posts here: 

https://httpscolonforwardslashforwardslashwwwdotzoltanbalazsdotcom.com/

So long Google.


Continue reading

  1. Ethical Hacker Tools
  2. Hacker Tools For Mac
  3. Hacker Tools Software
  4. New Hack Tools
  5. Pentest Tools Website
  6. Hacker Tools For Windows
  7. Hacking Tools For Mac
  8. Hacker Tools Free
  9. Underground Hacker Sites
  10. Hacker Tool Kit
  11. Easy Hack Tools
  12. Growth Hacker Tools
  13. Hacker Tools Online
  14. Blackhat Hacker Tools
  15. Pentest Tools Android
  16. Hacker Tools Windows
  17. Hacks And Tools
  18. Hacker
  19. Hacking Tools For Kali Linux
  20. Hack Tools Download
  21. Pentest Tools For Android
  22. Hack And Tools
  23. Hacking Tools Pc
  24. Hack Tools For Pc
  25. Nsa Hack Tools
  26. Termux Hacking Tools 2019
  27. Tools For Hacker
  28. Pentest Tools Kali Linux
  29. Hacking Tools Download
  30. Pentest Tools Open Source
  31. Hacker Tools For Mac
  32. Hacking Tools For Games
  33. Easy Hack Tools
  34. Nsa Hack Tools Download
  35. Pentest Tools Apk
  36. Android Hack Tools Github
  37. Wifi Hacker Tools For Windows
  38. Hacking Tools Windows
  39. Hacking Tools Windows
  40. Hack Apps
  41. Blackhat Hacker Tools
  42. Growth Hacker Tools
  43. Pentest Tools Bluekeep
  44. Hacker Security Tools
  45. Pentest Box Tools Download
  46. Hacker Tools Software
  47. Nsa Hacker Tools
  48. Pentest Reporting Tools
  49. Hackrf Tools
  50. Pentest Tools For Windows
  51. Top Pentest Tools
  52. Hacking Tools For Games
  53. Hack Tool Apk
  54. New Hack Tools
  55. Pentest Tools
  56. Hack Rom Tools
  57. Usb Pentest Tools
  58. Hack Apps
  59. Beginner Hacker Tools
  60. Pentest Tools Kali Linux
  61. Beginner Hacker Tools
  62. Hacker
  63. Hack Tools
  64. Termux Hacking Tools 2019
  65. Hacker Hardware Tools
  66. Pentest Tools For Mac
  67. Hacking Tools Windows
  68. Pentest Tools For Android
  69. Hacker Tool Kit
  70. Pentest Tools Website Vulnerability
  71. Hacking Tools Github
  72. Pentest Tools Bluekeep
  73. Hacker
  74. Hack Tools 2019
  75. Hack Tools Download
  76. Hack Tools For Ubuntu
  77. Hacking Apps
  78. Tools For Hacker
  79. Hacking Tools Free Download
  80. Hack Tools 2019
  81. Hack Website Online Tool
  82. Hack Tools For Games
  83. Pentest Tools For Mac
  84. Hack App
  85. Pentest Tools Alternative
  86. Hacking Tools For Windows
  87. Hacker Tool Kit
  88. Physical Pentest Tools
  89. Pentest Tools Free
  90. How To Install Pentest Tools In Ubuntu
  91. Hacker Security Tools
  92. Hack Tools For Windows
  93. Hacking Tools For Pc
  94. Hacker Tools 2019
  95. Hacking Tools And Software
  96. Pentest Automation Tools
  97. Pentest Tools Open Source
  98. Hacker Tools Linux
  99. Hacking Tools 2020
  100. Hacker Search Tools
  101. Hacking Tools Pc
  102. Best Hacking Tools 2019
  103. Best Hacking Tools 2020
  104. Hacking Tools Github
  105. Hacking Tools For Pc
  106. Hacking Tools For Games
  107. Hacking Tools For Pc
  108. How To Hack
  109. Pentest Tools Website
  110. World No 1 Hacker Software
  111. New Hack Tools
  112. New Hack Tools
  113. Hacker Tools Apk Download
  114. Pentest Tools Review
  115. Hacking Tools Pc
  116. Hacking Tools For Kali Linux
  117. Hacker Tools Online
  118. Hacking Tools Pc
  119. Pentest Tools Free
  120. Github Hacking Tools
  121. Pentest Tools Download
  122. Growth Hacker Tools
  123. Hack Tools Mac
  124. Pentest Tools Apk
  125. Hacker Tools For Ios
  126. Pentest Tools For Android
  127. Hacker Tools 2020
  128. Pentest Tools For Ubuntu
  129. Pentest Tools Github
  130. Hacker Tools For Ios
  131. Hack And Tools
  132. Pentest Tools
  133. Hacking Tools For Pc
  134. Hacker Tools Online
  135. Pentest Reporting Tools
  136. Hacker Search Tools
  137. Hack Tools For Windows
  138. Hack Tools
  139. Pentest Tools For Ubuntu

