7 ms·
Flame: Massive cyber-attack discovered, researchers say
- haberman 14y agoThe reason why Flame is [20MB] is because it includes many different libraries, such as for compression (zlib, libbz2, ppmd) and database manipulation (sqlite3), together with a LUA virtual machine. SQLite is 500kB, Lua is 150kb, zlib is 80kB, libbz2 is 60kB. Together this comes to less than 1MB, not 20MB. You would need an awful lot of libraries like this to get anywhere close to 20MB.
- timdorr 14y agoThey're likely skipping over a ton of libraries for brevity's sake. It captures data from audio, video, bluetooth, and other sources. A full BT stack is going to be pretty sizable. If there's any compression being done on that audio or video, that could also add to the bulk.
- runjake 14y agoI don't get the point of your comment. Are you saying you doubt it's 20MB? Or that it doesn't include a lot of libraries? What point are you trying to make exactly?
- fusiongyro 14y agoHe's pointing out that the explanation for the size given in the article isn't adequate because the facts don't bear it out.
- haberman 14y agoExactly. I particularly wanted to mention that it's entirely possible to ship software that uses libraries like this but isn't 20MB large. But maybe there are a lot more libraries included than are mentioned here (as another poster suggested).
- count 14y agoDidn't Sub7 do all of that back in the 90s?
- TheCapn 14y agoBBC won't provide the technical details that we hackers would require to differentiate the two. If it shares the likes of Stuxnet then it would have some pretty clever 0-days inside to help with infection and spreading.
- hippich 14y agoright. and it was NOT developed by state.
- makomk 14y agoI think hobbyist development of exploits of the kind that lead to Sub7 has mostly fallen out of fashion, to be honest. Most of the stuff out there these days seems to be commercially-driven scamware and phishing and its developers don't have the same incentive to make their code as 1337 as possible. So 90s-style exploit kits and RATs are quite unusual in 2012.
- swatkat 14y agoKaspersky blog has more info: http://www.securelist.com/en/blog/208193522/The_Flame_Questions_and_Answers http://www.securelist.com/en/blog/208193522/The_Flame_Questi...
- mkr-hn 14y agoThe LUA makes me wonder if the creator could be identified by their coding style.
- pjin 14y agoFrom the Kaspersky article, Flame ships with a Lua VM, sqlite3, zlib, libbz2, and an SSL library (probably OpenSSL?), and these and more apparently result in its unusually large size (almost 20 MB). Sounds almost like "lean malware" written by a relatively small team using easily available tools and libraries.
- raverbashing 14y agoYeah, I mean, sqlite3? In a 'virus'? What's next? Shipping the JVM and MariaDB
- duaneb 14y agoThe original virus may have only been a few hundred KB, which then bootstrapped the rest of the program. Just because you're writing malware doesn't mean you have to sacrifice good tools.
- fidotron 14y agoYes, this almost looks like they've created a sort of malware toolkit which has all the hard parts and exploits in C, but can be scripted quickly for purpose. Even better if the scripts can then be updated remotely as well. All things considered, this is the kind of thing you'd do if you were going to do this long term.
- spritrig 14y ago
- tomrod 14y agoMan, I love hearing the nitty-gritty security details. More like this, please!
- deleted 14y ago[deleted]
- vecinu 14y agoI assume we are going to see a complicated and interesting dissection a la Stuxnet? The Stuxnet TED talk [0] was really interesting, I ended up giving a talk to my department at work afterwards. [0] - http://www.youtube.com/watch?v=CS01Hmjv1pQ http://www.youtube.com/watch?v=CS01Hmjv1pQ
- jacquesgt 14y agoHere's a much deeper and more technical presentation Ralph Langner gave on Stuxnet. http://vimeopro.com/s42012/s4-2012/video/35806770 http://vimeopro.com/s42012/s4-2012/video/35806770
- LiquidSummer 14y agoI'm fed up by these technically lacking stories that don't give you the details but tell you that its "complex". While I realise that the BBC website is aimed towards the general public I think that it would be beneficial to include at least some technical details.
- davidandgoliath 14y agoIf you're fed up with that, avoid the mainstream media & delve into the blog post linked up above :)
- LiquidSummer 14y agoHaha! yeah I just finished reading the kinda-more-informative analysis (http://www.securelist.com/en/blog/208193522/The_Flame_Questions_and_Answers http://www.securelist.com/en/blog/208193522/The_Flame_Questi...). Seems very interesting. I wish that they would share the samples so other hobbyists could also see what it is like
- zby 14y agoOr links to sources - this is the web for god's sake!
- tlack 14y agoI'd love to know more about the command and control servers. If any of them involve paid hosting that might help to out the guilty party.
