Live data from Hacker News

Stuxnet Source Code

github.com

101–110 of 127 posts

Re: Stuxnet Source Code

#101
post #58

I remember reading a very well written article on stuxnet, detailing the entire way it worked. It was written in a very story-like way that built slowly until it revealed what the actual payload and impact was. Does anyone have a link to this article?

This Quora answer isn't article length but follows a similar story-like narrative and is well written imo. I remember reading this before I was working in tech and was amazed at how somebody(ies) came up with this

(Can't link direct URL as work filter doesn't allow Quora!)

https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web...

Re: Stuxnet Source Code

#102

Earlier quoted context omitted.

Yes, there are many ways to do that. When writing in a higher language such as e.g. C, you can use code obfuscators to make your C code extremely hard to read. If you want to make decompiling even impossible, you could modify the machine code generated by the C compiler. Even slight moderations are already enough. If you want to make it (virtually) impossible to even disassemble the machine code, you could encrypt yo…

> When writing in a higher language such as e.g. C, you can use code obfuscators to make your C code extremely hard to read. Obfuscating C code shouldn't have any bearing on the decompilability of the output. > If you want to make it (virtually) impossible to even disassemble the machine code, you could encrypt your binary itself except for a small bootstrap that will unencrypt the remainder of the binary when it run…

> This is stuff which was available back in 2003 -- that's when I first used techniques.

It was available already in the 1980's, so I learned at the time when I was manually disassembling computer games hoping to be able to crack them.

Re: Stuxnet Source Code

#103

Have anyone seen the documentary about stuxnet (Zero Days, 2016)? It's incredible. On the documentary, they mention another virus which was supposed to be even worse than Stuxnet, the project name was Nitro Zeus.

[dead]

Re: Stuxnet Source Code

#104

Earlier quoted context omitted.

Imagine if the same strategy were applied to biological warfare. Novel viruses tailored to be symptomatic and cause harm to just one specific world leader. If the technology exists, it could be the most formidable assassination tool available; a self-delivering, non-nuclear ace-in-the-hole for winning a war.

There is a very interesting conference from Defcon 25 about this exact subject: https://youtu.be/HKQDSgBHPfY?si=N9C-5VRNMtIoCQBB

Thanks, this was interesting.

Re: Stuxnet Source Code

#105
post #58

I remember reading a very well written article on stuxnet, detailing the entire way it worked. It was written in a very story-like way that built slowly until it revealed what the actual payload and impact was. Does anyone have a link to this article?

Check Ars Technica ?

Re: Stuxnet Source Code

#106

I remember first hearing about this while working at a US firewall company. The scale and precision of the attack kept this virus in the minds of everyone who appreciated what it proved capable of and the scale of social engineering employed to effect it. It kind of ushered in state-on-state cyber warfare, or at least, brought the reality of weaponized viruses to the public conscience.

Imagine if the same strategy were applied to biological warfare. Novel viruses tailored to be symptomatic and cause harm to just one specific world leader. If the technology exists, it could be the most formidable assassination tool available; a self-delivering, non-nuclear ace-in-the-hole for winning a war.

...it is also the plot device of the latest bond movie...

Re: Stuxnet Source Code

#107
post #80

Earlier quoted context omitted.

Stuxnet didn't break anything. It was used to override the working regime of centrifuges and conceal this fact from being discovered.

I guess to be more exact, Stuxnet didn't break anything, but the PLC payload it delivered was designed to damage centrifuges, and that would have been the module under test in that QA environment

Wasn't it actually about spoiling the whole stock of Iranian's Uranium by applying damaging amounts of centrifugal force to it? I'm probably wrong about that, just asking.

Re: Stuxnet Source Code

#108

Earlier quoted context omitted.

No casual antisemitism here. I would be very surprised if it turns out that Israel wasn't involved in Stuxnet. It's not like they don't have extremely good cyber capacity, or incentives to hinder an iranian nuclear program.

[flagged]

Honestly, it would be irresponsible and surprising if Israel _didn't_ try to sabotage Iran's nuclear program, especially given some of the things that the Iranians were saying publicly at the time.

Re: Stuxnet Source Code

#109
post #68

What always impressed me about Stuxnet wasn't the technical complexity, but the amount of spycraft that must have gone into identifying exactly what to program it to do, and what they could get away with.

France has enabled nuclear weapons programmes of many rouge states. Maybe Israelis just went to the Elysee palace, and asked?

I don't know about French nukes, but French-affiliated aerospace has a general rep as being leakier than most. Eh, "leakier" is a negative way of putting it . . how about "loose-lipped"? One tools selection from a French-based vendor - a cloud option for uncontrolled data - was turned down by uniformed dudes from the program office, based on this prejudice. But a similar cloud offering from "Ze Germans"? Oh, that was A-OK. Both products seemed built from compressed pellets of Turkish dander - of course they did, this is DoD shopping - but one of them did have that snappy Aryan zing.

Re: Stuxnet Source Code

#110

Earlier quoted context omitted.

[flagged]

Honestly, it would be irresponsible and surprising if Israel _didn't_ try to sabotage Iran's nuclear program, especially given some of the things that the Iranians were saying publicly at the time.

[flagged]
Post reply on HN