Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

61–70 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#61

I am in Tanzania(East Africa) and my father's computer is infected. All he did to get infected was plugging his laptop on the network at work(University of Dar Es Salaam). The laptop is next to me and my task this night is to try to remove this thing.

This malware is well written, and uses strong encryption. I would suggest that you and your father spend the evening reading up on backup practices, and reconsider the value proposition of open source software. I hope I am not coming off as a smug jerk. My hope is that rather than becoming frustrated and demoralized after an evening of fruitless hacking, you and your uni will recover, and become resilient against fut…

He has backups of his data.

I personally use linux and my github repo is here[1] where i have a bunch of encryption related projects(zuluCrypt,SiriKali and lxqt_wallet). The last windows computer i used was windows xp.

I dont want to move him to linux because i am not always around and he can ask other people for help when he is on windows.

[1] https://github.com/mhogomchungu

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#62
post #31

"Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." What Microsoft's software should be updated now to protect against this particular attack? Windows? Windows at the end user machines? The servers? Could someone share a "What should I do now to protect myself" guide, please? Thanks!

From everything I read last year... as long as someone has write access to a shared network resource, your network is vulnerable. I read about ways to detect it early with FSRM, but never tried it: https://chrisreinking.com/stop-cryptolocker-from-hitting-win... Experts, chime in? What is out there in 2017 (paid or not paid) as a way to protect network drives from ransomware?

Proper backup system?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#64
post #18

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

> Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

Unfortunately, I think the active hours period cannot be set to more than twelve hours, which is less than the time required for some surgical interventions. I can almost imagine it: OK everyone, ten-minute break while Windows installs its updates, this guy who's been on life support for the last ten hours can wait a little longer.

That's why updates are not forced on business-grade installs, and forcing them would be a very, very stupid decision.

Forced updates make sense for home users, since Microsoft can't depend on someone requiring them to keep their networks secure. For other types of users, second-guessing update policies is always a bad idea.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#66

Earlier quoted context omitted.

For this, run Windows update and install all updates. Additionally, it's smart to disable SMBv1 on all machines.

I disabled SMBv1 on the server. Good enough to protect our network share? Or is there some reason/benefit to disabling SMBv1 on client machines too? (I ran the simple powershell command on server: https://support.microsoft.com/en-us/help/2696547/how-to-enab... )

The main one is to have _all_ machines patched through windows update. That is what will protect you.

SMBv1 is an outdated protocol, in which there have been some severe vulnerabilities disclosed in the last few weeks, hence why I recommended to get rid of it at the same time.

That being said, the vulnerability being exploited here is in SMBv2, hence why patching all machines is crucial.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#67

Earlier quoted context omitted.

Your analogy doesn't really work because you can't copy a gun. These tools are way more dangerous than a gun because you can replicate them very quickly. You can never destroy the tools once they are created, someone always has a copy. This is what scares me more than nuclear weapons. A nuke requires a huge amount of people and infrastructure to maintain and launch. But a digital weapon? Pfft, copy that shit onto a U…

Why are power stations on the same network with some guy with a USB key?

Your incredulity would be fully justified in the 1990s, but with every year that passes, it is becoming harder and harder to fully isolate computer systems from other computer systems. I'd like to think I wouldn't let untrusted devices near my power plant, but I have some sympathy for those who struggle to keep their stuff secure in a world where security is ever harder to achieve.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#68
post #34

Earlier quoted context omitted.

> It sounds like the basic (?) security practices recommended by professionals - keep systems up-to-date, pay attention to whether an email is suspicious - would have covered your network. This is secondhand information (so take it for what it's worth, there could be pieces I'm missing), but I talked with a startup that was focusing on this problem, and the issue was not quite the computers and servers that IT were u…

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

In a perfect world there would be market pressure on device manufacturers: those device manufacturers who patch devices and ensure the patched versions are recertified, would win out over those who do not, in an environment where the expectation is for all these devices to be networked! But of course this requires a competitive market to exist, AND for recertification and patching to be trivial costs. Since they're not, even if a hospital administrator were to price in the risk of losing certifications on all their devices, it's likely that the risk would end up being less expensive than choosing that (potentially non-existent) security-conscious device manufacturer.

Anyone considering disclosure, responsible or not, should be aware of these types of secondary effects. Had these vulnerabilities hypothetically been discovered by a white hat or found their way to a leak-disseminating organization, the discoverers and gatekeepers should consider that not everything can be patched, and the ethical thing to do here would have been to notify Microsoft and wait for a significant product cycle to release technical details. I somehow doubt the Shadow Brokers had that aim, though. And it's saddening that even in the hypothetical case, many people would choose "yay transparency!" over a thoughtful enumeration of consequences.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#70

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

Are we watching this thing wake up right now?
Post reply on HN