الثلاثاء، 23 يناير 2024

Vlang Binary Debugging

Why vlang? V is a featured, productive, safe and confortable language highly compatible with c, that generates neat binaries with c-speed, the decompilation also seems quite clear as c code.
https://vlang.io/

After open the binary with radare in debug mode "-d" we proceed to do the binary recursive analysis with "aaaa" the more a's the more deep analys.



The function names are modified when the binary is crafted, if we have a function named hello in a module named main we will have the symbol main__hello, but we can locate them quicly thanks to radare's grep done with "~" token in this case applied to the "afl" command which lists all the symbols.


Being in debug mode we can use "d*" commands, for example "db" for breakpointing the function and then "dc" to start or continue execution.


Let's dissasemble the function with "pD" command, it also displays the function variables and arguments as well, note also the xref "call xref from main"


Let's take a look to the function arguments, radare detect's this three 64bits registers used on the function.


Actually the function parameter is rsi that contains a testing html to test the href extraction algorithm.


The string structure is quite simple and it's plenty of implemented methods.




With F8 we can step over the code as we were in ollydbg on linux.


Note the rip marker sliding into the code.


We can recognize the aray creations, and the s.index_after() function used to find substrings since a specific position.


If we take a look de dissasembly we sill see quite a few calls to tos3() functions.
Those functions are involved in string initialization, and implements safety checks.

  • tos(string, len)
  • tos2(byteptr)
  • tos3(charptr)

In this case I have a crash in my V code and I want to know what is crashing, just continue the execution with "dc" and see what poits the rip register.



In visual mode "V" we can see previous instructions to figure out the arguments and state.


We've located the crash on the substring operation which is something like "s2 := s1[a..b]" probably one of the arguments of the substring is out of bounds but luckily the V language has safety checks and is a controlled termination:



Switching the basic block view "space" we can see the execution flow, in this case we know the loops and branches because we have the code but this view also we can see the tos3 parameter "href=" which is useful to locate the position on the code.



When it reach the substr, we can see the parameters with "tab" command.



Looking the implementation the radare parameter calculation is quite exact.


Let's check the param values:


so the indexes are from 0x0e to 0x24 which are inside the buffer, lets continue to next iteration,
if we set a breakpoint and check every iteration, on latest iteration before the crash we have the values 0x2c to 0x70 with overflows the buffer and produces a controlled termination of the v compiled process.





