4 ms·
Waiting for victims to run your malware is not an active process. It requires no resources on the attacker's part beyond maintaining a server. Maybe it will co
by sp0rk 5y ago
Waiting for victims to run your malware is not an active process. It requires no resources on the attacker's part beyond maintaining a server.
Maybe it will connect to a server that has been dead for five years or maybe it's pointing towards a domain name that the attacker still maintains. Maybe instead of a trojan, it's a cryptolocker or old school destructive malware. I don't know why anybody would want to gamble with something like this.
Also, some of the exploits are one-size-fits-all because they target the underlying libraries that the software is using.
- tomc1985 5y agoYes but the mechanics of exploit crafting aren't generic at the slightest. Everything is bespoke. Which means that for the random bystander the probability that your specific-combination-of-old-software-and-data being exploited is extremely low. If you've reason to be paranoid, sure. And if you're trolling old warez archives with software contemporary to the time, sure. But otherwise? The odds are too low and the possibility space too high for anyone to bother
- romwell 5y ago>Waiting for victims to run your malware is not an active process. Except that's not what we are talking about. The old piece of software here is known to not be malware. >I don't know why anybody would want to gamble with something like this. Everything you do in life is a gamble. Everything is a risk. And the risk of opening an external file in a common format that just happens to have a carefully crafted exploit for extremely uncommon, outdated software that you happen to use to open it is so, so, low, that the risk of the computer exploding in your face on power-up becomes significant compared to that. Yet people aren't deterred from booting up their machines just because there was this laptop one time that did explode.