Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

11–20 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#11
post #7

How does > When exploited, the vulnerability allows an attacker to remotely execute arbitrary code go along with > [...] will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it [...] Is this a fucking joke? Looks like some company just want to push their name out there and get some free media exposure.

From the article: The vulnerability exists because Windows allows the OLE packager (packager .dll) to download and execute INF files. In the case of the observed exploit, specifically when handling Microsoft PowerPoint files, the packagers allows a Package OLE object to reference arbitrary external files, such as INF files, from untrusted sources.

So the process is initiated through a spearphish, and when the file is opened the vulnerability causes the system to download additional code and execute it.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#12
This exploit is delivered with a PowerPoint document, so no remote hole. It's a bit strange, that the reference a CVE (for which no information is available) and just generically describe the campaign and whatnot. The real report though is only available after a registration? That's not really the way things should be done. If there is a threat, inform people about it and don't hide all the stuff.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#13
post #6

Is it me or is the linked article remarkably content free given the about of security babble it contains? The nice aspect of the Heartbleed branding was its simple and clear message, not having opaque sentences such as "Visibility into this campaign indicates targeting across the following domains" and self serving platitudes such as "As part of our normal cyber threat intelligence operations, iSIGHT Partners is trac…

I guess it is actually about the context in this case, not about the issue itself. Exploits via outlook and office existed for a long time. This is hardly something new. Targeting a specific region / company / group of people, based on politics, without spamming everyone in the world with this vulnerability is a relatively new thing. It looks like they really did want to stay hidden for a long time.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#14
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

And their map suggests that poland is in the middle of russia. What the hell.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#15
post #6

Is it me or is the linked article remarkably content free given the about of security babble it contains? The nice aspect of the Heartbleed branding was its simple and clear message, not having opaque sentences such as "Visibility into this campaign indicates targeting across the following domains" and self serving platitudes such as "As part of our normal cyber threat intelligence operations, iSIGHT Partners is trac…

It says basically nothing. It gives a CVE (for which no information is available) and says the exploit was used with PowerPoint documents, that's it.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#17
but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it

What's next, "Zero-day Impacting All Versions of All Operating Systems - allows users to download and execute arbitrary code"? I suppose if you're a fan of user-hostile walled-garden trusted-computing models you might consider that a vulnerability, but I think it's safe to assume that most people consider the ability to "download and execute arbitrary code" to be a very useful and fundamental feature of an OS.

from Vista SP2 to Windows 8.1

I'm curious if this "vulnerability" also exists in XP.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#18
post #4

> An attacker can exploit this vulnerability to execute arbitrary code but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it So, it's a remote exploit, but requires the user to open a document.

Maybe I'm reading into details too much, but they never said "open". They said: "specifically when handling Microsoft PowerPoint files". Outlook allows previews of office files and "handling" may be involved even before the presentation is actually opened / previewed. It's just speculation though.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#19

but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it What's next, "Zero-day Impacting All Versions of All Operating Systems - allows users to download and execute arbitrary code"? I suppose if you're a fan of user-hostile walled-garden trusted-computing models you might consider that a vulnerability, but I think it's safe to assume that…

Don't forget to spice up your report with "THE RUSSIANS DID IT!!!!!!!!!!111!1".

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#20
post #10
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission.

Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.

Post reply on HN