22 ms·
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
- campuscodi 9y agoIt's not 12 nations.... it's all over the world...
- erikbye 9y agoYes, 70+ countries.
- jstanley 9y agoBotnets don't care about countries. It's not an attack against 70+ countries, it's an attack against everyone on the internet.
- erikbye 9y agoThe point was that it is worldwide.
- jstanley 9y agoWhen a nuclear bomb is dropped on Hiroshima, is that an attack against hundreds of buildings, or is it an attack against Hiroshima? :) Thinking of it as "an attack against 70+ countries" is an anachronism. The attack doesn't care about countries. It doesn't even need to acknowledge their existence.
- nyolfen 9y agoWe really are living in the future. My condolences to the NHS, but what a time to be alive.
- doktrin 9y agoOut of curiosity, what about this attacks feels futuristic? If anything it feels very retro, in that it hails back to the notorious worm attacks from the earliest days of networked computing.
- nyolfen 9y agothe headline more than anything -- pilfered secret spy software stolen by (probably) a rival intelligence agency, released to the public without scrutiny, repurposed by cybercriminals, used to ransom data indiscriminately for decentralized software currency, bringing major institutions to their knees, and defeated by a guy in his bedroom at his parents' house who accidentally found a secret kill switch. it all feels very cyberpunk, and very much like a fictional plot, unfortunate circumstances aside
- nyolfen 9y agoaha, and i see i'm not the only one who thinks so: http://www.antipope.org/charlie/blog-static/2017/05/rejection-letter.html http://www.antipope.org/charlie/blog-static/2017/05/rejectio... though a bit of it is in your camp as well: > It's a worm — a boringly old-hat idea first introduced into fiction by SF author John Brunner in his 1977 novel "The Shockwave Rider".
- mhogomchungu 9y agoI am in Tanzania(East Africa) and my father's computer is infected. All he did to get infected was plugging his laptop on the network at work(University of Dar Es Salaam). The laptop is next to me and my task this night is to try to remove this thing.
- iagovar 9y agoJust that? No click somehwhere?
- raesene6 9y agoIf someone connects to a network which has been infected and they've not applied the appropriate patch (MS17-010) it looks like they're in trouble if they're running Windows and don't have a firewall blocking incoming connections. So first person in a network has to have fallen for the phishing attack, but once it's in the network it can spread via the ETERNALBLUE exploit.
- crocal 9y agoI confirm that. Once inside network it's a carnage.
- smelendez 9y agoIt can copy itself across a network through a vulnerability in SMB, Windows' file-sharing protocol. That's the bug that was disclosed in the NSA leaks. Microsoft released a patch in March, but of course not all computers are patched.
- rhizome 9y agoClicks are for phishing and trojans, i.e. human vulnerabilities. This is due to an operating system bug, which is a technical vulnerability. If you can get the right network packets to an unpatched machine, you can infect that machine.
- devrandomguy 9y agoThis malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against future attacks.
- RangerScience 9y ago> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. Of course, as @mhogomchunu points out in his comment - is this the sort of thing where only one weak link is needed? Still. Maybe this will help the proponents of keeping government systems updated? And/or, maybe this will prompt companies like MS to roll out security-only updates, to make it easier for sysadmins to keep their systems up-to-date...? (presumably, a reason why these systems weren't updated is due to functionality concerns with updates...?)
- dekhn 9y agoIf you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc).
- stonogo 9y agoThat's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-documented for several years. In the general case, "I have a lot of machines" is an excuse provided by the unable to evade being held responsible by the uninformed.
- bluGill 9y ago
- deleted 9y ago[deleted]
- Asdfbla 9y agoOne of the side effect if states participate in the proliferation of offensive tools. Won't be the last time state-sponsored tools, exploits or backdoors fall into the hands of interested third parties. I think collateral damage like that is way underrated by politicians all around the globe that call for their respective intelligence agencies to build up offensive capabilities to be able to conduct cyber warfare and whatnot.
- willstrafach 9y agoThe vulnerability is already patched, it is not a 0-day. Regardless of the leak, anyone could have reverse engineered the security patch to see how it worked.
- dberhane 9y agoMaybe it is now the time for a major review of the NHS Microsoft software dependency and should seriously consider switching to Linux based software. Here is the BBC news update about the NHS Cyber attack: "NHS trusts 'ran outdated software' Some who have followed the issue of NHS cyber security are sharing a report from the IT news site Silicon, which reported last December that NHS trusts had been running outdated Windows XP software. The website says that Microsoft officially ended support for Windows XP back in April 2014, meaning it was no longer fixing vulnerabilities in the system - except for clients that paid for an extended support deal. The UK government initially paid Microsoft £5.5 million to keep providing security support - but the website adds that this deal ended in May 2015."
- UK-AL 9y agoA simple patching policy would have fixed this
- olivermarks 9y agohttps://youtu.be/VjfaCoA2sQk https://youtu.be/VjfaCoA2sQk Hitler rants about cloud security. Sorry couldn't resist...
- zigzigzag 9y agoLinux doesn't have a magic fix for buffer overflows in networking stacks written in C.
- ledneb 9y ago> except for clients that paid for an extended support deal It does have a fix for this, though
- 21 9y agoYeah, it's called "install the latest kernel". Upgrading to a new version of Windows was apparently not possible, which also means that upgrading to a new Linux version would also have been out of the books. So the only solution would have been to hire someone to backport whatever fix was needed.
