Live data from Hacker News

Symantec found evidence of Longhorn against 40 targets spread in 16 countries

symantec.com

11–20 of 49 posts

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#11

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

> educate wife and children

I'm guessing you don't have teens who have to have the latest mod for every game they play. Giving up a very real download for the slight chance of a virus is a risk they are very willing to make.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#12
post #7

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

- Don't run day to day with local admin

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC.

Not sure what to think of these people

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#13
post #7

Earlier quoted context omitted.

- Don't run day to day with local admin

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

Well, I think this picture sums up a lot of thoughts on this subject: https://xkcd.com/1200/

In a nutshell, your user account has all your data, all your session cookies, all your logins and passwords, all your documents.... Everything.

And what can root/Administrator do? That's right, play with device drivers and systems stuffs. Once you have the primary user's account, unless it's a multiuser system, it's game over.

Just with user creds, I can start encrypting files to #evil_private_key , emailing browser data, keylogging, screencapping, data injection, and being a general nuisance.

The only good defense I've seen to this is what Qubes incorporates: Zones. It's virtual machines, with unique unspoofable borders, that you can configure to only allow the minimum amount of permission the container needs. Bank Zone only needs to talk to bank and financial websites. It doesn't need sound, or direct graphics access. Tor Zone allows talking through TCP on specified ports to and from, to allow Tor across system.

In that case, yes a specific system could be compromised, but using containers like that keeps damage limited.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#14
post #7

Earlier quoted context omitted.

- Don't run day to day with local admin

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

That's because UAC in windows is worthless, it's a broken version of sudo that fails to do the one thing necessary, force a re-authentication of credentials. There's little point in popping up a warning than people can simply click right past without requiring admin credentials.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#15

Too bad it's not like Microsoft's Longhorn - then it would have been delivered years late as a shadow of it's promised self (Vista) ;)

And it would be deprecated tomorrow [1]

[1] https://support.microsoft.com/en-ca/help/22882

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#16
post #7

Earlier quoted context omitted.

- Don't run day to day with local admin

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

UAC is merely a prompt that desensitizes users to more prompts. Whenever UAC shows up, for most people, the default reflex is just make the annoying prompt go away. Yes it to death.

Users simply should not log in as Administrators for day-to-day use. Anything requiring Administrator permissions should force a full log out, and change of identity. UAC doesn't educate users. Users should either be locked out of dangerous operations, or not locked out.

Administrators should take action only when there's the awareness that their decisions could result in the need to perform a full re-install of the system, without internet access.

This is the "nuke from orbit" gambit. It's the only way to be sure.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#17
post #13

Earlier quoted context omitted.

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

Well, I think this picture sums up a lot of thoughts on this subject: https://xkcd.com/1200/ In a nutshell, your user account has all your data, all your session cookies, all your logins and passwords, all your documents.... Everything. And what can root/Administrator do? That's right, play with device drivers and systems stuffs. Once you have the primary user's account, unless it's a multiuser system, it's game over…

Yes, exactly, I also have sudo no password on my linux boxes. If you're on my account you can keylog me or dump my keepass DB from memory. You may as well go ahead and have root too.

UAC is particularly bad in that it also produces problems with older applications and causes other applications to pop up UAC dialogs frequently. It's a huge annoyance with little security impact.

At worst it may make malware harder to remove if I do get infected - but in my experience, 99% of the malware you find kicking around on the internet isn't rootkit loaded 0 days - it's script kiddies crapping out iStealer to dump browser passwords or darkcomet to run DDoS botnets.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#18

>On one occasion a computer in the United States was compromised but, following infection, an uninstaller was launched within hours, which may indicate this victim was infected unintentionally. How do they know that?

They're being polite to the CIA whose charter forbids domestic ops (or at least severely constrains them.)

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#19

Earlier quoted context omitted.

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

That's because UAC in windows is worthless, it's a broken version of sudo that fails to do the one thing necessary, force a re-authentication of credentials. There's little point in popping up a warning than people can simply click right past without requiring admin credentials.

It works if you have a separate admin account. Then at least you have to enter its credentials, if not your own.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#20
post #11

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

> educate wife and children I'm guessing you don't have teens who have to have the latest mod for every game they play. Giving up a very real download for the slight chance of a virus is a risk they are very willing to make.

Seriously, it's not just teens either, it's many college students too. In general, anyone who didn't have to buy their own stuff has a bit less respect for it, and while that doesn't describe all teens or college students, it describes a huge number of them; a rich target pool.

I remember in the early days of exploitative XDCC botting, practically all of the most exploited ip ranges were scholastic; new devices each semester, often given to teens as a present.

Post reply on HN