Read more


  1. Hacker Tools List
  2. Hacker Search Tools
  3. Hack Tool Apk No Root
  4. Pentest Tools Free
  5. Tools For Hacker
  6. Pentest Recon Tools
  7. Hacker Security Tools
  8. Pentest Tools Framework
  9. Hack Tools Mac
  10. Github Hacking Tools
  11. Best Hacking Tools 2019
  12. Hacking Tools 2019
  13. Hacking Tools Name
  14. Hacking Tools Windows 10
  15. Hack And Tools
  16. World No 1 Hacker Software
  17. Pentest Tools Website Vulnerability
  18. Black Hat Hacker Tools
  19. How To Hack
  20. Nsa Hack Tools
  21. Hacking Tools Mac
  22. Hacker Tools Windows
  23. Hack And Tools
  24. Nsa Hacker Tools
  25. Hacker Tools Windows
  26. Hack Tools
  27. Hacking Tools Windows 10
  28. Hak5 Tools
  29. Hacking Tools Download
  30. Pentest Tools Website Vulnerability
  31. Easy Hack Tools
  32. Physical Pentest Tools
  33. Install Pentest Tools Ubuntu
  34. Pentest Tools List
  35. Pentest Tools Download
  36. Underground Hacker Sites
  37. Pentest Tools Github
  38. Hack And Tools
  39. Pentest Tools Url Fuzzer
  40. Hacking Tools
  41. Hack Tools For Mac
  42. Pentest Tools Tcp Port Scanner
  43. Best Pentesting Tools 2018
  44. Hacker Hardware Tools
  45. Hacker Tools Windows
  46. Physical Pentest Tools
  47. Beginner Hacker Tools
  48. Hack App
  49. Pentest Tools Linux
  50. Pentest Tools Framework
  51. Pentest Tools Subdomain
  52. Computer Hacker
  53. Pentest Tools Port Scanner
  54. Hacking Tools Hardware
  55. Free Pentest Tools For Windows
  56. World No 1 Hacker Software
  57. Hacking Tools For Mac
  58. Hack And Tools
  59. Hacker Tools For Ios
  60. Hack Rom Tools
  61. Pentest Tools List
  62. Computer Hacker
  63. Hack Tools Pc
  64. World No 1 Hacker Software
  65. Pentest Tools Website
  66. Hack App
  67. Hacker Techniques Tools And Incident Handling
  68. Growth Hacker Tools
  69. Pentest Tools Android
  70. Hack Tools For Mac
  71. Termux Hacking Tools 2019
  72. Hacking Tools Software
  73. Top Pentest Tools
  74. Hack Tools For Ubuntu
  75. Pentest Tools Open Source
  76. Nsa Hack Tools
  77. Pentest Tools Alternative
  78. Hack Tools For Pc
  79. Hacker Tools For Windows
  80. Hacker Tools Software
  81. Pentest Tools Review
  82. Pentest Tools Find Subdomains
  83. Physical Pentest Tools
  84. Pentest Tools Bluekeep
  85. Usb Pentest Tools
  86. Hacker Tools 2019
  87. How To Install Pentest Tools In Ubuntu
  88. Hacker
  89. New Hack Tools
  90. Wifi Hacker Tools For Windows
  91. Hack Tools Github
  92. Best Hacking Tools 2020
  93. Pentest Tools Port Scanner
  94. Beginner Hacker Tools
  95. Hack Tools For Mac
  96. Hacker Search Tools
  97. Pentest Tools Online
  98. How To Make Hacking Tools
  99. Pentest Tools Download
  100. Hack Tools Online
  101. How To Hack
  102. Hacker Tools
  103. New Hack Tools
  104. Nsa Hacker Tools
  105. Best Hacking Tools 2020
  106. Hacking Tools 2020
  107. Hack Tool Apk No Root
  108. Hacking Tools Mac
  109. Hacking Tools Software
  110. Pentest Tools Review
  111. Pentest Tools
  112. Pentest Tools Port Scanner
  113. World No 1 Hacker Software
  114. Pentest Tools Kali Linux
  115. Hack Tools
  116. Underground Hacker Sites
  117. Hacking Tools For Windows
  118. Hack Tools
  119. Hack Tools For Games
  120. Hacker Tool Kit
  121. Pentest Tools Kali Linux
  122. Hacker Tools For Mac
  123. Hacking Apps
  124. Hacking Tools For Games
  125. Hacker Tools For Pc
  126. Pentest Tools Download
  127. Hacker Tools Free
  128. Pentest Tools
  129. Hak5 Tools
  130. Hackrf Tools
  131. How To Install Pentest Tools In Ubuntu
  132. Hacking Tools For Windows 7
  133. Black Hat Hacker Tools
  134. Pentest Tools Review
  135. What Are Hacking Tools
  136. Hacking Tools For Beginners
  137. Hacking Tools For Kali Linux
  138. Termux Hacking Tools 2019
  139. Hacker Tools Free Download
  140. Underground Hacker Sites
  141. Pentest Tools For Mac
  142. Hacker Tools
  143. Hack Tool Apk No Root
  144. Hacker Tools For Mac
  145. What Are Hacking Tools
  146. Hacking Tools Kit
  147. Hacker Techniques Tools And Incident Handling
  148. Hacker Tools Linux
  149. Hacking Tools For Games
  150. Hacker Tools For Ios
  151. How To Make Hacking Tools
  152. Hacking Tools Usb

Why (I Believe) WADA Was Not Hacked By The Russians

Disclaimer: This is my personal opinion. I am not an expert in attribution. But as it turns out, not many people in the world are good at attribution. I know this post lacks real evidence and is mostly based on speculation.