- olliej 9y agoCyber attacks use patched exploit to attack systems running out of date software, even in large enterprises handling sensitive data? I give a pass to individuals (bandwidth for updates can be expensive, regular users don't know about patch Tuesday etc), but enterprise scale deployment should have IT for this, and IT should have been well aware of this kind of thing happening.
- daxorid 9y agoStrangely enough, people like Matt Blaze are out beating the "don't blame the victim" drum by stating the exact opposite, giving a pass to large enterprises under the "patching is hard" mantra: https://www.cs.columbia.edu/~smb/blog/2017-05/2017-05-12.html https://www.cs.columbia.edu/~smb/blog/2017-05/2017-05-12.htm...
- deleted 9y ago[deleted]
- raesene6 9y agoOne of the big problems here will be for any country which makes a lot of use of older computers using Windows XP as there is no patch for this vulnerability on that OS version. How many systems that is, is debatable but by at least one benchmark (https://www.netmarketshare.com/operating-system-market-share.aspx?qprid=10&qpcustomd=0 https://www.netmarketshare.com/operating-system-market-share...) we're looking at 7% of the desktop PC market that could be exposed with no patch available.
- chronial 9y ago> no patch available Not anymore: https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/ https://blogs.technet.microsoft.com/msrc/2017/05/12/customer...
- SomeStupidPoint 9y agoThis is what blowback looks like. The US military and intelligence communities focused hard on cyber offense, rather than improving the defensive standards and technologies practiced among allies. Because of this, several allies have important systems compromised by (essentially) US-engineered malware. Well, at least DARPA is sort of on it: http://archive.darpa.mil/cybergrandchallenge/ http://archive.darpa.mil/cybergrandchallenge/ (There's also work stemming from the HoTT body of work on verified systems, as I understand it. But that doesn't have a sexy webpage.)
- Keverw 9y agoWow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the table while eating lunch.
- jbob2000 9y agoYour analogy doesn't really work because you can't copy a gun. These tools are way more dangerous than a gun because you can replicate them very quickly. You can never destroy the tools once they are created, someone always has a copy. This is what scares me more than nuclear weapons. A nuke requires a huge amount of people and infrastructure to maintain and launch. But a digital weapon? Pfft, copy that shit onto a USB key and one guy can wipe out power stations across the entire country.
- MichaelGG 9y agoWhy are power stations on the same network with some guy with a USB key?
- ghrifter 9y agoBecause they are all connected in a IoT with MongoDB, React, and Node.js /s
- billharrison 9y agoBecause people still use USB drives to copy information to airgapped computers. It is easier than the alternatives.
- marcosdumay 9y agoYes, they do. Yes, it easier. Yet, it completely undoes the "airgap" thing.
- deleted 9y ago[deleted]
- jansho 9y agoFrom the Guardian: "He adds that the fear is that the ransonware cannot be broken and thus data and files infected are either lost or that the only way to get them back would be to pay the ransom, which would involve giving money to criminals." The new terrorism. https://www.theguardian.com/society/live/2017/may/12/england-hospitals-cyber-attack-nhs-live-updates https://www.theguardian.com/society/live/2017/may/12/england...
- pveierland 9y agoHow is it terrorism if the purpose is to get money?
- jansho 9y agoI meant it in a more general way: a group of horrible people taking over a core function of society and saying "If you don't do x we will do y." And they will actually do y. As you may have gathered, my original statement is more eloquent.
- civilian 9y agoIt isn't more eloquent, because it's wrong. Wouldn't saying: "The new mafia." or "The new shake-down" be more accurate? Terrorism is done for political reasons and often involves things that involve putting fear into the populace. Your general "If you don't do x we will do y." statement does cover terrorism, but it covers terrorism because it covers _all kinds of threats_. So I suppose what you really meant was: "The new threat." Words are important :]
- jansho 9y agoAh sorry, I got it wrong twice. But you got me thinking again: because this ransomware is targeting the infrastructure itself (national healthcare service) isn't this playing with fear too? If I was in hospital, or my friends/family, I would be acutely paranoid that medical devices will go wrong, medicine administration will go wrong, the A&E will go bonkers et cetra. I've worked in healthcare before, and this kind of domino effect is very easy to believe in. (Funnily enough, my old organisation was making a fuss about upgrading from Windows XP just last year. A lot of my colleagues complained that this was hardly a priority)
- nyolfen 9y agoBBC says up to 74 nations now: http://www.bbc.com/news/live/39901370 http://www.bbc.com/news/live/39901370
- soneca 9y ago"Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." What Microsoft's software should be updated now to protect against this particular attack? Windows? Windows at the end user machines? The servers? Could someone share a "What should I do now to protect myself" guide, please? Thanks!
- alltakendamned 9y agoFor this, run Windows update and install all updates. Additionally, it's smart to disable SMBv1 on all machines.
- degenerate 9y agoI disabled SMBv1 on the server. Good enough to protect our network share? Or is there some reason/benefit to disabling SMBv1 on client machines too? (I ran the simple powershell command on server: https://support.microsoft.com/en-us/help/2696547/how-to-enable-and-disable-smbv1,-smbv2,-and-smbv3-in-windows-vista,-windows-server-2008,-windows-7,-windows-server-2008-r2,-windows-8,-and-windows-server-2012 https://support.microsoft.com/en-us/help/2696547/how-to-enab...)
