6 ms·
Anti-virus software is utterly worthless in detecting previously-unknown rootkits. Not a factor. The typical attack vector for any system would be compromising
by throwaway09223 3y ago
Anti-virus software is utterly worthless in detecting previously-unknown rootkits. Not a factor.
The typical attack vector for any system would be compromising the inbound software. This is really easy to do when people are downloading and installing random programs from websites. This used to be less common, but popular cutting edge tools have popularized it recently "distro packaging is too slow, etc, curl|bash to install"
On linux, most base software comes from the distro repositories. The question there is how hard it would be to compromise these systems (including one of the mirrors). This includes ancillary packaging systems (pip, cpan, gems, conda, etc)
- consumer451 3y ago> Anti-virus software is utterly worthless in detecting previously-unknown rootkits. Maybe the "this will be easy" part was that without AV software, there was a greater chance that they could just spin up Metasploit, and wouldn't even have to use one their stockpiled zero-days?
- autoexec 3y agoWhy worry about stockpiled zero-days even for non-linux systems when they can just force MS or Apple to hand over data or inject whatever they want into an OS "update".
- consumer451 3y agoIf I'm beginning to recall the story correctly, it's that your suggested route would involve more time, paperwork, and this particular op might not be important enough to get the big guns authorized by the higher-ups. Hence, "oh, this will be (relatively) easy..."
- throwaway09223 3y agoAV doesn't detect the exploit mechanism -- that's not how it works. It's only pattern matching existing binaries. The difficulty level is "recompile with small changes and test that it doesn't match" not "develop a new attack vector" It really is stupid and pointless against an attacker with even a bare minimum of competence (able to run a software build vs downloading binaries)
- IIsi50MHz 3y agoThis would fit my expectations of a classical 1990s antivirus, however I would expect modern ones to also employ heuristics against behaviours. Are you referring specific'ly to a limitation ClamAV?
- consumer451 3y agoBut AV (EPP) could detect a binary which was passed through a traditional vector, like phishing or gaining access to a "trusted" email account and attaching a compromised PDF, as a random example. Just a reminder that I was originally talking about desktop Linux, and all of the additionally installed attack surface which that entails. It would seem to me that it does not matter how "technical" a user is, they are still human, and some of the time anyone could fall for a well formed phishing attack. We all get tired, overworked, or click too fast, etc. Not running AV on a desktop OS and relying on one's own superhuman technical ability seems like the exact type of hubris that would be ripe for attack.
- midasuni 3y agoHow many genuine issues (not nonsense like “blah.con has stored a cookie” does your av pick up?
- consumer451 3y agoIt is very likely that a modern AV (I should have been saying EPP) will pick up your average re-encoded payload, or Metasploit fun time. Certainly they will pickup most known vulnerabilities. Endpoint Protection (EPP) orgs use the same CVE DBs that adversaries use. See another user's comment: https://news.ycombinator.com/item?id=38594247 https://news.ycombinator.com/item?id=38594247 Security is an onion, perfect is the enemy of good, etc... Why make it easier for the adversaries? While annoying, running EPP on your desktop OS is not exactly neuroscience. Ideally, it's furnished by the OS provider so that there are fewer parties to trust. I hate to say it, but Microsoft is now teaching by example. MS has factually one of the best-in-class Endpoint Protection agents on the market. If resources allowed, all other desktop OS providers should follow suit, otherwise they are just shirking responsibility.
- CAP_NET_ADMIN 3y agoMost of the currently used AV software contains heuristic/ML components that are able to gather and analyze various indicators of compromise. Without something like that running, you're basically tied to manual review of systems running at the moment. Making malware for such scenarios is basically making a Base64-encoded script in the language of your choice and then exploiting something(either the user or some software) to get it to execute. I know, because I've been writing small malware toys and it got blasted by both Bitdefender and ESET.
- hulitu 3y ago> Most of the currently used AV software contains heuristic/ML components that are able to gather and analyze various indicators of compromise Ransomware runs just fine on corporate computers with the latest and greatest "antivirus" software. I really lost hope some 10 years ago, when i saw that i have to manually remove malware from memory sticks, because macaffe was clueless. After more than a year they released an update that will detect and remove the malware (it was a virus speading through autorun.inf with exe names which did not have any sense like jhghjjj.exe)
- consumer451 3y agoI can't speak to that particular attack vector today, but it's interesting that McAfee isn't even on this Gartner chart, and that Microsoft is now a leader. Things have really changed in that space. https://www.cybereason.com/blog/cybereason-named-a-leader-in-2022-gartner-magic-quadrant-for-endpoint-protection-platforms https://www.cybereason.com/blog/cybereason-named-a-leader-in...
- CAP_NET_ADMIN 3y agoCorporate Ransomware attacks typically use 0-days and social engineering to achieve goals. No system is perfect, but a system in place is better than not having anything in place. Things have changed in the last 10 years. Long gone are the days of only using signature databases. https://attackevals.mitre-engenuity.org/results/enterprise?vendor=bitdefender&vendor=microsoft&vendor=mcafee&evaluation=wizard-spider-sandworm&scenario=1 https://attackevals.mitre-engenuity.org/results/enterprise?v...
- heavyset_go 3y ago> On linux, most base software comes from the distro repositories. The question there is how hard it would be to compromise these systems (including one of the mirrors). This includes ancillary packaging systems (pip, cpan, gems, conda, etc) IMO if you're worried about the NSA, I assume they have access to root certificates and your package manager that uses TLS would be vulnerable. Wouldn't have to compromise any system or mirror to do so.
- throwaway09223 3y agoI mean yeah, I would say that's one way to compromise those systems.
- sp1rit 3y ago> your package manager that uses TLS would be vulnerable most distro package managers (dpkg, rpm, etc.) tend to use gpg which shouldn't suffer from those issues (but they could obviously still have some sort of other backdoor for gpg). Still, I feel like distro packages are really secured compared to stuff you install via pip/npm/... as I don't believe they do anything beyond protecting downloads with TLS.
- consumer451 3y agoThis seems like an extremely important point, which applies not just to desktop Linux (my OP,) but especially server Linux. Since I am very much a Linux & infosec muggle, please indulge me with these possibly dumb questions: What are the mitigations for the lack of provenance in pip/npm? Does properly configured SELinux do enough? Or is the fact that many of these packages use 80/443 negate that? Or is the fact that a pip/npm package could be comprised after install, during update the main problem? I always think of that left-pad NPM drama, could that single dev have comprised thousands of systems by changing his update to something much more nefarious, instead of just deleting the package? Again, sorry if these are dumb questions.
- sp1rit 3y agoWell, it depends on what you consider "properly configured". But I'd say most systems used by developers aren't secured against these attacks. This mostly boils down to (like discussed elsewhere in this thread) that the developer runs his tools as his user, thus malicious software can modify his .bashrc and using that hijack a later sudo invocation to gain full access. The thing that "protects" you is package locking, where unless you explicitly update your packages, you'll stay on an uncomprimised version (this broke with leftpad, as every available version was deleted). Locking has the downside that you don't get security updates for your software, which might be even more harmful tho.