Let's start with the main facts we know about the WADA hack, in chronological order:


1. Some point in time (August - September 2016), the WADA database has been hacked and exfiltrated
2. August 15th, "WADA has alerted their stakeholders that email phishing scams are being reported in connection with WADA and therefore asks its recipients to be careful"  https://m.paralympic.org/news/wada-warns-stakeholders-phishing-scams
3. September 1st, the fancybear.net domain has been registered
   Domain Name: FANCYBEAR.NET    ...    Updated Date: 18-sep-2016    Creation Date: 01-sep-2016
 
4. The content of the WADA hack has been published on the website
5. The @FancyBears and @FancyBearsHT Twitter accounts have been created and started to tweet on 12th September, reaching out to journalists
6. 12th September, Western media started headlines "Russia hacked WADA"
7. The leaked documents have been altered, states WADA https://www.wada-ama.org/en/media/news/2016-10/cyber-security-update-wadas-incident-response


The Threatconnect analysis

The only technical analysis on why Russia was behind the hack, can be read here: https://www.threatconnect.com/blog/fancy-bear-anti-doping-agency-phishing/

After reading this, I was able to collect the following main points:

  1. It is Russia because Russian APT groups are capable of phishing
  2. It is Russia because the phishing site "wada-awa[.]org was registered and uses a name server from ITitch[.]com, a domain registrar that FANCY BEAR actors recently used"
  3. It is Russia because "Wada-arna[.]org and tas-cass[.]org were registered through and use name servers from Domains4bitcoins[.]com, a registrar that has also been associated with FANCY BEAR activity."
  4. It is Russia, because "The registration of these domains on August 3rd and 8th, 2016 are consistent with the timeline in which the WADA recommended banning all Russian athletes from the Olympic and Paralympic games."
  5. It is Russia, because "The use of 1&1 mail.com webmail addresses to register domains matches a TTP we previously identified for FANCY BEAR actors."

There is an interesting side-track in the article, the case of the @anpoland account. Let me deal with this at the end of this post.

My problem with the above points is that all five flag was publicly accessible to anyone as TTP's for Fancy Bear. And meanwhile, all five is weak evidence. Any script kittie in the world is capable of both hacking WADA and planting these false-flags.

A stronger than these weak pieces of evidence would be:

  • Malware sharing same code attributed to Fancy Bear (where the code is not publicly available or circulating on hackforums)
  • Private servers sharing the IP address with previous attacks attributed to Fancy Bear (where the server is not a hacked server or a proxy used by multiple parties)
  • E-mail addresses used to register the domain attributed to Fancy Bear
  • Many other things
For me, it is quite strange that after such great analysis on Guccifer 2.0, the Threatconnect guys came up with this low-value post. 


The fancybear website

It is quite unfortunate that the analysis was not updated after the documents have been leaked. But let's just have a look at the fancybear . net website, shall we?

Now the question is, if you are a Russian state-sponsored hacker group, and you are already accused of the hack itself, do you create a website with tons of bears on the website, and do you choose the same name (Fancy Bear) for your "Hack team" that is already used by Crowdstrike to refer to a Russian state-sponsored hacker group? Well, for me, it makes no sense. Now I can hear people screaming: "The Russians changed tactics to confuse us". Again, it makes no sense to change tactics on this, while keeping tactics on the "evidence" found by Threatconnect.

It makes sense that a Russian state-sponsored group creates a fake persona, names it Guccifer 2.0, pretends Guccifer 2.0 is from Romania, but in the end it turns out Guccifer 2.0 isn't a native Romanian speaker. That really makes sense.

What happens when someone creates this fancybear website for leaking the docs, and from the Twitter account reaches out to the media? Journalists check the website, they see it was done by Fancy Bear, they Bing Google this name, and clearly see it is a Russian state-sponsored hacker group. Some journalists also found the Threatconnect report, which seems very convincing for the first read. I mean, it is a work of experts, right? So you can write in the headlines that the hack was done by the Russians.

Just imagine an expert in the USA or Canada writing in report for WADA:
"the hack was done by non-Russian, but state-sponsored actors, who planted a lot of false-flags to accuse the Russians and to destroy confidence in past and future leaks". Well, I am sure this is not a popular opinion, and whoever tries this, risks his career. Experts are human, subject to all kinds of bias.

The Guardian

The only other source I was able to find is from The Guardian, where not just one side (it was Russia) was represented in the article. It is quite unfortunate that both experts are from Russia - so people from USA will call them being not objective on the matter. But the fact that they are Russian experts does not mean they are not true ...

https://www.theguardian.com/sport/2016/sep/15/fancy-bears-hackers--russia-wada-tues-leaks

Sergei Nikitin:
"We don't have this in the case of the DNC and Wada hacks, so it's not clear on what basis conclusions are being drawn that Russian hackers or special services were involved. It's done on the basis of the website design, which is absurd," he said, referring to the depiction of symbolically Russian animals, brown and white bears, on the "Fancy Bears' Hack Team" website.

I don't agree with the DNC part, but this is not the topic of conversation here.

