3 ms·
I think it's different for good now. Detection is better, response is better. The exploits used in blackhole would be patched really quickly, and detected reall
by SCHiM 5y ago
I think it's different for good now. Detection is better, response is better. The exploits used in blackhole would be patched really quickly, and detected really quickly.
I think it would be detected quickly because the most likely payload dropped would be ransomware. which makes it immediately obvious to users they got owned. I don't think it would take longer than a day to discover a zero day exists in $BROWSER once a group starts a campaign using it.
All software distributors that expose attack surface to a large consumer base have all had plenty of time to learn how to deal with a major security hole that needs to be patched asap. Once a researcher tweets about a 0day in $BROWSER, there'll be an incomplete patch 1 day later. 4 days later the final patch is out. Auto updates ensure every user has the patch the moment they go online.
But I do think we can still see a CCG using a browser exploit to infect people, but I don't think we'd see exploits packaged and sold inside exploit kits.
- staticassertion 5y agoThere are definitely significant economic changes - the turnaround time for discovery, patch, rollout is way tighter. I suppose that could make a generalized kit much harder to sell. Once it's sold once you basically have to assume it'll be burned soon. Time will tell.
- rosndo 5y agoOnly way we’re going to see another exploit pack like blackhole is if it’s targeting Android devices which aren’t receiving security updates.
- staticassertion 5y agoOr there's more vertical integration in exploit packs ie: they pair it with some sort of post exploitation payload that's better at hiding. Or something else we haven't thought of.