3 ms·
Wannacry used the exploit from EternalBlue to create one of the most famous ransomware worms in recent memory, and wasn't the only malware to leverage that one
by muricula 4y ago
Wannacry used the exploit from EternalBlue to create one of the most famous ransomware worms in recent memory, and wasn't the only malware to leverage that one exploit:
https://arstechnica.com/information-technology/2019/05/eternally-blue-baltimore-city-leaders-blame-nsa-for-ransomware-attack/ https://arstechnica.com/information-technology/2019/05/etern...
https://en.wikipedia.org/wiki/WannaCry_ransomware_attack https://en.wikipedia.org/wiki/WannaCry_ransomware_attack
Despite lots and lots of POCs, I haven't seen attackers use spectre in the wild yet. Maybe sophisticated actors are using it but they haven't been caught yet, or more likely they just use more traditional and reliable ways to get info leaks. But if traditional info leaks dwindle, they may turn to speculative execution attacks.
- blaser-waffle 4y agoThe level of access required to make Spectre work, basically shoehorning microcode into the CPU, means that you'd already have some deep hooks in the box anyway. Easier to use other methods at that point.
- muricula 4y agoSpectre does not require changing the CPU's microcode. You just need to be able to run native code or even javascript. https://security.googleblog.com/2021/03/a-spectre-proof-of-concept-for-spectre.html https://security.googleblog.com/2021/03/a-spectre-proof-of-c... https://leaky.page/ https://leaky.page/