Live data from Hacker News

The Microsoft Update mechanism has been used to spread malware

f-secure.com

31–40 of 64 posts

Re: The Microsoft Update mechanism has been used to spread malware

#31
Apparently the other tricky bit is that Windows can be set to auto-configure network proxies (presumably for enterprise support), so the infected host pretends to be the source of auto-config info in order to direct the other systems to connect through it to get to Windows Update. At which point the infected system can infect the package, which has been signed so it will auto-install.

Re: The Microsoft Update mechanism has been used to spread malware

#32
The SecureList summary was much more detailed: http://www.securelist.com/en/blog/208193558/Gadget_in_the_mi...

Flame took advantage of WPAD, a little-known magical hostname (http://en.wikipedia.org/wiki/Web_Proxy_Autodiscovery_Protoco...) to do MITM attacks on the Windows Update servers.

Flame then installed 'WuSetupV.exe' with the description "Desktop Gadget Platform" "Allows you to display gadgets on your desktop".

What's amazing is that Windows Update doesn't require explicit validation of an update-only certificate chain. It seems like any certificate from the Microsoft root can certify updates (!).

Re: The Microsoft Update mechanism has been used to spread malware

#33
post #7

Oh look, another scaremongering and purposely misleading article from F-Secure. This is starting to become a regular thing isn't it; I guess the recession must have hit them particularly hard.

I actually feel Mikko & the folks at f-secure are very good at explaining things to people who aren't everyday "virus fighters," but i felt the exact same way you did (like they were scaremongering) when they said "The Nightmare Scenario."

I'm on the fence about this issue, honestly. Part of me feels like they believe passionately that we're stepping into new, dangerous territory. The other part of me indeed feels like this is great advertising for not only them, but their industry (And they're going to push it all they can).

But the fact of the matter is they admit they can't protect you, whoever you are, from these types of targeted attacks. I've seen well respected speakers from Defcon go back and forth with Mikko on Twitter about the efficiency of AV.

It sucks you're (the parent) being downvoted but this is an issue, what with the incredible amount of FUD that comes with every serious attack.

EDIT: My mistake in misspelling Mikko's name. Sorry about that.

Re: The Microsoft Update mechanism has been used to spread malware

#34
post #33
post #7

Oh look, another scaremongering and purposely misleading article from F-Secure. This is starting to become a regular thing isn't it; I guess the recession must have hit them particularly hard.

I actually feel Mikko & the folks at f-secure are very good at explaining things to people who aren't everyday "virus fighters," but i felt the exact same way you did (like they were scaremongering) when they said "The Nightmare Scenario." I'm on the fence about this issue, honestly. Part of me feels like they believe passionately that we're stepping into new, dangerous territory. The other part of me indeed feels li…

Mikko, Mikko Hyponnen. Not "Mykko".

Re: The Microsoft Update mechanism has been used to spread malware

#35
post #17
post #12

Earlier quoted context omitted.

And here come the shills, one or perhaps two at a time to defend the article from any critique. I'm afraid I've grown bored of this dance, entertaining as it may have been I've become listless.

yeah, shills. sure. no way you're getting downvoted for spreading FUD and then exolicitly refusing to back it up. Nope. Must be shills.

The dude's comment history is hilariously shilly.

Re: The Microsoft Update mechanism has been used to spread malware

#36
post #20

Earlier quoted context omitted.

The same would happen on ubuntu if someone steals the repository keys. This has nothing to do with copy protection.

Yes. But you can always get the source and build the package yourself. Can you do that with Windows?

Yes but some one can break into whatever server is hosting the source and add a backdoor withought anyone noticing for quite a while, do you go through all the code you compile? Can't think of any specific examples right now but i remember this happening a few times

Re: The Microsoft Update mechanism has been used to spread malware

#38
post #34
post #33

Earlier quoted context omitted.

I actually feel Mikko & the folks at f-secure are very good at explaining things to people who aren't everyday "virus fighters," but i felt the exact same way you did (like they were scaremongering) when they said "The Nightmare Scenario." I'm on the fence about this issue, honestly. Part of me feels like they believe passionately that we're stepping into new, dangerous territory. The other part of me indeed feels li…

Mikko, Mikko Hyponnen. Not "Mykko".

I believe it's Hyppönen, but Muphry's Law will probably strike me also ;)

Re: The Microsoft Update mechanism has been used to spread malware

#39
post #34
post #33

Earlier quoted context omitted.

I actually feel Mikko & the folks at f-secure are very good at explaining things to people who aren't everyday "virus fighters," but i felt the exact same way you did (like they were scaremongering) when they said "The Nightmare Scenario." I'm on the fence about this issue, honestly. Part of me feels like they believe passionately that we're stepping into new, dangerous territory. The other part of me indeed feels li…

Mikko, Mikko Hyponnen. Not "Mykko".

[deleted]

Re: The Microsoft Update mechanism has been used to spread malware

#40
> I guess the good news is that this wasn't done by cyber criminals interested in financial benefit. They could have infected millions of computers. Instead, this technique has been used in targeted attacks, most likely launched by a Western intelligence agency.

You mean the bad news.

Post reply on HN