3 ms·
More generally, is there a known correlation between kernel panics and exploits, especially on macOS? > Almisshal’s device shows what appears to be an unusual
by aarchi 6y ago
More generally, is there a known correlation between kernel panics and exploits, especially on macOS?
> Almisshal’s device shows what appears to be an unusual number of kernel panics (phone crashes) between January and July 2020. While some of the panics may be benign, they may also indicate earlier attempts to exploit vulnerabilities against his device.
- saagarjha 6y agoNot necessarily. But panics could be an indicator of failed exploits.
- AnHonestComment 6y agoFailing exploits tend to cause kernels to panic.
- alternatetwo 6y agoI doubt it's macOS only, if you remember EternalBlue, that was called that way because it kept bluescreening on machines the NSA tested it on ...
- _kbh_ 6y agoDo you have a source on the blue screening?. Usually code names are random but can be less random within a group of exploits/projects (such as eternalblue, eternalromance, eternalsyngery, eternalchampion)
- FreshFries 6y agoNot OP, but just google Windows7 & eternalblue EDIT: I realise now that does not answer your question. Apologies.
- _kbh_ 6y agoI've blue screened plenty of computers with eternalblue in the past. I am just not convinced its where the name comes from, I feel like its just a happy accident.
- ryanmcdonough 6y agoThe name came from a previous exploit called BlueKeep, which wasn't related to BSOD. In fact: "On 6 September 2019, an exploit of the wormable BlueKeep security vulnerability was announced to have been released into the public realm.[4] The initial version of this exploit was, however, unreliable, being known to cause "blue screen of death" (BSOD) errors. A fix was later announced, removing the cause of the BSOD error." They even fixed a BSOD issue that popped up in BlueKeep as that was no good to them.
- _kbh_ 6y agoEternalBlue is probably ancient and additionally was leaked to the public 2 years prior to BlueKeep.
- Plutoberth 6y agoFailed exploits, especially kernel-level ones, will result in higher system instability. I'm aware of at least one company (ZecOps) that specializes in detecting exploitations using crash analysis.