Alexander Baranov:
"the hackers were most likely amateurs who published a "semi-finished product" rather than truly compromising information. "They could have done this more harshly and suddenly," he said. "If it was [state-sponsored] hackers, they would have dug deeper. Since it's enthusiasts, amateurs, they got what they got and went public with it.""

The @anpoland side-track

First please check the tas-cas.org hack https://www.youtube.com/watch?v=day5Aq0bHsA  , I will be here when you finished it. This is a website for "Court of Arbitration for Sport's", and referring to the Threatconnect post, "CAS is the highest international tribunal that was established to settle disputes related to sport through arbitration. Starting in 2016, an anti-doping division of CAS began judging doping cases at the Olympic Games, replacing the IOC disciplinary commission." Now you can see why this attack is also discussed here.


  • My bet is that this machine was set-up for these @anpoland videos only. Whether google.ru is a false flag or it is real, hard to decide. It is interesting to see that there is no google search done via google.ru, it is used only once. 
  • The creator of the video can't double click. Is it because he has a malfunctioning mouse? Is it because he uses a virtualization console, which is near-perfect OPSEC to hide your real identity? My personal experience is that using virtualization consoles remotely (e.g. RDP) has very similar effects to what we can see on the video. 
  • The timeline of the Twitter account is quite strange, registered in 2010
  • I agree with the Threatconnect analysis that this @anpoland account is probably a faketivist, and not an activist. But who is behind it, remains a mystery. 
  • Either the "activist" is using a whonix-like setup for remaining anonymous, or a TOR router (something like this), or does not care about privacy at all. Looking at the response times (SQLmap, web browser), I doubt this "activist" is behind anything related to TOR. Which makes no sense for an activist, who publishes his hack on Youtube. People are stupid for sure, but this does not add up. It makes sense that this was a server (paid by bitcoins or stolen credit cards or whatever) rather than a home computer.
For me, this whole @anpoland thing makes no sense, and I think it is just loosely connected to the WADA hack. 

The mysterious Korean characters in the HTML source

There is another interesting flag in the whole story, which actually makes no sense. When the website was published, there were Korean characters in HTML comments. 



When someone pointed this out on Twitter, these Korean HTML comments disappeared:
These HTML comments look like generated HTML comments, from a WYSIWYG editor, which is using the Korean language. Let me know if you can identify the editor.

The Russians are denying it

Well, what choice they have? It does not matter if they did this or not, they will deny it. And they can't deny this differently. Just imagine a spokesperson: "Previously we have falsely denied the DCC and DNC hacks, but this time please believe us, this wasn't Russia." Sounds plausible ...

Attribution

Let me sum up what we know:

It makes sense that the WADA hack was done by Russia, because:

  1. Russia being almost banned from the Olympics due to doping scandal, it made sense to discredit WADA and US Olympians
  2. There are multiple(weak) pieces of evidence which point to Russia
It makes sense that the WADA hack was not done by  Russia, because: 
  1. By instantly attributing the hack to the Russians, the story was more about to discredit Russia than discrediting WADA or US Olympians.
  2. In reality, there was no gain for Russia for disclosing the documents. Nothing happened, nothing changed, no discredit for WADA. Not a single case turned out to be illegal or unethical.
  3. Altering the leaked documents makes no sense if it was Russia (see update at the end). Altering the leaked documents makes a lot of sense if it was not Russia. Because from now on, people can always state "these leaks cannot be trusted, so it is not true what is written there". It is quite cozy for any US organization, who has been hacked or will be hacked. If you are interested in the "Russians forging leaked documents" debate, I highly recommend to start with this The Intercept article
  4. If the Korean characters were false flags planted by the Russians, why would they remove it? If it had been Russian characters, I would understand removing it.
  5. All evidence against Russia is weak, can be easily forged by even any script kittie.

I don't like guessing, but here is my guess. This WADA hack was an operation of a (non-professional) hackers-for-hire service, paid by an enemy of Russia. The goal was to hack WADA, leak the documents, modify some contents in the documents, and blame it all on the Russians ...

Questions and answers

  • Was Russia capable of doing this WADA hack? Yes.
  • Was Russia hacking WADA? Maybe yes, maybe not.
  • Was this leak done by a Russian state-sponsored hacker group? I highly doubt that.
  • Is it possible to buy an attribution-dice where all six-side is Russia? No, it is sold-out. 

To quote Patrick Gray: "Russia is the new China, and the Russians ate my homework."©

Let me know what you think about this, and please comment. 

More information