Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

141–150 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#141
I'm afraid that this attack demonstrates that the old PC architecture: Side-loading any app, userspace, privilege escalation, low level file sharing functionality just isn't for purpose.

If malware can exploit a 0-day, 100-day, 1000-day security hole in a corporate network of 2000 machines, its too easy for that malware to share itself across the network and send emails attachments to AllUsers (every single company I've worked for still allow Everyone to send anything to Everyone).

Microsoft's next XP patch should be to remove SMB functionality or just outright disable it (and probably remove IE and other nonsense installed by default too).

And when Windows 7 expires the final patch should be a severe lock down too..

Re: Another Ransomware Outbreak Is Going Global

#142

On a related note, I don't understand the reason behind transactions like this: https://blockchain.info/tx/9778c698f3f2a2c9b9e9f0fdea3c96e8f... Is there something special about using numerous senders like that?

That just means someone's got a wallet containing the private keys corresponding to a lot of addresses. So when they want to move some coins, they just sign all the various transactions and send the money to new addresses.

Re: Another Ransomware Outbreak Is Going Global

#143

Earlier quoted context omitted.

Yeah, and the Department of Defense is capable of nuking major cities. And it's about as relevant to this discussion.

Everyone would notice a nuclear attack. NSA exploiting vulnerabilities to their own ends, not so much.

This is absolutely detectable, and IDS signatures already exist for EternalBlue (Let alone the fact that it was patched by Microsoft in March).

Re: Another Ransomware Outbreak Is Going Global

#144

Does anyone know if any tools exist on Linux which can be used for early detection of ransomeware? Something that monitors file access, disk activity, etc. for suspicious behavior and can trigger some action or alert? I think I remember some discussion about using a 'canary file' - some innocent looking file with known contents which should never be modified. If a modification is detected, you know something fishy is…

Tripwire is the archetype, it's been around for over 15 years.

https://en.wikipedia.org/wiki/Open_Source_Tripwire

Re: Another Ransomware Outbreak Is Going Global

#145
post #65
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…

> But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to security exploits even after they've been disclosed and patched.

You are correct about this. Patches were released in March, but many seem to have put off security-critical patching.

Re: Another Ransomware Outbreak Is Going Global

#146
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

> All of the affected companies' should be considered compromised by the NSA.

Which is ironic seeing as the ransomware, like WannaCry, is using the NSA supplied 'EternalBlue' exploit.

Re: Another Ransomware Outbreak Is Going Global

#147

Earlier quoted context omitted.

Distrusting Windows was the wisest thing you did since you climbed off your horse. [1] No, seriously. How is it paranoia to think the NSA was/is surveilling your Windows installation if we already have proof that they have the means [2] and motivation [3] to do it at scale? [1] http://www.quotes.net/show-quote/34121 [2] https://en.wikipedia.org/wiki/EternalBlue [3] https://en.wikipedia.org/wiki/PRISM_(surveillance_pr…

There is no proof of means or motivation to use 0-days at scale. In fact, using EternalBlue "at-scale" would have caused it to not stay a 0-day for very long.

That's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment.

If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.

Re: Another Ransomware Outbreak Is Going Global

#148
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

[deleted]

Re: Another Ransomware Outbreak Is Going Global

#149
post #61
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

"Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised." March 14 of what year ? I would say 2000 but I am open to discussion ...

People who don't run Windows shouldn't get cocky! There are many, many attacks on Linux:

Here's one in the news from just last week. A ransomware where the victim agreed to pay the equivalent of US$1MM in bitcoin.

https://arstechnica.com/security/2017/06/web-host-agrees-to-...

Re: Another Ransomware Outbreak Is Going Global

#150

Earlier quoted context omitted.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

This is absurd nonsense, but my viewpoint is a lonely one on HackerNews.

It makes sense if you consider that some folks will only read headlines and potentially skim news coverage without checking any further into validity.
Post reply on HN