- LiquidSummer 14y agoHighly unlikely that that will happen, simply because even the smaller virus writers take precaution when buying servers, they usually do it using stolen credit cards that are not hard to acquire. In addition, the it also depends whether the hosting companies are willing to assist people with the investigation.
- hippich 14y agoif I would invest that much time into writing software, I would add TOR or i2p connectivity and would connect to hidden service
- duaneb 14y agoI would love to see the binary, even if it means waiting until vulnerabilities are patched.
- josephkern 14y agoAt 20MB I would be suprised if it didn't patch itself with new exploits.
- duaneb 14y agoHopefully the infected would not only patch but perform quarantines.
- thursley 14y agoMore technical details (pdf) on: http://www.crysys.hu/skywiper/skywiper.pdf http://www.crysys.hu/skywiper/skywiper.pdf Although the naming differs it has been noted on several blogs that it is the same malware.
- rhdoenges 14y ago> sKyWIper may have been active for as long as five to eight years spooky.
- LiquidSummer 14y agoI always hesitate a little bit when I open a pdf, specially when it is one on malware
- missing_cipher 14y agoWould opening a pdf via Chrome for example provide any extra protection? From what I understand most of the exploits are because of embedded media, no?
- LiquidSummer 14y agoExtra protection as opposed to opening it in adobe reader, yes, much likely. Chrome has a sandbox for pdfs as far as I'm aware, they also provide a lot of big bug bounties to people who find any remote execution bugs in Chrome. So, in conclusion, yes, chrome provides relatively more security than other software when opening PDFs.
- fishcakes 14y agoWe should just convert the comments to a poll. Who is behind this?
- fishcakes 14y agoChina
- fishcakes 14y agoUS
- fishcakes 14y agoIsreal
- fishcakes 14y agonon-state actor
- codesuela 14y agoNorth Korea
- maayank 14y agoHow would we keep track of scores? would you keep editing your post to reflect changes in voting? (this is besides the point if it is a good or bad idea. In any case, it is certainly seems novel to me)
- dylanhassinger 14y agoWeyland-Yutani
- ktizo 14y agoCotDC (only saying this because the list of features reminds me of an article I read years ago about MS Back Orifice)
- radagaisus 14y ago>> Our estimation of development ‘cost’ in LUA is over 3000 lines of code, which for an average developer should take about a month to create and debug. They should do project estimation instead of Security Analysis.
- munin 14y ago"It’s easier to hide a small file than a larger module." my mind is blown. small files are not like small rocks. it's a computer!
- gue5t 14y agoAssuming fairly dense formats (no .wavs or .bmp images), large files necessarily mean more than small files, so they draw more attention to themselves. "Why is /foo/bar using 300MB of disk?" is a much more likely avenue of inquiry than "Why is /foo/bar using 50KB of disk?".
- moe 14y agoExcept the last time when 20MB was "large" was in the early 1990s. Today, even if someone goes to clean out their harddrive, a 20MB file is unlikely to even appear on the radar.
- cstejerean 14y agoUnless you're dealing with most corporate mail systems.
- duaneb 14y agoI don't quite understand what you mean - the 20MB file would stand out on a mail server? I find that unlikely, unless they're running OpenBSD. Is the 20MB file attached to mail messages? That also seems unlikely, if only because that's a really stupid way to design a virus.
- Travis 14y agoThe reason it's a stupid way to design a virus currently is because that was one of the primary attack vectors in the past. Yes, most decent mail systems will protect against this. But some might not -- might as well use what's worked in the past as well as other options. Also, what if the mail component were used to hide/archive the virus? Hide a virus attachment from someone to themself, then have some bootstrap code (Outlook/email client exploit, perhaps) that loads the email archived virus back onto the comp.
- gcb 14y agoTheir conclusion that because it doesn't steal money it can't belong to cybercriminals is bogus and show how little they understand of the industry. I've heard of researchers from one company dumpster diving the competition. A worm (as amateur as a 20mb one ) could easily be the work of those kind. But i think it gets less press than "evil country" "omg world cyber war" ...not that it may not be happening anyway.
- mikegirouard 14y ago> "Currently there are three known classes of players who develop malware and spyware: hacktivists, cybercriminals and nation states." Surely that can't be all-inclusive… is it?
- dfc 14y agoHow could it not be? That is a very broad group. Who else has the motivation to develop and maintain large scale malware/spyware? If you want to be pedantic about it cybercriminal is probably broad enough to be all inclusive. I guess you could include companies like Sony but they were probably excluded for not having the same malicious intent.
- NelsonMinar 14y agoThe Wired ThreatLevel article is a good alternative summary to the BBC article. http://www.wired.com/threatlevel/2012/05/flame/ http://www.wired.com/threatlevel/2012/05/flame/
- DrummerHead 14y agoThose paragraphs are so short that it makes me angry.