Live data from Hacker News

Flame: Massive cyber-attack discovered, researchers say

bbc.com

81–84 of 84 posts

Re: Flame: Massive cyber-attack discovered, researchers say

#81
post #70

Earlier quoted context omitted.

Unless you're dealing with most corporate mail systems.

I don't quite understand what you mean - the 20MB file would stand out on a mail server? I find that unlikely, unless they're running OpenBSD. Is the 20MB file attached to mail messages? That also seems unlikely, if only because that's a really stupid way to design a virus.

The reason it's a stupid way to design a virus currently is because that was one of the primary attack vectors in the past. Yes, most decent mail systems will protect against this. But some might not -- might as well use what's worked in the past as well as other options.

Also, what if the mail component were used to hide/archive the virus? Hide a virus attachment from someone to themself, then have some bootstrap code (Outlook/email client exploit, perhaps) that loads the email archived virus back onto the comp.

Re: Flame: Massive cyber-attack discovered, researchers say

#82

Earlier quoted context omitted.

FLAME isn't a virus, it is software from Brazil, just like LUA is from Brazil. "Tool prototyping in the FLAME platform is based on the Lua scripting language. Lua is adopted in FLAME as an extension language: its interpreter is embedded as a library into the measurement agents. On the one hand, the Lua interpreter gives to the scripts running in the agents access to active measurement primitives through a high-level,…

Thank you for doing ten-minutes of research. Your investigative style of journalism is apparently better than both Kaspersky and the BBC.

Looks like that link's since been updated to make it clear that this is a completely unrelated piece of software called Flame that just happened to use LUA too, with it being very unlikely that any code could be shared between the two. Basically, the name's just a coincidence.

Re: Flame: Massive cyber-attack discovered, researchers say

#83

Earlier quoted context omitted.

I always hesitate a little bit when I open a pdf, specially when it is one on malware

Note that while the exploit is in the PDF, the vulnerability is in the PDF reader. In practice, Adobe's software is the only attack surface anyone ever exploits, so you can read exploit-laden PDFs worry-free by using a less popular alternative. The same is true with Word/Excel files, etc. You should still have some kind of comprehensive security solution in place, particularly for a business environment, but use of n…

I've no idea why everyone only exploits Adobe's software though. For instance, pretty much all the open source PDF readers are based on a single PDF library called Poppler with a history of security vulnerabilities - exploit that and you should be able exploit all of them in one fell swoop.

Re: Flame: Massive cyber-attack discovered, researchers say

#84
post #31
post #2

Didn't Sub7 do all of that back in the 90s?

right. and it was NOT developed by state.

I think hobbyist development of exploits of the kind that lead to Sub7 has mostly fallen out of fashion, to be honest. Most of the stuff out there these days seems to be commercially-driven scamware and phishing and its developers don't have the same incentive to make their code as 1337 as possible. So 90s-style exploit kits and RATs are quite unusual in 2012.
Post reply on HN