I remember having to write a presentation about Stuxnet while at Uni, it was insane. At the time they reckoned the authors had a functioning QA environment to ensure it actually worked (broke) the Siemens PLCs they were targeting.
Stuxnet Source Code
41–50 of 127 posts
Re: Stuxnet Source Code
#42I remember having to write a presentation about Stuxnet while at Uni, it was insane. At the time they reckoned the authors had a functioning QA environment to ensure it actually worked (broke) the Siemens PLCs they were targeting.
Nitpick but it was even harder, they wanted to keep the PLCs intact, report back normal operation, and change the control output specifically to destroy/damage uranium centrifuges
Re: Stuxnet Source Code
#43Earlier quoted context omitted.
Nitpick but it was even harder, they wanted to keep the PLCs intact, report back normal operation, and change the control output specifically to destroy/damage uranium centrifuges
Yep. I'd be surprised if their QA environment didn't contain at least one uranium centrifuge.
Re: Stuxnet Source Code
#44Re: Stuxnet Source Code
#45Earlier quoted context omitted.
A nuclear plant is just as weaponizable as any large dam...
Is it? The nuclear fallout of a plant may linger for longer than any destruction done by the water of a large dam I would say or do you mean something else?
Re: Stuxnet Source Code
#46Earlier quoted context omitted.
Nuclear power is vastly better in terms of emissions, so I'd argue that blowing up a plant or two is worth stopping global warming. But why target plants when a dirty bomb attack would be way easier and more effective? Additionally, most countries don't have the resources to pull off something like Stuxnet, and the ones that do have much more to gain through corporate and government espionage.
There is some problem there though - peacefully using nuclear power creates plutonium, which could be later extracted.
Re: Stuxnet Source Code
#47Re: Stuxnet Source Code
#48Can anyone explain why Stuxnet was admitted to and publicised so much. Aren’t secret operations usually kept… secret? What was the motivation for the PR drive?
Remembering that the only reason we even know about stuxnet is because it was so aggressive that practically every PC on the planet caught it at one point. Also "stuxnet" is the name we gave it, it seems similar to another US Govt project that we know very little about codenamed "Olympic Games".
If it had not been so aggressive it would have gone completely unnoticed. Likely this is the case for a lot of state-sponsored malware. (especially coming out of FIVE-EYES).
Re: Stuxnet Source Code
#49Has anybody else here read Kim Zetter's great book Countdown to Zero Day? It's a wonderful look at the discovery of Stuxnet.
Re: Stuxnet Source Code
#50I just love that not only they copyrighted it, they even give excuses for it. You can't copyright someone else's work, regardless of how long you took to reverse-engineer it from disassembled binaries. Obviously the "rights owners" are not going to take those two guys to court (pity though, that would've been hilarious), but since the only reason those two could license this is that this is a computer virus and no on…