- alltakendamned 9y agoThe main one is to have _all_ machines patched through windows update. That is what will protect you. SMBv1 is an outdated protocol, in which there have been some severe vulnerabilities disclosed in the last few weeks, hence why I recommended to get rid of it at the same time. That being said, the vulnerability being exploited here is in SMBv2, hence why patching all machines is crucial.
- pryce 9y agoI notice that Microsoft is claiming the exploit is in SMBv1 in their patch description [1]. [1] https://support.microsoft.com/en-us/help/4012598/title https://support.microsoft.com/en-us/help/4012598/title
- jordan314 9y agoCan't law enforcement follow the transactions of the public address of the ransom bitcoin wallet until the bitcoin is sold?
- lossolo 9y agoThere are services that will mix your coins making it impossible to track because he will receive other people coins from the pool.
- 21 9y agoNot impossible, just hard. And the cops can go and track each individual person from that pool if they really care. Even if we are talking about thousands. Remember the story from a few days ago where to track a possible spy they went through all glasses prescriptions from a city.
- lossolo 9y agoIt's different beast. It's almost impossible if done right. How would you track this person? You only see end transactions from those addresses which are not mixed with coins of attackers. You would need to check EVERY possible place where bitcoin exchange happen and there hundreds in hundreds of countries in blind to check if bitcoin address x was used there. Then some countries maybe even will not give you any information because electronic currency doesn't exist in their law and it's not a felony to use mixing service etc. etc. That's why they use bitcoin in the first place for 99% of criminal activities in Internet.
- QML 9y agoDo you think it would be possible for those services to block or 'embargo' transactions from 'tainted' addresses, such as the ones used for the cyberattacks' ransom?
- lossolo 9y agoWhy would they? It's against their business model. They don't have company name and street address on their sites for a reason.
- natch 9y agoThis gives the lie to the notion that a government master key or back door scheme could be protected from leaks and abuse.
- dhimes 9y agoCame here to say this. I completely agree.
- anigbrowl 9y agoI do not believe that attacks of this scale or coordination are undertaken by private actors. This is warfare; it just isn't kinetic yet.
- ComodoHacker 9y agoEdit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-010.aspx https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomware-used-in-widespread-attacks-all-over-the-world/ https://securelist.com/blog/incidents/78351/wannacry-ransomw...
- dhimes 9y agoAre we watching this thing wake up right now?
- devrandomguy 9y agoWe are seeing new requests from existing bots, the historical data is not shown on this map.
- dhimes 9y agoGotcha. So yeah, we're seeing it wake up. The first little increase (up to 600) was about the time the article was published.
- knowaveragejoe 9y agoWhere are you seeing this? This isn't historical data.
- squeaky-clean 9y agoHere's a page with more info https://intel.malwaretech.com/botnet/wcrypt https://intel.malwaretech.com/botnet/wcrypt
- dhimes 9y ago
- turnip123942 9y agoI think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
- slashcom 9y agoI worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
- betenoire 9y agoHumor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
- bajsejohannes 9y agoHow would you practically do that? Send all those encrypted hard drives to NSA to be decrypted? Publish the backdoor, effectively rendering that encryption scheme broken?
- asdfgadsfgasfdg 9y agoJust ask the NSA to send you the un-encrypted files - they probably have them in their database anyway.
- H1Supreme 9y agoThen encryption wouldn't be doing what it's set out to do.
- ajmurmann 9y agoSo developers of ransomware would build backdoors into their ransomware because the law requires them to?
- TomK32 9y agoSo... I'm running Linux on all my systems, how bad will it be for me?
- TomK32 9y agoOh, and I'm flying tomorrow, what software does an Airbus run on?
- crocal 9y agoSCADE, FWIW...
- deleted 9y ago[deleted]
- doubleunplussed 9y agoMy university sent around an email with a photo of GRUB displaying some ransomware message with a demand 222 bitcoins. Sure freaked me out, as a linux user who usually gets to ignore emails like this, but upon investigation it was unrelated [1] to today's events. The screenshot was of ransomware that while still terrifying, existed before today. [1] https://www.welivesecurity.com/2017/01/05/killdisk-now-targeting-linux-demands-250k-ransom-cant-decrypt/ https://www.welivesecurity.com/2017/01/05/killdisk-now-targe...
- c3534l 9y agoIt could also just be the NSA banking on everyone assuming it's someone using NSA tools.
- JackFr 9y agoAs far as I can see it hasn't moved the needle on Bitcoin/$ today though. Ransom ware was a play for big Bitcoin holders to unwind large positions at the highs without too much downward pressure in Bitcoin market.
- jayess 9y agoYou can keep an eye on their bitcoin wallet (or at least one of them): https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N...
- sp332 9y agoTwo others are https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX... and https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8is...
- zyztem 9y ago12 Nations that did not apply security patches
- brilliantcode 9y agoIsn't it peculiar that Russia remains the least hit or not even hit at all? It seems like the West was a clear target. Connecting the dots here, it's suffice to say Shadow Brokers serves Russian interests. We are seeing bullet holes from what seem to have been cyber warfare between the former cold war foes.
- tankenmate 9y agoTime of day, come back in 12 hours and check again. That said the Russian government is trying to move people to local distributions of Linux, like Astra Linux, but I don't think the uptake is enough to explain low infection rate in Russia.
