Live data from Hacker News

Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon

github.com

61–63 of 63 posts

Re: Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon

#61
post #3

Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant (the same target of the cyber-weapon) as I listened to the audio book[2] based on this ~12 years ago, entirely changed how I viewed critical industrial infrastructure. One quote from the book that stuck with me was how you can only use a cyber weapon once at full potential, as…

[flagged]

Re: Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon

#62
post #36

Earlier quoted context omitted.

Where did the binaries come from? Did Iran release them?

From what I recall reading, stuxnet itself was found in the wild. Even though it was certainly created for a specific target. That’s how security researchers were able to study it fairly quickly. So the binaries were already out there to pull from other infected systems.

Can confirm. I was working in Azerbaijan with people from Iran at the time and had it infect my pendrive and work PC. No anti-virus picked it up at the time.

Re: Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon

#63
post #3

Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant (the same target of the cyber-weapon) as I listened to the audio book[2] based on this ~12 years ago, entirely changed how I viewed critical industrial infrastructure. One quote from the book that stuck with me was how you can only use a cyber weapon once at full potential, as…

Important to note that the system(s) it infected were non-trivially air-gapped, so it had to do the entirety of it's infectious work without command and control servers or receiving any additional input. It had to be an entirely autonomous process from infection to propagation to execution. Pretty amazing to have been pulled off seemingly so successfully.

[dead]
Post reply on HN