4 ms·
While this is undoubtedly scary, it looks very Windows-specific and would seem unlikely to affect a somewhat security-conscious Linux user. Java and IE exploit
by aselzer 12y ago
While this is undoubtedly scary, it looks very Windows-specific and would seem unlikely to affect a somewhat security-conscious Linux user.
Java and IE exploits, autorun files, NTFS...
> The malicious firmware created a secret storage vault that survive
> military-grade disk wiping and reformatting, making sensitive data
> stolen from victims available even after reformatting the drive and
> reinstalling the operating system.
And that's why it's possibly not the greatest idea to replace simple firmware and drivers with small operating systems (Intel AMT, microcode, SSDs, Smart TVs etc.).
- fragsworth 12y agoThe attacks were highly specific to the targets they were going after. It's a large team with massive resources - if you become a target, being a Linux user will not protect you from their attacks.
- wongarsu 12y agoI suspect that most of their targets use Windows, so we have more malware samples from Windows hosts. The article specifically mentions that they heavily suspect that a Mac malware exists, yet they haven't found it yet. Consequently we don't know which exploits they use to get on Macs. They also talk about a wide range of servers being infected, only attacking Windows servers would be very limiting. My best guess is that if you are a target, using Linux makes their work harder but not impossible. They had over a decade to figure this out and vulnerabilities in Linux software are found all the time.
- AlyssaRowan 12y agoActually, I think they quite like high-uptime Linux peers for their C&Cs.
- aselzer 12y agoThe site shows a PHP script targeting vbulletin. Obviously there are lots of ways of attacking servers, especially if they run PHP applications and such. There was once a PDF exploit for iOS that made it possible to jailbreak the phone (or run any code) if the user opened a PDF, so the PHP program could have been redirecting to something like this. Linux malware would probably have a much lower effectiveness / $, so it doesn't pay off for them.
- cnvogel 12y ago> unlikely to affect a somewhat security-conscious Linux user Obviously the reported malware is Windows specific, but there's no fundamental roadblock to implement something similar in Linux. - malware injected in the boot process: Have a patched grub/syslinux/gummiboot that, after loading the Linux kernel, patches in the first stages of a rootkit. Common syscall tables and important system functions (kalloc, ...) are easy to identify, as long as the API doesn't radically change. - secret, encrypted, storage vault in the registry is surely harder to hide, because there's typically not ONE huge monolithic binary configuration database. So, probably one would have to find a feature of ext4/btrfs/xfs/... to hide things in some internally used filesystem object that's not visible to userspace (you can, after all, patch the fs kernel module if necessary) - patching the SSD or harddrive is surely doable, just have a look at the hdparm manpage for inspiration. (--fwdownload is the official undocumented API :-)). [just thinking about the parallels, a sophisticated attacker will surely spend some time tailoring his rootkit/malware better] But obviously it would be much harder to persist on a machine, given that internal APIs are much more unstable and bootloader frequently overwritten on OS updates (the Win Bootloader/boot partition, afaik, never...). On the other hand, the targeted users (industrial/military corporations) will probably stick with yesteryear's RedHat Enterprise, rather than "bleeding edge" Arch/gentoo.