- brilliantcode 9y agoYeah definitely downvote manipulations going on again... At this point I'm not even upset or shocked. It just further supports the narrative Russia is seeking to manipulate/exploit the internet to their benefit. Considering the average Russian is poorer than an Indian, it looks like Putin is going to fuck over his country as his countrymen cheer him on and suffer in poverty and alcoholism. The West will crush the feeble Russian economy back to Tsar days.
- ghrifter 9y agoBernie's loss still sting?
- dang 9y agoWe asked you many times to stop breaking the Hacker News guidelines with uncivil and unsubstantive comments. Since you've ignored us, continued, and gotten worse, we've banned your account. Insinuations of astroturfing and shillage without evidence are not allowed here [1], and bad enough, but national rants and slurs are completely unwelcome. 1. https://hn.algolia.com/?sort=byDate&prefix=true&page=0&dateRange=all&type=comment&query=by:dang%20astroturf https://hn.algolia.com/?sort=byDate&prefix=true&page=0&dateR...
- lukaa 9y agoJust use Linux and 90% of your problems with malware is history.Your own customization of kernel will make your even more secure.
- Cakez0r 9y agoLet's not pretend that Linux is invulnerable to the class of exploits that make this kind of malware possible [1]. Windows isn't a target because it's vulnerable (all software is vulnerable). Windows is targeted because it's widely used. If the majority of systems were using Linux, malware authors would simply adapt to write malware targeting Linux instead. [1] https://nvd.nist.gov/vuln/detail/CVE-2016-7117 https://nvd.nist.gov/vuln/detail/CVE-2016-7117
- devrandomguy 9y agoall software is vulnerable This is false, and spreads FUD. It does a great disservice to those who do meticulously maintain their systems, to those who sacrifice convenience and beauty for stability and security, to those who take the time to scrutinize other people's work. It is possible to build and deploy secure software. Linux dominates the datacenter; we are a high value target, and have been for quite some time now.
- wu-ikkyu 9y ago>It is possible to build and deploy secure software. By secure, you don't mean 100% secure, do you?
- devrandomguy 9y agoI mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.
- wu-ikkyu 9y agoHas there ever been such a product? What about exploits on the software/hardware underlying the supposedly secure software?
- cryogenspirit 9y agoQ: does anyone know how to disable regular internet access in Windows except through a virtual machine (VMware or Virtualbox)? I have set up my mom to use a live debian cd through VMware, but I would also like to disable networking through Windows Edge and Explorer. I don't know how to do this however. Myself, I follow a similar scheme but using a linux virtual guest and host. Is it easy to disable networking for all networking except for apt/yum and vmware/kvm? Lastly, does anyone know what it costs for a personal subscription to grsecurity?
- boardwaalk 9y agoMy first thought would be to clear the routing table on Windows (maybe using a batch script on startup?) and using bridged networking in the VM. That would totally disable internet access on Windows though, including updates (but you also wouldn't have that attack surface!)
- cryogenspirit 9y agoThanks. Had a brief look, seems useful. Does the VM using the "nat" mode of networking also use Windows routing table? I don't know much about the networking between guest and host, except that the guest uses NetworkManager through its ethernet device. Even though this is a virtual device, I didn't think it would go through Windows' own net stack. Would the bridged networking be any different than passing through the USB wifi adapter directly to VMware? (at which point the host doesn't have access to internet)
- boardwaalk 9y agoAs far as I understand it, with bridged networking you're basically sharing the network device -- your VM has it's own stack down to the MAC address. So as long as your network device is still online (in the sense of being enabled in Windows and having a cable attached), packets for a particular MAC will travel to the right network stack. This is probably useful from the VirtualBox manual: > With bridged networking, VirtualBox uses a device driver on your host system that filters data from your physical network adapter. This driver is therefore called a "net filter" driver. This allows VirtualBox to intercept data from the physical network and inject data into it, effectively creating a new network interface in software... I'd try it, it wouldn't be hard to reverse.
- print_r 9y agoWhile I can understand WikiLeaks position, I feel like it was incredibly short sighted and uninformed of them to release the code itself. Unless you believe that they are working with the Russian (and other?) governments to destabilize the west. Personally, I wouldn't be surprised if this was the case.
- H4CK3RM4N 9y agoMy impression was hat the Shadow Brokers already had, or were about to release the tools which Wikileaks ended up leaking. Regardless, these should've been disclosed to the manufacturers under Obama's policies.
- print_r 9y agoI would be curious as to the agenda of these "Shadow Brokers" it all sounds very Gibsonesque. Recent events have made Neuromancer seem more and more prophetic to me.
- H4CK3RM4N 9y agoThey were hackers who acquired a trove of state secrets and were looking to make a quick buck. I've linked an archive of their initial statement below. I think it speaks volumes about how far the NSA can be trusted that these people were the ones to leak the tools instead of a state actor or someone previously known. https://web.archive.org/web/20160815124425/https://github.com/theshadowbrokers/EQGRP-AUCTION https://web.archive.org/web/20160815124425/https://github.co...
