Live data from Hacker News

Flame: Massive cyber-attack discovered, researchers say

bbc.com

31–40 of 84 posts

Re: Flame: Massive cyber-attack discovered, researchers say

#32
post #10

I'd love to know more about the command and control servers. If any of them involve paid hosting that might help to out the guilty party.

if I would invest that much time into writing software, I would add TOR or i2p connectivity and would connect to hidden service

Re: Flame: Massive cyber-attack discovered, researchers say

#34

We should just convert the comments to a poll. Who is behind this?

How would we keep track of scores? would you keep editing your post to reflect changes in voting?

(this is besides the point if it is a good or bad idea. In any case, it is certainly seems novel to me)

Re: Flame: Massive cyber-attack discovered, researchers say

#35

Earlier quoted context omitted.

Would opening a pdf via Chrome for example provide any extra protection? From what I understand most of the exploits are because of embedded media, no?

Extra protection as opposed to opening it in adobe reader, yes, much likely. Chrome has a sandbox for pdfs as far as I'm aware, they also provide a lot of big bug bounties to people who find any remote execution bugs in Chrome. So, in conclusion, yes, chrome provides relatively more security than other software when opening PDFs.

Even better would be firefox's javascript based pdf reader.

Re: Flame: Massive cyber-attack discovered, researchers say

#36

More technical details (pdf) on: http://www.crysys.hu/skywiper/skywiper.pdf Although the naming differs it has been noted on several blogs that it is the same malware.

I always hesitate a little bit when I open a pdf, specially when it is one on malware

It depends: will you render it using Adobe's software?

Re: Flame: Massive cyber-attack discovered, researchers say

#37
post #35

Earlier quoted context omitted.

Extra protection as opposed to opening it in adobe reader, yes, much likely. Chrome has a sandbox for pdfs as far as I'm aware, they also provide a lot of big bug bounties to people who find any remote execution bugs in Chrome. So, in conclusion, yes, chrome provides relatively more security than other software when opening PDFs.

Even better would be firefox's javascript based pdf reader.

You can always open it inside a throwaway VM. I keep a couple ;-)

Re: Flame: Massive cyber-attack discovered, researchers say

#38
post #21
post #3

Kaspersky blog has more info: http://www.securelist.com/en/blog/208193522/The_Flame_Questi...

Aren't these the guys who wigged out because they thought Duqu was written in an entirely new custom virus language? And it was actually Visual C++? The second most common compiler on the planet? (after GCC) I would take their analysis with a big pinch of salt.

A complete digression, but I see people say this all the time: when they want to use the "take with a grain of salt" metaphor, they increase the amount of salt to try to make it seem like the information is even more untrue.

But the whole point of the "grain of salt" metaphor is that it's so minuscule as to make no difference. So it would make more sense to say "take it with a half grain of salt," since that would imply the information is even more useless.

Re: Flame: Massive cyber-attack discovered, researchers say

#39
post #3

Kaspersky blog has more info: http://www.securelist.com/en/blog/208193522/The_Flame_Questi...

>At the moment, we haven’t seen use of any 0-days; however, the worm is known to have infected fully-patched Windows 7 systems through the network, which might indicate the presence of a high risk 0-day. I really want to know what that 0day is, I can't comprehend how hard it would be to find a 0day remote execution on a Windows system

I've always wondered if cyber criminals have tons of undiscovered security holes in Windows and other major pieces of software that they just don't release.
Post reply on HN