Didn't Sub7 do all of that back in the 90s?
Flame: Massive cyber-attack discovered, researchers say
31–40 of 84 posts
Re: Flame: Massive cyber-attack discovered, researchers say
#32I'd love to know more about the command and control servers. If any of them involve paid hosting that might help to out the guilty party.
Re: Flame: Massive cyber-attack discovered, researchers say
#33We should just convert the comments to a poll. Who is behind this?
Re: Flame: Massive cyber-attack discovered, researchers say
#34We should just convert the comments to a poll. Who is behind this?
(this is besides the point if it is a good or bad idea. In any case, it is certainly seems novel to me)
Re: Flame: Massive cyber-attack discovered, researchers say
#35Earlier quoted context omitted.
Would opening a pdf via Chrome for example provide any extra protection? From what I understand most of the exploits are because of embedded media, no?
Extra protection as opposed to opening it in adobe reader, yes, much likely. Chrome has a sandbox for pdfs as far as I'm aware, they also provide a lot of big bug bounties to people who find any remote execution bugs in Chrome. So, in conclusion, yes, chrome provides relatively more security than other software when opening PDFs.
Re: Flame: Massive cyber-attack discovered, researchers say
#36More technical details (pdf) on: http://www.crysys.hu/skywiper/skywiper.pdf Although the naming differs it has been noted on several blogs that it is the same malware.
I always hesitate a little bit when I open a pdf, specially when it is one on malware
Re: Flame: Massive cyber-attack discovered, researchers say
#37Earlier quoted context omitted.
Extra protection as opposed to opening it in adobe reader, yes, much likely. Chrome has a sandbox for pdfs as far as I'm aware, they also provide a lot of big bug bounties to people who find any remote execution bugs in Chrome. So, in conclusion, yes, chrome provides relatively more security than other software when opening PDFs.
Even better would be firefox's javascript based pdf reader.
Re: Flame: Massive cyber-attack discovered, researchers say
#38Kaspersky blog has more info: http://www.securelist.com/en/blog/208193522/The_Flame_Questi...
Aren't these the guys who wigged out because they thought Duqu was written in an entirely new custom virus language? And it was actually Visual C++? The second most common compiler on the planet? (after GCC) I would take their analysis with a big pinch of salt.
But the whole point of the "grain of salt" metaphor is that it's so minuscule as to make no difference. So it would make more sense to say "take it with a half grain of salt," since that would imply the information is even more useless.
Re: Flame: Massive cyber-attack discovered, researchers say
#39Kaspersky blog has more info: http://www.securelist.com/en/blog/208193522/The_Flame_Questi...
>At the moment, we haven’t seen use of any 0-days; however, the worm is known to have infected fully-patched Windows 7 systems through the network, which might indicate the presence of a high risk 0-day. I really want to know what that 0day is, I can't comprehend how hard it would be to find a 0day remote execution on a Windows system