- print_r 9y agothat's pretty heavy. life imitating art for sure. thanks
- placeybordeaux 9y agoGoing through their wallets it looks like they've gotten 32 pay outs, some for more than 300 USD. Are there any addresses that they are using outside of the four listed int he article? It'd be an interesting project to try and track where these funds go and where they came from. https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 https://blockchain.info/address/13AM4VW2dhxYgXeQepoHkHSQuy6N... - 11 https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX... - 4 https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw https://blockchain.info/address/12t9YDPgwueZ9NyMgw519p7AA8is... - 6 https://blockchain.info/address/1QAc9S5EmycqjzzWDc1yiWzr9jJLC8sLiY https://blockchain.info/address/1QAc9S5EmycqjzzWDc1yiWzr9jJL... - 11
- doomrobo 9y agoThey'll probably be tumbled (i.e Bitcoin laundering), meaning that we'll get no info from the transactions at all.
- placeybordeaux 9y agoI haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?
- billharrison 9y agoI can't speak for a current safe limit, but it isn't very hard to transfer funds between various cryptocurrencies. Tumbling is not secure with a large amount of coins. All you have to do is monitor all transactions and figure out what went in and what came back out. If you start splitting things off in small amounts on various blockchains things become much harder to track. This is assuming the attackers know what they are doing. I would be against that.
- doomrobo 9y agoA cursory check doesn't bring up any Helix (the largest tumbler out there) stats. I'm not certain they even make that info public. Also I wouldn't know how to measure the level of privacy in this context.
- gildas 9y agoQ: could fuzzing techniques help to take down such (p2p) botnets?
- arca_vorago 9y agoFirst of all, while I of all people love to pile onto the anti-NSA bandwagon (within constitutional reason that is, I don't advocate their abolishment, but that's a different conversation), there are quite a few non-three-letter related things that have contributed to this story and ones like it. The primary issue at the heart of things like this, beyond the backdoors and 0-days is this: bad IT. That being said though, bad IT is far too often the fault of upper management, and not the IT people themselves. After years of sysadmining, I've seen the inside of hundreds of companies, from fortune 500 oil to medium sized law firms. You know what they have all been doing over the years? Cutting costs by cutting IT. Exept... they completely fail to consider long term consequences, which end up costing more. I blame things like this on two main groups. Boards of directors, and company executives. Far too often I ran into a situation where a company didn't even have a CIO or a CTO, and you had some senior one man miracle show drowning in technical debt reporting to a CEO or CFO and getting nowhere, and therefore getting no support, no budget, no personell, etc. I've seen exceptions too, but they are far too rare. If it's not technical debt that's drowning the company, it tends to be politics. The bottom line is forward thinking IT personell don't get heard, and inevitably companies hire people or an MSP with all the proprietary, cisco, microsoft, oracle, etc bullshit certs that make the C's feel better, but don't actually produce the wanted results. They inevitably end up providing an inferior product with inferior service at a short term cost just as high as doing it right the first time, and a much higher long term cost. If I could say one thing that could help prevent issues like this, besides my standard whinging on about FOSS and the four freedoms and such, is that we need better CTO's and CIO's to advocate on behalf of IT departments, and I think senior sysadmins who feel they have hit a ceiling should consider going for their MBA's and transitioning to those titles. Now, onto the NSA angle of the story. Well... all I can say is I told ya so, with an extra note that HN in the past few years has been surprisingly dismissive of FOSS proponents who have been warning about these things. First they made fun of us for saying everything was being spied on, and then Snowden happened. (often followed by bullshit like "are you suprised?" or "what do you have to hide?" Then we warned about proprietary systems, and then NSA/CIA tool leaks happened. (often followed by things like "but its for foreign collection only" and "but the NSA contributes to SElinux") Ya'll aren't listening until after the fact, and that's not going to fix anything.
- 9y ago
- mschuster91 9y agoApparently, this has spread to Deutsche Bahn... 1) a railway dispatcher just tweeted that IT systems will be shut down (https://twitter.com/lokfuehrer_tim/status/863139642488614912 https://twitter.com/lokfuehrer_tim/status/863139642488614912) 2) a journalist tweeted that an information display of DB fell victim to ransomware (https://twitter.com/Nick_Lange_/status/863132237822394369 https://twitter.com/Nick_Lange_/status/863132237822394369). I guess that #1 and #2 are related, though.
- mtgx 9y agoIs Russia being hit the most because it was the NSA the one that was exploiting this vulnerability before? Perhaps they are leveraging some other leaked NSA tool that gives them more direct access to Russian computers?
- Irreal 9y agoIs it possible to cause havoc on banks worldwide?
- deleted 9y ago[deleted]
- anigbrowl 9y agoI'm surprised by the lack of speculation on the identity of the perpetrators.
- mdkdog 9y agoIt looks to me like common stupidity...people opening attachments that they should not be opening. No need to involve CIA NSA or other tree letters agency hacking tool...just old school phishing. I see this happening much to often....people opening *.pdf.js attachment. No need for another conspiracy theory...stupidity explains it all. Just my 50¢.
- robertfw 9y agoIt looks like you have not done any "looking" at this at all. This is a worm that is using the ETERNALBLUE (and possibly other) exploits to infect all vulnerable machines on a network without user interaction plenty of stupidity for sure, but the stupidity is at the number of unpatched systems
- mdkdog 9y agoMy bad...the article is not really clear thou... My first comment...and my first fail... /me sad!
- hoschicz 9y agoIt doesnt involve only pdf.js file, the key is a bug in samba that means that all you need to get infected is to connect to an infected network.
