Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

271–280 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#271
post #258

Earlier quoted context omitted.

https://www.malwaretech.com/2016/01/exploring-peer-to-peer-b...

Wow, that's pretty amazing work! How is he able to add new supernodes to the cluster? I would expect a supernode to have some sort of credentials that are used for authentication. If not, isn't it possible to neutralize the botnet by overloading it with supernodes that don't send malicious commands?

According to his initial explanation - "In a peer to peer botnet, bots which can receive incoming connections act as servers (called supernodes)."

So in some cases the only requirement for a node to be a supernode is that it can receive incoming connections. I take this to mean that any computer that is 1. infected with the botnet program, 2. can receive incoming connections, becomes a supernode. Under those circumstances there's no need to reverse engineer the botnet program, all you have to do is set up a vulnerable computer, allow it to be compromised and infected becoming a supernode; then monitor the traffic of incoming connections.

He later mentions that supernodes can be filtered based on "age, online time, latency, or trust." This tells me that certain botnets do have a level of trust that is defined in each peer list.

I believe your last question refers to the concept of sinkholing or blackholing. These methods have been used by the FBI to take down botnets through DNS hijacking, I think.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#272
post #231

Earlier quoted context omitted.

I would be curious about this too. I'd assume many of them would be running Windows 7, maybe? (Let's hope it's not XP). Also, does Windows 10 Pro attached to a domain controller still have the same aggressive updates? Or do domain admins dictate that policy? At one company I worked at, everyone in IT could volunteer for the patch group to get security patches a few days before the rest of the machines. That seems to…

> Let's hope it's not XP BMJ released a report[0] just two days ago alleging that up to 90% of the NHS's computers are still running XP. > Many hospitals use proprietary software that runs on ancient operating systems. Barts Health NHS Trust’s computers attacked by ransomware in January ran Windows XP. Released in 2001, it is now obsolete, yet 90% of NHS trusts run this version of Windows. [0] http://www.bmj.com/cont…

It appears the Theresa May is trying to deflect attention from the fact that there has been massive under investment in NHS IT infrastructure by reinforcing that it is a 'international attack on a number of countries and organisations'.

Whilst this is true, it's probably also true that the impact of this attack is highly concentrated across organisations with chronic under-investment and a laissez-faire attitude to security.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#273

First of all, while I of all people love to pile onto the anti-NSA bandwagon (within constitutional reason that is, I don't advocate their abolishment, but that's a different conversation), there are quite a few non-three-letter related things that have contributed to this story and ones like it. The primary issue at the heart of things like this, beyond the backdoors and 0-days is this: bad IT. That being said thoug…

IT is just a reflection of overall society. In the name of immediate profit, we're cutting all we can cut, including essential services and maintenance; sooner or later we end up paying the full price for it.

This will not change until the reward systems for managerial classes change significantly.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#274
post #90
post #22

Earlier quoted context omitted.

That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…

if your job is to keep a bunch of computers working, keeping the systems running is the goal. Deploying security patches quickly is not always considered a requirement. Again, the problem is that rolling out patches quickly often leads to unplanned problems that can't be easily detected or rolled back from. That can cause problems worse than leaving security issues unpatched.

If your systems are exposed to the Internet, then deploying security patches quickly is a part of keeping the systems running - as illustrated by this case, where the systems obviously are not running and can't be easily rolled back to a working state.

The business of cybercrime is changing. With the growing popularity of ransomware, we should expect a gradual decrease in time between a published remote vulnerability and your systems getting attacked. It may be useful to delay patches by a day to see if there aren't any glaring problems encountered by others - but it's not a reason do leave open holes that were patched in March. Frankly, there was no good reason why this attack hadn't happened a month ago; next time the gap may be much smaller.

Yes, there is a chance that installing a security update to break your systems. But there's also a chance that not installing a security update will break your systems, and that chance, frankly, is much higher.

Furthermore, "That can cause problems worse than leaving security issues unpatched" seems trivially untrue. Every horrible thing that might happen because of a patch broken in a weird way may also happen because of an unpatched security issue. Leaving security issues unpatched can take down all your systems and data, plus also expose confidential information. A MS patch, on the other hand, assuming that it's tested in any way whatsoever, won't do that - at most, it will take down some of your systems, which is bad, but not as bad as e.g. Spain's Telefonica is experiencing right now. What patch could have caused them even worse problems?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#275
post #18

Earlier quoted context omitted.

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

So your workstation is next to a bed and is attached to a machine which feeds a drip to keep a little girl alive and it gets your untested patch or whole OS upgrade and the dosage is increased or the driver stops and the patient dies. Only non-critical machines can just automatically apply software patches from Redmond (or anybody). This is not laziness or incompetence - only a few weeks ago military grade exploits f…

So your workstation is next to a bed and is attached to a machine which feeds a drip to keep a little girl alive and it gets hit by a worm like this one, stops working and the patient dies.

As long as the chance of cyberattacks is larger than the chance of horrible patches, you simply accept the risk of horrible patches and install them anyway. Or keep the system totally isolated from everything, if it's that critical.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#276
post #236

It looks to me like common stupidity...people opening attachments that they should not be opening. No need to involve CIA NSA or other tree letters agency hacking tool...just old school phishing. I see this happening much to often....people opening *.pdf.js attachment. No need for another conspiracy theory...stupidity explains it all. Just my 50¢.

It looks like you have not done any "looking" at this at all. This is a worm that is using the ETERNALBLUE (and possibly other) exploits to infect all vulnerable machines on a network without user interaction plenty of stupidity for sure, but the stupidity is at the number of unpatched systems

My bad...the article is not really clear thou... My first comment...and my first fail... /me sad!

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#277
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

The problem is that the NSA is run by humans. Humans leak things by their own volition. No amount of best practices or levels of trust can change this.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#278

So If I pay how does the hackers decrypt my HD? Is there a way to sniff the key and pay once - decrypt everywhere?

You send them the code (encrypted key?) from your machine, they send you back the key that works for your machine.

If you have multiple computers (as these large organizations do), you need to pay for each one separately; the key for one won't work for the other. Perhaps they offer volume discounts?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#279

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…

Just because patches are available does not mean that they have been applied. Legacy applications, specialized hardware, vendor shenanigans, and organizational inertia can be significant impediments to keeping operating systems at current runlevels.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#280

Earlier quoted context omitted.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

He is not talking about the actual flaws as being the example as to why we shouldn't give the NSA backdoor access; he is saying that the leaks prove that even the NSA can't keep their stuff secret. If they couldn't keep their hacking tools secret, why should we think they can keep their backdoor access secret?

Good time to remind folks that gmail, facebook, whatsapp, amazon etc aren't going to be able to protect their data forever at the levels they currently are capable off.

A couple of bad business decisions and they are where yahoo is today. So be smart about how you use these services and educate the non-technical folks around you.

Post reply on HN