4 ms·
Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant (the same target o
by kibitzor 25d ago
Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant (the same target of the cyber-weapon) as I listened to the audio book[2] based on this ~12 years ago, entirely changed how I viewed critical industrial infrastructure. One quote from the book that stuck with me was how you can only use a cyber weapon once at full potential, as it’ll either get patched and/or everyone can reverse engineer it to use.
For those not familiar with Stuxnet, it’s a discovered cyber-weapon from 2010 which “reportedly destroyed almost one-fifth of Iran's nuclear centrifuges. ” and “ neither the United States nor Israel has openly admitted responsibility” but likely were the developers [1]
[1-Wikipedia Entry](https://en.wikipedia.org/wiki/Stuxnet https://en.wikipedia.org/wiki/Stuxnet)
[2-“Countdown To Zero Day” book if you liked the Wikipedia entry](https://www.audible.com/pd/Countdown-to-Zero-Day-Audiobook/B00P30Z5F2 https://www.audible.com/pd/Countdown-to-Zero-Day-Audiobook/B...)
[3-“Zero Days” movie](https://www.imdb.com/title/tt5446858/ https://www.imdb.com/title/tt5446858/)
- fathermarz 25d agoThis is amazingly awesome. Very intriguing and what a great idea in the first place. One of the most important pieces of modern software IMO.
- BLKNSLVR 25d agoImportant to note that the system(s) it infected were non-trivially air-gapped, so it had to do the entirety of it's infectious work without command and control servers or receiving any additional input. It had to be an entirely autonomous process from infection to propagation to execution. Pretty amazing to have been pulled off seemingly so successfully.
- stingraycharles 25d agoWasn’t it actually not as successful as it could have been? I recall something about it spreading to more machines than it should have, which caused it to be detected earlier than it should have.
- deleted 25d ago[deleted]
- BLKNSLVR 25d agoPlaying with definitions of success in this reply, but, yes, I think the industrial control system detection wasn't quite narrow enough. Very successful in doing what was intended. Less successful in limiting collateral damage; the collateral damage of which was earlier than intended discovery (or discovery at all). What lessons have they learned, though, so what's out there now, with 10 years more learning, and now AI assistance? Scary thought. We're all pwnt.
- theturtletalks 25d agoYes they actually flooded the market with USB drives with Stuxnet. But it was actually too good and started infecting non-target computers. That’s what got a malware researcher to dig in and he saw multiple zero days being used and deduced it was a Mossad and US operation.
- Tangurena2 24d agoSome of the code needed to be digitally signed to execute on target hardware, so being able to get the actual digital certs meant that Stuxnet could not be a hacker group and could only be some national agency or "Bond villain."
- shuwix 24d ago[dead]
- tehjoker 25d agoWhere did the binaries come from? Did Iran release them?
- DANmode 25d agoAre you referring to the government of Iran, or the (possibly Iranian) sec people they handed the flash drives from the parking lot to?
- nirav72 25d agoFrom what I recall reading, stuxnet itself was found in the wild. Even though it was certainly created for a specific target. That’s how security researchers were able to study it fairly quickly. So the binaries were already out there to pull from other infected systems.
- ralphhughes 24d agoCan confirm. I was working in Azerbaijan with people from Iran at the time and had it infect my pendrive and work PC. No anti-virus picked it up at the time.
- CMDDestory 25d agoThanks,providing readable code for everyone is inherently a thing of pride.
- maledadams 24d ago[flagged]
- kotaKat 23d ago"you can only use a cyber weapon once at full potential, as it’ll either get patched and/or everyone can reverse engineer it to use" This is why I jokingly always suggested to people the safest public charger to use was the one the NSA brings to DEFCON/Shmoocon/etc. The NSA ain't burning an exploit on a bunch of nerds. ;)