- toyg 9y agoNot in Samba, in the SMB protocol implementation on Windows. Samba servers are safe.
- blackflame7000 9y agoI was debugging a private web app today when I noticed a python script agent suddenly performing a port scan on me. it was querying for something called "a2billing/common/javascript/misc.js". After googling that phrase it seems im not the only person who has seen this today. The country of origin of the IP was Britain. After Further investigation, it appears this attack could be in relation to this http://www.cvedetails.com/cve/CVE-2015-1875/ http://www.cvedetails.com/cve/CVE-2015-1875/
- itissid 9y agoDoes any one have a running list of the organizations effected so far?
- drinchev 9y agoSo If I pay how does the hackers decrypt my HD? Is there a way to sniff the key and pay once - decrypt everywhere?
- PeterisP 9y agoYou send them the code (encrypted key?) from your machine, they send you back the key that works for your machine. If you have multiple computers (as these large organizations do), you need to pay for each one separately; the key for one won't work for the other. Perhaps they offer volume discounts?
- incompatible 9y agoSend it how, do they provide an email address and helpfully send it back by return mail? A tor hidden service maybe? I'd have assumed they just take the money without bothering to decrypt anything, but maybe they are looking for repeat customers.
- detaro 9y agoOnce it's reported that paying for (your specific one, or even just some) ransomware doesn't give users files back, you loose a lot of money. Ransom only works if it's believable you have something to ransom.
- PeterisP 9y agoDepends on the particular malware, but generally it will direct you to a (tor) website explaining the details, often with newbie-friendly guides on how to set up the accounts needed to buy and transfer bitcoin. They generally do offer a way to decrypt, it's a long term business for them, not a one-time prank; and the results matter - first, the "audience" who are willing and able to pay generally have multiple devices, and they won't pay for the dozen other devices if the first "trial" device isn't successfully decrypted, and second, the infection spreads over victim's contacts - so your buddy who also got the malware managed to decrypt, you're more likely to pay, and if your buddy paid and failed to decrypt, the crooks won't get a dime from you. There are all kinds of options. For example, one piece of malware offered to decrypt two files of your choosing for free when you contacted them, just to show that they can do so, as a 'teaser' before paying the full amount. Besides, why wouldn't they decrypt? It's not like it costs them anything or takes much effort; if they have the ability but wouldn't send the keys, then that's just hurting their business "PR/advertising" for no reason whatsoever.
- Myrmornis 9y agoThere's no evidence that this attack targeted the NHS or other health systems, right? Just spreading randomly by email, highest infection probabilities certain older Microsoft OSs?
- toyg 9y agoYeah it looks like "large public institutions" were affected simply because that's where you'll find more unpatched (or unpatchable, in the case of XP) machines.
- billharrison 9y agoThis definitely wasn't targeted. Check here - https://intel.malwaretech.com/botnet/wcrypt/?t=24h&bid=all https://intel.malwaretech.com/botnet/wcrypt/?t=24h&bid=all
- f2f 9y agoCisco's TALOS team just published an analysis: http://blog.talosintelligence.com/2017/05/wannacry.html http://blog.talosintelligence.com/2017/05/wannacry.html
- gazos 9y agoIm hearing the password wncry@20l7 decrypts the zip within the PE resources. anyone confirm?
- kabes 9y agohttps://twitter.com/0xSpamTech/status/863224147576594432 https://twitter.com/0xSpamTech/status/863224147576594432 Believe what you want of it of course.
- gazos 9y agoIm hearing the password wncry@20l7 decrypts the zip within the PE resources. anyone confirm?
- ncomputersorg 9y agoThe singularity could be the result of a cyberwar: https://ncomputers.org/singularity https://ncomputers.org/singularity
- nthcolumn 9y agoShadowbrokers claiming blame: https://twitter.com/0xSpamTech https://twitter.com/0xSpamTech Analysis here: http://blog.talosintelligence.com/2017/05/wannacry.html http://blog.talosintelligence.com/2017/05/wannacry.html
- djanklow 9y agoWhy don't telecom providers help remove devices who are requesting an exorbitant amount of requests? Wouldn't this kill bot nets, if the exponential growth effect became impossible?
- remarkEon 9y agoIf I want a deep technical analysis of what we know so far, where do I go?
- deleted 9y ago[deleted]
- microcolonel 9y ago> The attacks were reminiscent of the hack that took down dozens of websites last October, including Twitter, Spotify and PayPal, via devices connected to the internet, including printers and baby monitors. Lazy writing at NYTimes; what on earth does this attack have to do with the one at hand? It's not broadly the same type of attack, nor the same scale, nor the same outcome.
- CCing 9y agoIs OSX affected ?
- Retr0spectrum 9y agoFor the record, no.
- runesoerensen 9y agoDHS Statement on Ongoing Ransomware Attacks: https://www.dhs.gov/news/2017/05/12/dhs-statement-ongoing-ransomware-attacks https://www.dhs.gov/news/2017/05/12/dhs-statement-ongoing-ra...
- reviewmon 9y agoAnticiaption for an attack tied to an all time high bitcoin?
- sasas 9y agoHere is a link to the malware sample and technical implementation details. https://gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168 https://gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b...
