7 ms·
Cisco's Talos team analysis of WannaCry worm
- mctx 9y agoUnreadable on Chrome on iOS https://i.imgur.com/j13tqGn.png https://i.imgur.com/j13tqGn.png
- kyrra 9y agoSeems they fixed it. (Did a refresh and alls good now)
- neom 9y ago"it is simply scanning accessible servers for the presence of the DOUBLEPULSAR backdoor. In cases where it identifies a host that has been implanted with this backdoor, it simply leverages the existing backdoor functionality available and uses it to infect the system with WannaCry." - Not a security person but that seems pretty clever, and incredibly worrying. I presume we'll see more of this type of attack in the future - but curious if this has been a popular vector of compromising in the past? Also curious about what a / how a killswitch domain works?
- syoc 9y agoIt is quite clever. Computer worms were much more common in the past. https://en.wikipedia.org/wiki/Computer_worm https://en.wikipedia.org/wiki/Computer_worm The lack of highly available and remotely exploitable vulnerabilities have made them less common.
- Mtinie 9y agoOr, "less commonly discussed". Why would worms be less prevalent today when the density of targets has increased one-hundred fold? Many systems may be inoculated but there are lots and lots of non-patched machines in the World.
- problems 9y agoIn large part they are less common because of NAT's popularity. Back in 2003, most people were on dialup or had a single machine plugged directly into the Internet. Microsoft had no firewall out of the box. So by default you exposed all your Microsoft networking services to the whole Internet. NAT changed that, it made it so no one could directly connect to all the vulnerable machines floating around. Your phone is unable to infect other phones on your providers network or the wider internet in this same way. No one is out mass exploiting those IOT light bulbs with default telnet passwords because they're not exposed directly to the Internet. There are a few however exploiting vulnerable NAT routers... probably the only sort of worm to see widespread success in recent years.
- ptrincr 9y agoExactly this. MSBlast was so prevalent that ISP's would prevent infected computers from accessing the internet, by redirecting them to a page which described how they could remove the infection and patch themselves up. I don't remember that happening with any other type of infection.
- problems 9y agoAnd I don't think we'll ever see that again. Even if there are big vulnerabilities in Linksys, DLink, Netgear or common ISP shipped modem/router combos - there are just too many different devices to see it on the same scale.
- Mtinie 9y agoThank you for the explanation!
- justinsaccount 9y agoYou stopped before the next sentence which completely changes the context: > In cases where the system has not been previously compromised and implanted with DOUBLEPULSAR, the malware will use ETERNALBLUE for the initial exploitation of the SMB vulnerability. This is the cause of the worm-like activity that has been widely observed across the internet. This is not really any different from Blaster from 2003.
- nikanj 9y agoWas Blaster using a hole that had been patched months ago?
- throwaway91111 9y agoMonths? No. Weeks? Yes.
- justinsaccount 9y agoAbout a month, yes In that case, it was supposedly because of the patch: > According to court papers, the original Blaster was created after security researchers from the Chinese group Xfocus reverse engineered the original Microsoft patch that allowed for execution of the attack The patch was ms03-026: Buffer Overrun In RPC Interface Could Allow Code Execution Published: July 16, 2003 (could, hah) > The worm was first noticed and started spreading on August 11, 2003 It was a huge problem at college campuses well into September. Students would arrive with their brand new laptops running XP and get hit with the worm 30 seconds after connecting to the network. Really the main difference is blaster was just an annoyance and mostly just broke random things like the DHCP service, but was easily fixed.
- deleted 9y ago[deleted]
- rwbhn 9y ago> Also curious about what a / how a killswitch domain works? From the article: The above subroutine attempts an HTTP GET to this domain, and if it fails, continues to carry out the infection. However if it succeeds, the subroutine exits. The domain is registered to a well known sinkhole, effectively causing this sample to terminate its malicious activity.
- averagewall 9y agoApart from the invididual victims, ransomware seems like it should have a good effect on computer security overall since it actually harms the people who get infected and motivates them to do security better. Most viruses keep quiet so people don't know or care if they're infected and contributing to DDOSs or spreading to others. I sometimes use computers that have obvious viruses on them, and it the people running them just let it happen because it doesn't stop their work.
- voltagex_ 9y agoIt seems like very few viruses are "obvious" these days - aside from ransomware. How do you know what you're doing on these computers isn't affected or compromised in that case?
- averagewall 9y agoUsually just printing. I find the viruses on my USB drive after printing from it on other people's computers. I keep that drive for one-way use and never get files back off it because they're all potentially infected.
- qb45 9y agoNote that that the pendrive itself is potentially "infected" too, sometimes there are OS and file manager bugs resulting in code execution without the user clicking anything.
- averagewall 9y agoThose bugs would be zero-days and patched before viruses using them are widespread.
- DanBC 9y agoYou put files onto the stick. You put the stick in someone else's machine and print the files. The stick might be infected after this use. You don't put the stick back in your machine, because it might be infected. Do you continue to put it in other people's machines to keep printing?
- maksimum 9y ago> .der, .pfx, .key, .crt, .csr, .p12, .pem, .odt, .sxw, .stw, .3ds, .max, .3dm, .ods, .sxc, .stc, .dif, .slk, .wb2, .odp, .sxd, .std, .sxm, .sqlite3, .sqlitedb, .sql, .accdb, .mdb, .dbf, .odb, .mdf, .ldf, .cpp, .pas, .asm, .cmd, .bat, .vbs, .sch, .jsp, .php, .asp, .java, .jar, .class, .mp3, .wav, .swf, .fla, .wmv, .mpg, .vob, .mpeg, .asf, .avi, .mov, .mp4, .mkv, .flv, .wma, .mid, .m3u, .m4u, .svg, .psd, .tiff, .tif, .raw, .gif, .png, .bmp, .jpg, .jpeg, .iso, .backup, .zip, .rar, .tgz, .tar, .bak, .ARC, .vmdk, .vdi, .sldm, .sldx, .sti, .sxi, .dwg, .pdf, .wk1, .wks, .rtf, .csv, .txt, .msg, .pst, .ppsx, .ppsm, .pps, .pot, .pptm, .pptx, .ppt, .xltm, .xltx, .xlc, .xlm, .xlt, .xlw, .xlsb, .xlsm, .xlsx, .xls, .dotm, .dot, .docm, .docx, .doc Phewww! Good thing I'm using .tex to write my thesis and write most of my code in .py... lol
- vecplane 9y agoIs there a domain we can connect to with https? Seems strange that an article as important as this wouldn't be served securely.
- cheeze 9y agoI've seen a few mentions of something along the lines of "The malware then checks for files with a file extension as listed in the appendix and encrypts these using 2048-bit RSA encryption." I'm not super well versed in crypto, but is this possible? I assume they use symmetric encryption and then RSA encrypt the symmetric keys?
- Dolores12 9y agoThere are some bitcoins flowing in into their wallet https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX...