3 ms·
Wannacry had a really obvious and weird kill-switch ( presumably to limit damage ) an un-registered domain[1]. Marcus Hutchins a British security researcher re
by deepnet 9y ago
Wannacry had a really obvious and weird kill-switch ( presumably to limit damage ) an un-registered domain[1].
Marcus Hutchins a British security researcher registered this domain.
As the domain offswitch ping was obvious Hutchins was seemingly the only competent researcher who read the source code.
Hutchins, Britain's Saviour of the NHS[2] (Britain's National Health Service) was outed by the British tabloid press that published his home address.
Next Marcus Hutchins was arrested while attending DefCon and is currently awaiting trial in the US on unrelated charges. [3]
Wannacry had spread throughout the NHS and was preventing actual life saving operations, it spread on some Microsoft XP and mostly unpatched 7 systems, from the audit:
"NHS Digital told us that all organisations infected by WannaCry shared
the same vulnerability and could have taken relatively simple action to protect
themselves
.
... NHS Digital told us that the majority of NHS devices infected were
unpatched but on supported Microsoft Windows 7 operating systems. Unsupported
devices (those on XP) were in the minority of identified issues. NHS Digital has also
confirmed that the ransomware spread via the internet, including through the N3
network (the broadband network connecting all NHS sites in England),"[4] NHS Digital Audit
[1] https://whoapi.com/blog/3079/what-is-the-domain-name-that-stopped-wannacry/ https://whoapi.com/blog/3079/what-is-the-domain-name-that-st...
[2] http://www.independent.co.uk/news/uk/home-news/nhs-cyber-attack-hack-marcus-hutchins-hero-accidental-wannacry-north-korea-a7738231.html http://www.independent.co.uk/news/uk/home-news/nhs-cyber-att...
[3] http://www.independent.co.uk/news/uk/home-news/marcus-hutchins-arrested-latest-us-authorities-wannacry-cyberattack-nhs-las-cegas-mccaran-a7875761.html http://www.independent.co.uk/news/uk/home-news/marcus-hutchi...
[3] https://www.nao.org.uk/wp-content/uploads/2017/10/Investigation-WannaCry-cyber-attack-and-the-NHS.pdf https://www.nao.org.uk/wp-content/uploads/2017/10/Investigat...
From a comedic dystopian science fiction perspective this coincides the politics of underfunding the NHS, institutional costs of running Microsoft's patches on vital life-saving equipment, the US intelligence services offensive rather than defensive playbook, and an "unlikely" hero.
Might make a great novel except if ludicrously we are about to live it as a pretext.
- Crosseye_Jack 9y ago> As the domain offswitch ping was obvious Hutchins was seemingly the only competent researcher who read the source code. If iirc it was an accidental discovery of the kill switch. He noticed the pings to the domain, noticed it was un-reg’ed, thought “hmmm if I reg this domain I will be able to see how many other infections and their location when they ping home”. So reg’ed the domain. It was then when he noticed the code would quit out if the domain was in use.