- sasas 9y agoMalware tech need recongnition! By being the first to register the hard coded domain in the malware they have slowed the spread significantly ... https://twitter.com/josephfcox/status/863171107217563648 https://twitter.com/josephfcox/status/863171107217563648
- WheelsAtLarge 9y agoWow, the future is here and it's not looking very good. We need to diversify our OS's in the enterprise. This time it was MSFT next it could be linux. No OS gives an absolute guarantee. The systems are relatively dumb now what will happen when AI has gotten deeper into our everyday lives. This is a wake up call.
- rdiddly 9y ago"Emergency rooms were forced to divert people seeking urgent care." I feel like the words "urgent" and "forced" might both be a bit shy of absolutely true here?
- Myrmornis 9y ago> Security experts described the attacks as the digital equivalent of a perfect storm. Just in case there are any journalists reading - never use the term "perfect storm".
- rileytg 9y agois this supporting evidence of the us doing something "wrong" by creating these tools? disclaimer: i hope no b/c it's like any other military tech being leaked and used, but am not sold either way.
- marcrosoft 9y agoIf anyone reading this was effected by this attack, please take this as an opportunity to start the journey to become "antifragile". If you are severely effected by this (mainly speaking about ransomeware) it means you lack backups and the ability to self-heal infrastructure. These attacks will only get more frequent and more sophisticated. So, start now.
- JohnTHaller 9y agoMedical offices are notorious for having machines out of date, not properly secured, and not backed up. Just recently I wanted to get test results from a few years earlier from a previous doctor. Nope, the machine they were on runs a proprietary GE setup and it crashed. The same test a few years earlier? The hospital lost them and had no record of them being done. A different test I had done a month ago was hooked up to an aging Windows XP machine. Yes, it was networked, though I'm unsure if it was intranet only (I doubt it). In the US, you have to manage your own healthcare. Get every result as a hard copy or on disk (in the case of MRI etc) and save it yourself. And back it up. That way you're prepared.
- rorykoehler 9y agoI recently went to a consultancy sales meeting with a GP who wanted me to port the MS Dos Patient Record Management system used by his medical centre to the cloud. While I'm sure with a suitable budget it could have been figured out the fact that I could only find a handful of references to the database file format when searching google didn't bode well. It looked like I would have to reverse engineer the parsing and interpretation of the bytecode. In the end my advice was to hire data entry professionals to do it manually.
- JohnTHaller 9y agoYou likely preserved your own sanity and theirs.
- swetabhsuman8 9y agoMASSIVE RANSOMWARE ATTACK HITS 74 COUNTRIES http://hackernucleus.com/eternalblue-hacker-news-massive-ransomware-attack-hits-74-countries/ http://hackernucleus.com/eternalblue-hacker-news-massive-ran...
- joshmn 9y agoHi there! Welcome to HN! Be sure to check out the community guidelines to ensure you and your brand are well-represented on HackerNews. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- rorykoehler 9y agoThe entertainment system on my flight is mysteriously down. I wonder if it's connected. As a side thought does anyone know the vulnerability of critical systems such as airliners, air traffic control etc?
- mgalka 9y agoWhat exactly does this NSA tool do? Every story I've seen glosses over how it works.
- jgaa 9y agoIt seems this one was designed to shut down hospitals ;)
- erikbye 9y agoThe tools in reference are from the Equation Group dump the Shadow Brokers did. Equation Group is believed to be the NSA (a group within). EG activity dates back to at least 1996. More info on EG: https://securelist.com/files/2015/02/Equation_group_questions_and_answers.pdf https://securelist.com/files/2015/02/Equation_group_question... The dump contains many tools; but the ones used in this attack are two exploits for vulnerabilities in Windows SMB (Server Message Block, a file sharing protocol) implementation. Microsoft patched this in March, but as we all know, many systems remain unpatched. The vulnerabilities allowed for remote code execution. Practical exploit info: https://www.exploit-db.com/docs/41896.pdf https://www.exploit-db.com/docs/41896.pdf The two exploits, EternalBlue and EternalChampion targets respectively SMBv2 and SMBv1. That's not how the ransomware gets inside the network in the first place though, that is done by a user executing a file received via email, or downloaded from a received URL. But, through these two exploits, once inside, it can spread through the network (subnet) worm-like. Actually, the ransomware first checks for the existence of the backdoor (also from the same dump of tools) called DoublePulsar. If the ransomware does not find it to be implanted, it will use one of the two aforementioned exploits, based on which ports and protocols it makes a connection to. The DoublePulsar backdoor is installed on at least 400,000+ systems worldwide. You can read more about it here: https://countercept.com/our-thinking/analyzing-the-doublepulsar-kernel-dll-injection-technique/ https://countercept.com/our-thinking/analyzing-the-doublepul...
- jgaa 9y agoIf NSA made it, and failed to protect it - then NSA should be liable for law suits to pay for damages.
- lmz 9y agoShould that apply only to NSA or also to the writers of e.g. Metasploit exploits?
- jgaa 9y agoNSA made a weapon with the purpose of harming someone. In court, intent matters.
- thoth 9y agoSo: A makes a product with flaws, B makes an exploit, C leaks that exploit, D adds a harmful payload to the exploit and goes on to extort/profit from E, who has computers systems they failed to patch in time... and somehow B and only B is at fault?
- nomercy400 9y agoFTFY: and somehow D and only D is at fault? You'll see that they'll get the blame and the rest goes free.
- Kali909 9y agoSo does being able to enforce it. No one is going to sue the US DoD and come out winning.
