Live data from Hacker News

Transmission BitTorrent app contained malware

forum.transmissionbt.com

211–220 of 355 posts

Re: Transmission BitTorrent app contained malware

#211

Earlier quoted context omitted.

"It will then sleep for three days. Note that, in a different sample of KeRanger we discovered, the malware also sleeps for three days, but also makes requests to the C2 server every five minutes." It's fascinating!

Isn't it possible to fire a takedown notice to that server? I mean KeRanger committed a felony and Amazon (assuming you mean Amazon's EC2 server) might react quickly if they realize what has happened. It might save a lot of computers from getting destroyed. As long as the server is somewhere in the Western world, it should not be a problem.

It's a "Command-and-Control" server (C&C or C2).

https://en.wikipedia.org/wiki/Command_and_control_%28malware...

I just learned that too. For me, C&C reminds me "Command and Conqueer" (the game).

https://en.wikipedia.org/wiki/Command_%26_Conquer

Re: Transmission BitTorrent app contained malware

#212
post #195

Earlier quoted context omitted.

This is exactly why sandboxed apps (e.g., iOS/UWP/etc.) are a good thing.

Or the Mac App Store itself. Its enforced sandboxing would have provided a decent first line of defense against this, but torrent clients can't be submitted to the App Store due to Apple not liking the legal aspects, not to mention the other issues people have with it. (Outside the store, apps can still opt into sandboxing, but that wouldn't help with a malicious installer.)

I doubt Apple keeps it out for "Legal" aspects. iTunes sales seems more likely.

Re: Transmission BitTorrent app contained malware

#213

Earlier quoted context omitted.

Isn't it possible to fire a takedown notice to that server? I mean KeRanger committed a felony and Amazon (assuming you mean Amazon's EC2 server) might react quickly if they realize what has happened. It might save a lot of computers from getting destroyed. As long as the server is somewhere in the Western world, it should not be a problem.

It's a "Command-and-Control" server (C&C or C2). https://en.wikipedia.org/wiki/Command_and_control_%28malware... I just learned that too. For me, C&C reminds me "Command and Conqueer" (the game). https://en.wikipedia.org/wiki/Command_%26_Conquer

Thanks, I just realized it after reading Claud Xiao and Jin Chen's analysis, too. Apparently, this ransomware uses Tor to hide its origin.

Analysis: http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...

Re: Transmission BitTorrent app contained malware

#214

Earlier quoted context omitted.

> "Open source software is especially vulnerable to this kind of stuff." I am sorry, what? Why would open source contain more bugs/hacks than closed source specifically? It is more often in the news for few reasons, including that many projects are widely used. However it's against any PR from companies to have their security issues disclosed like they are in open source so they try to minimize the exposure. See [1]…

Not because of the fact that it's open source, but because of the distribution models used. SourceForge has been linked to bundled malware and hijacked projects like GIMP and FileZilla.

I don't follow, what does it matter for the "distribution model" if the software is open- or closed-source? The problem with SourceForge were its malware-riddled installers, how would it be any better if the downloads were proprietary software?

Re: Transmission BitTorrent app contained malware

#215

Earlier quoted context omitted.

"It will then sleep for three days. Note that, in a different sample of KeRanger we discovered, the malware also sleeps for three days, but also makes requests to the C2 server every five minutes." It's fascinating!

Isn't it possible to fire a takedown notice to that server? I mean KeRanger committed a felony and Amazon (assuming you mean Amazon's EC2 server) might react quickly if they realize what has happened. It might save a lot of computers from getting destroyed. As long as the server is somewhere in the Western world, it should not be a problem.

The server isn't on EC2, it's hosted on Tor. The malware uses an HTTP-to-TOR gateway service (onion.nu and onion.link) to pull down the encryption key and README file from one of three different hidden services. In theory you could try to get the gateways to block the connections, but I'm not sure they're likely to be cooperative.

Re: Transmission BitTorrent app contained malware

#216

On a related note, Windows Defender detects malware when downloading the windows putty installer. Trojan: Win32/Varpes.J!plock http://www.chiark.greenend.org.uk/~sgtatham/putty/download.h... Not sure how to report.

try uploading the file to virustotal, avira etc. Windows Defender should in the alert have a button to report to microsoft.

Re: Transmission BitTorrent app contained malware

#217

Earlier quoted context omitted.

But ideally there are no credentials because Jenkins doesn't need to push code to the repo (and can clone the pubically available code).

But it might need to push new (binary) updates if the master/deploy branches gets updated or a commit contains a specific tag. As far as I know, only the binary was updated. I'd be interested to hear, though, how it got compromised after all.

Yeah, that makes sense. Build servers are one of the weakest links in distributing software. That's why this exists and I'm glad it's making progress:

https://reproducible-builds.org

And even if you sign updates, the key management for doing that is usually centralized, which can be bad:

http://arstechnica.com/security/2016/02/most-software-alread...

Re: Transmission BitTorrent app contained malware

#218

Earlier quoted context omitted.

It's a "Command-and-Control" server (C&C or C2). https://en.wikipedia.org/wiki/Command_and_control_%28malware... I just learned that too. For me, C&C reminds me "Command and Conqueer" (the game). https://en.wikipedia.org/wiki/Command_%26_Conquer

Thanks, I just realized it after reading Claud Xiao and Jin Chen's analysis, too. Apparently, this ransomware uses Tor to hide its origin. Analysis: http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...

I liked the "We have ticket system." (in the screenshot of "README_TO_DECRYPT.txt").

They ask (only) 1 BtC as a ransom.

Re: Transmission BitTorrent app contained malware

#219

I've become increasingly paranoid lately, given that things like these happen and major bugs are uncovered in software that I use almost every day. It's good that the Transmission developer reacted quickly and made waves so that people can at least be aware that they might have been exposed.. But I wonder how many more applications from the hundreds that I have installed on my machines contain weird stuff - either in…

> Open source software is especially vulnerable to this kind > of stuff. Give it 2 or 3 years and stories will come trickling out about how most OS apps have had commits from hackers, governments etc. So far most source checking - to the extent that it happens at all - is all about buffer overruns and the like; micro stuff that's easily catchable. Well, you say that, but, you know, heartbleed etc. But what about whol…

Open Source software has existed for more than 2 or 3 years, you know.

All software is vulnerable to bad actors writing malicious code. What makes it any safer if its proprietary software? In any case, in a pessimistic scenario you'd have to change your sentence to "give it 2 or 3 years and stories will come trickling about how ALL apps, open or closed source, were tampered with by hackers, the government, etc".

Re: Transmission BitTorrent app contained malware

#220
Oh dear god. Used 2.90 past week, when I saw the news I updated immediately, checked for all the files, found nothing. I hope my MacBook will stay fine tomorrow. I got it backed up on Time Machine anyway. Where do we go from here, since I lost the trust, what are the alternatives? And from now one, I'll go with Brew Cask for everything possible.

F* GUI /s

Post reply on HN