In order to increase resilience against this threat while large networks patch and upgrade, there are additional measures that can be taken I'd say those are the first things that should be done, regardless of the presence of exploits; exposing a port/listening service to the Internet you don't need, especially one that can remotely give complete control to an attacker, is always a bad idea. Fortunately the majority…
Even nat won't save you. Most NAT assumes unlimited outbound 0.0.0.0/0 tcp/udp/icmp . Almost all configuration is that permissive. And I just need 1 packet to puncture. https://samy.pl/pwnat/
NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
31–40 of 40 posts
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#32I know we should always assume good faith. From all the vulnerabilities they know, they chose to publish one that's known and only concerns outdated software. Maybe I'm too skeptical but when the NSA starts leaking fixes for zero day exploits, I'll take them more seriously.
Zero-days are far more useful to them as exploitable points of entry as opposed to patches.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#33The fact that NSA does so little for cybersecurity is telling. When they say patch something, it probably means it should be national emergency.
It means that it’s good to have a backdoor you can use, it’s bad if your enemy can also use it. So the moment NSA pushes you to patch it’s because it’s no longer exclusive to them so the backdoor is no longer an asset but a liability.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#34I know we should always assume good faith. From all the vulnerabilities they know, they chose to publish one that's known and only concerns outdated software. Maybe I'm too skeptical but when the NSA starts leaking fixes for zero day exploits, I'll take them more seriously.
That’s kinda like saying you’ll only take google seriously when they start releasing their SERP algorithms. Zero-days are far more useful to them as exploitable points of entry as opposed to patches.
Perhaps it's not wise to have the same organization looking after both the defensive aspects of our security, AND also offensive espionage operations.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#35I know we should always assume good faith. From all the vulnerabilities they know, they chose to publish one that's known and only concerns outdated software. Maybe I'm too skeptical but when the NSA starts leaking fixes for zero day exploits, I'll take them more seriously.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#36I know we should always assume good faith. From all the vulnerabilities they know, they chose to publish one that's known and only concerns outdated software. Maybe I'm too skeptical but when the NSA starts leaking fixes for zero day exploits, I'll take them more seriously.
Why would they leak vulnerabilities they've spent millions of dollars to find? Seems like that would be a waste of money with zero benefit to their mission.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#37I know we should always assume good faith. From all the vulnerabilities they know, they chose to publish one that's known and only concerns outdated software. Maybe I'm too skeptical but when the NSA starts leaking fixes for zero day exploits, I'll take them more seriously.
But I still don't see how that could be a reason to not take this warning seriously.
I think that the cynical view of this would rather be that they consider the potential harm from someone they don't like, making a 1m machines botnet from this, to be greater that the benefit they get from themselves making a 1m machines botnet.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#38I know we should always assume good faith. From all the vulnerabilities they know, they chose to publish one that's known and only concerns outdated software. Maybe I'm too skeptical but when the NSA starts leaking fixes for zero day exploits, I'll take them more seriously.
I can't exactly say that I trust NSA, and I don't doubt that they have knowledge of vulnerabilities that they aren't releasing. But I still don't see how that could be a reason to not take this warning seriously. I think that the cynical view of this would rather be that they consider the potential harm from someone they don't like, making a 1m machines botnet from this, to be greater that the benefit they get from t…
I think the NSA has a real image problem. They released ghidra. They admitted it was a recruitment tool. They now release this warning which basically tells us to update our software. Anyways, if they really want to improve their image, they need to release zero day exploits and prove it's not just an offensive but also a defensive agency.
The release of an exploitable bug might deny them a couple of targets but will protect millions.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#39Earlier quoted context omitted.
I can almost picture the NSA staff meeting: "Let's bait Hacker News randos by issuing an advisory about a nearly internet-wide vulnerability that gives unrestricted access to Windows computers. Then, when they visit our website to learn more, we'll nab them!" Thanks for taking a bullet for the team on this one, Internet stranger.
Reminds me of the UK UFO trap story. In the UK it's illegal to listen to police on scanners so detectives transmitted a hoax radio message about a UFO landing near Doncaster, South Yorkshire, then arrested several people who turned up at the spot, charging them with illegally using scanners to monitor police radio transmissions.
Some cops somewhere decided to send a letter to everyone who had a warrant stating they won a boat. To make sure they didn’t immediately run they went through a couple fake formalities like pictures and such until they opened the door to the boat garage. Inside were uniformed officer waiting to make the arrest.
Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows
#40Earlier quoted context omitted.
It means that it’s good to have a backdoor you can use, it’s bad if your enemy can also use it. So the moment NSA pushes you to patch it’s because it’s no longer exclusive to them so the backdoor is no longer an asset but a liability.
Right, so...patch it
I was just providing my take on when and why would NSA warn for this.