- mirimir 9y agoWell, gun manufacturers have been sued in the US. Now they're protected by the Protection of Lawful Commerce in Arms Act. But NSA is part of US DOD. So the chances of a successful claim are about zero.
- blitmap 9y agoThe real world doesn't update in 2 months. (I wish it did.) The NSA should have responsibly disclosed the vulnerabilities they had been sitting on as soon as they were discovered. That protects national security - not this.
- hollander 9y agoI wonder if any NSA computer or employee is affected by this. The best thing would be if the family of the directors and management would be affected. Just to show how stupid and irresponsible they act.
- whatupmd 9y agoWikileaks should have disclosed before dumping publicly. Burning down the house to prove that there are fire safety issues is the wrong approach.
- wu-ikkyu 9y agoLikewise not calling the fire department when you know all of our houses are likely to be burnt down in the hopes that some "bad guys" might get burnt is also the wrong approach.
- boomboomsubban 9y agoThis has nothing to do with Wikileaks, who have tried not to release any unpatched vulnerabilities in the Vault 7 documents and have been ignored by many companies they have approached offering to disclose vulnerabilities. At least double check you've got the right person before labeling them an arsonist.
- kneel 9y agoWikileaks did not disclose these exploits https://motherboard.vice.com/en_us/article/shadow-brokers-dump-alleged-windows-exploits-and-nsa-presentations-on-targeting-banks https://motherboard.vice.com/en_us/article/shadow-brokers-du...
- blitmap 9y agoI sort of wonder if Microsoft could create a mode for Windows where if it detects a security update available, it MUST update. I have spent a lot of the time trying to get Windows to just fucking STOP, but there are environments where security-before-use would seem ideal.
- EmlynC 9y agoWhat gets me is why we don't see more viruses that _deliver_ the patch to fix the vulnerability. It's perhaps a little more difficult as you'd need a vulnerability to keep spreading the innoculation. Arguably, though you release the virus, let it spread and then trigger the innoculation using a mechanism like calling out to a webserver, just as the kill switch worked here.
- marksomnian 9y agoThat's an interesting idea: release a virus to cite a virus. Reminds me of the game Uplink, where [spoiler alert] you choose to either help spread a virus to destroy the Internet, or help spread a "counter-virus", hacking large servers to cure them before they're overrun. Digital vigilantism, that's what that is.
- EmlynC 9y ago"Digital vigilantism" that's exactly it.
- adrianN 9y agoYou run the risk of jail time without the upside of ransom payments.
- EmlynC 9y agoTrue, plus, I forget the legislation but you are effectively breaking into the computer first which is a crime. Committing a crime for a noble outcome is still a crime. Incentives is a real issue here and those that provide the patch would, reasonably, expect a reward i.e. MS for updates, AV provider for testing, finding and securing the vulnerability and a whitehat for disclosure. However, there is no reason why a "charitable" hacking group wouldn't do this as part of some sort of digital vigilantism. Sometimes people do things without extrinsic reward and the thrill here is that it is as hard as cracking, but you get to know that your efforts could be immediately applied.
- hd4 9y agoWe Linux people really should not miss this opportunity to bring people on board. Ubuntu is a great starting point.
- lngnmn 9y agoJust for reminder - the second leak does not match the vault7 leak, which is supposed to be from the very same NSA. There is not a single proof or reason to believe that the second leak was not a fake (while the vault7 leak looks more legit) . There are reasons to think that the same people are behind the second leak and the malware, and the malware, which is said to be based on "a leaked NSA exploit", was the part of a single plan. It is not that hard to guess who is behind the internet bullying.
- Kali909 9y agoThere's the bitcoin ransom aspect, but presumably a worm like this could extract a massive amount of data from infected servers and send that back to someone/somewhere? Bank transactions, patient medical data, stored passwords/keys/CA info, contacts, emails, configuration files, registry dumps for firewall rules etc etc. (I'm not that creative so there's probably a lot more that's been exfiltrated). Pretty hellish knowing they'd let that quietly sit there, in the name of espionage. I'm not sure the benefits outweigh the damage they're doing, without even mentioning the chilling effect and lack of confidence this instills in IT everywhere.
- wu-ikkyu 9y agoRight, the real money is not going to come from the bitcoin ransoms, but from the information on millions of patients which they surely made copies of.
- pja 9y agoI see the Rust Evangelism Strike Force are out in action again. Guys, it may surprise you, but some of this kit predates Rust :)
- kibwen 9y agoEr, aside from yours, there are literally two comments in this 444-comment thread that have mentioned Rust, both of them written by a single person. Given that both those comments also mention sel4, perhaps we ought to invoke the sel4 Evangelism Strike Force? :P
- kabes 9y agoI hope the NSA can be hold accountable for this and we can finally all agree that a government holding on to 0-days and asking for loophole encryption always bites back to the very people they claim to protect.
- agent3bood 9y agoThe article could have been writen in 15 lines or less. Why u do this
- turblety 9y agoJust to let you know in the UK we'll all be safe from things like this. The UK's banning encryption so stuff like this won't happen in the future. Phew. I feel safer!
- a3n 9y agoI think tools like this should be secured at least as well as "research" stores of smallpox and other biotoxins. And certainly tracked long after they've outlived their usefulness within the agency that produced them. Or maybe smallpox isn't actually stored as securely as I assume?