WannaCry – New Variants Detected
111–120 of 164 posts
Re: WannaCry – New Variants Detected
#112Earlier quoted context omitted.
The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
http://researchcenter.paloaltonetworks.com/2017/05/palo-alto...
Re: WannaCry – New Variants Detected
#113Could the 51% "bug" in bitcoin actually be used to an advantage here? A 51% vote to invalidate all these transactions? I assume it doesn't work like that but figured I would ask.
Re: WannaCry – New Variants Detected
#114Could the 51% "bug" in bitcoin actually be used to an advantage here? A 51% vote to invalidate all these transactions? I assume it doesn't work like that but figured I would ask.
If this attack occurred against, for example, the CN government, they may step in and force miners to invalidate.
This scale is world-wide, there's no loss of public image and the amount of BTC is very small in the scheme of things.
Re: WannaCry – New Variants Detected
#115Earlier quoted context omitted.
"older Windows versions" Win 10 is vulnerable without the patch that came out in march.
>Win 10 is vulnerable without the patch that came out in march Microsoft clearly disputes this in their own posts on the subject. https://blogs.technet.microsoft.com/msrc/2017/05/12/customer... "Customers running Windows 10 were not targeted by the attack today." What's your source?
Re: WannaCry – New Variants Detected
#116I think it's hilarious how these "kill switches" are supposedly meant to detect sandboxes, to make it harder for security researchers to analyze the malware. While actually making it easy for security researchers to completely disable all installations around the entire world. That's just what I heard, but it makes sense. There are far more sane ways to implement a kill switch without using unregistered domains. (For…
From the sounds of it, it seems like the researchers didn't expect the killswitch to disable the malware outside of the sandbox any more than the author of the malware did[0].
[0]: https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
Re: WannaCry – New Variants Detected
#117Earlier quoted context omitted.
An XP computer is old, Windows 8.1 is one generation back. Both are vulnerable to this exploit. Yes, patches have been available for supported versions, I don't know how that makes anything I said wrong or misleading.
We agree about it being not JUST old Windows versions being affected. I replied to your comment because the "old" Windows XP having no patch available was significant here, and I read your comment as saying "old" windows versions were not proportionally more responsible for WannaCry's rapid spread. Windows XP is still the third largest version of Windows by current installed base (after Windows 10 and Windows 7). The…
I addressed that it wasn't "old" Windows because there is a crazy belief out there that this only hit XP.
Re: WannaCry – New Variants Detected
#118Earlier quoted context omitted.
Hasn't that been a common thing in bitlocker malware for ages too? Did they just manage to craft so really persuasive emails this time?
WannaCry is a worm. It does not require people to click on anything in emails to be infected. It scans for vulnerable computers and infects them directly over the network.
Re: WannaCry – New Variants Detected
#119Earlier quoted context omitted.
The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
It continues to be a very common attack method and I'd be surprised if it wasn't leveraged again.
Re: WannaCry – New Variants Detected
#120Earlier quoted context omitted.
>Win 10 is vulnerable without the patch that came out in march Microsoft clearly disputes this in their own posts on the subject. https://blogs.technet.microsoft.com/msrc/2017/05/12/customer... "Customers running Windows 10 were not targeted by the attack today." What's your source?
WannaCry ("the attack") didn't target Windows 10 installations (probably since most Win10 users have updates enabled), but Windows 10 is still vulnerable without the patch.