Earlier quoted context omitted.
http://www.phenoelit.org/stuff/cd00r.c
But it still need root or CAP_NET_RAW?
Powerful, highly stealthy Linux trojan may have infected victims for years
71–80 of 103 posts
Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#72Details via: https://securelist.com/blog/research/67962/the-penquin-turla... Notably, the C&C domain has been sinkholed by Kaspersky. This has been linked to the complex "Turla" industrial espionage malware, as it shares a C&C server. (Turla: http://securelist.com/analysis/publications/65545/the-epic-t... )
MiniDuke in turn screams Russia in its target selection and spear phishing related to the Ukrainian bid to join NATO.
Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#73Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#74Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#75I can't shake the feeling that current security measures are designed in the wrong way. Antiviruses are fundamentally flawed (blacklist instead of whitelist; mostly curing instead of preventing). Filtering traffic is difficult (it is relatively easy to hide information in heavy legitimate traffic). Maybe the way ahead is in ensuring that files (and images in memory, flash,...) don't get changed. Maybe we should have…
The problem is that we currently rely on user discretion. Users are really bad at preventing malware from infecting their system. We can do some things, sure -- sandboxing by default, etc. But when it comes down to it, if the user is able to click an 'allow access to my banking information' button, then that user will be getting screwed. The only response I can think of is taking that power out of the hands of the us…
Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#76Earlier quoted context omitted.
That's been successful enough in the past that there's a strong selective pressure for malware to look more like legitimate traffic. How much time are you going to spend reviewing each HTTPS request made to an EC2 IP address? Similarly, if that works, there's zero chance that a large vendor won't use the same endpoint for software updates, advertising and activity tracking, etc. to make filtering impossible.
I don't dispute that malware is incentivised to look like legitimate traffic. I wanted to respond to your comment about vendors using one endpoint to inhibit filtering. They have as much freedom to do this as I do to deny them any internet access if they do. If the product does not operate as advertised in light of this, it will be promptly returned to the retailer. Also, good filtering isn't based on an IP address a…
I support this in principle but it really needs regulatory reform: it's hard or impossible return opened software or a device when the manufacturer changes their policies a year after you bought it. That latter point is becoming more relevant as we increasingly see computers deeply integrated into expensive devices with long service lifetimes. Just wait until a car manufacturer pushes out one of those combined “security fixes and new terms of service / we collect your personal data” patches and you're faced with living with problems, suing, or clicking Accept and hoping you'll have better options in a few years when you're looking for a new car.
> Also, good filtering isn't based on an IP address alone but that's splitting hairs. Yes it is time consuming but I argue privacy isn't free, it must be protected and defended, we all have to find the medium we are happy with.
That's a worthy sentiment but I think it's a losing game because at its root it's a social problem. It's going to be a tough battle as long as companies have very limited regulation for collecting personal information, the ability to unilaterally change service terms after purchase with no right to compensation, and – particularly critical – no penalty for security failures except in rare cases where an expensive lawsuit succeeds.
(That wouldn't directly affect outright malware but corporate responsibility would increase the incentives to take security more seriously than most companies have in the past)
Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#77So it might not have? And they're not sure? And "at least one" means it might only be one.
All this makes me highly suspicious of the article.
Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#78It's a userland trojan and it's "one of the most complex APTs in the world"? One wonders what these people would think if they found MosDef in the wild.
I believe they mentioned the fact it couldn't be detected by netstat as an example of it's sophistication. idk how this got 127 upvotes.
Re: Powerful, highly stealthy Linux trojan may have infected victims for years
#79> Even a regular user with limited privileges can launch it, allowing it to intercept traffic and run commands on infected machines. Huh, how do they do that? > The underlying executable file is written in the C and C++ languages and contains code from previously written libraries, a property that gives the malicious file self-reliance. Does that mean something? I don't get it. I thought arstechnica usually was writt…
>> Even a regular user with limited privileges can launch it, allowing it to intercept traffic and run commands on infected machines. >Huh, how do they do that? They must have some pretty powerful zero-day vulnerability they're exploiting. Expect patches.
"The trojan is able to run arbitrary commands even though it requires no elevated system privileges"
This is just a terribly written article. Few if any tech details, and any tech language just doesn't make sense/contradicts itself.
Sadly The this is another example of a larger downward trend in the quality of articles on Ars. They should use some of that sweet Conde Nast money and clone John Siracusa a few times!