Earlier quoted context omitted.
From your source: "Customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March. If customers have automatic updates enabled or have installed the update, they are protected. For other custome…
If you or your IT dept is not installing updates, especially security patches, over 2 months after they come out, somethings horribly wrong.
WannaCry – New Variants Detected
151–160 of 164 posts
Re: WannaCry – New Variants Detected
#152Earlier quoted context omitted.
WannaCry ("the attack") didn't target Windows 10 installations (probably since most Win10 users have updates enabled), but Windows 10 is still vulnerable without the patch.
Again, where is the source? I seriously doubt that the worm author would let go such a profitable target if they can infect Windows 10. According to this: https://www.netmarketshare.com/operating-system-market-share... Windows 10 has almost 4 times users than XP (and supposedly the gap is growing larger)
Re: WannaCry – New Variants Detected
#153Earlier quoted context omitted.
If it's not registerable it's not functional as a kill switch?
It's not supposed to be a kill switch. (Even though it works as one.) The domain check is there to detect whether the infection is running in a sandbox environment. If the domain check succeeds, it assumes it's being analyzed and aborts. Or at least that's the prevailing theory.
Re: WannaCry – New Variants Detected
#154Earlier quoted context omitted.
If you or your IT dept is not installing updates, especially security patches, over 2 months after they come out, somethings horribly wrong.
The reality is, this is very common.
Re: WannaCry – New Variants Detected
#155Earlier quoted context omitted.
My guess is this is why we're seeing multiple bitcoin addresses: The original authors first released it with their own bitcoin address. It then spreads p2p around the world wherever it can to front-facing PCs. Then 3rd-party spearfishers are sending it to corporate networks with their own bitcoin address so they can get the credit for getting past/through firewalls.
If the payment goes to them instead of the original authors, how could the new hijackers of the virus offer to decrypt the data? I'd assume only the original authors have access to the private keys needed for that. If someone was really clever they could change the Tor addresses it talks to for command & control and write their own complete replacement backend, but at that point it seems like you'd be looking at peop…
Re: WannaCry – New Variants Detected
#156> A new variant with no kill-switch recovered by Kaspersky as a virustotal.com upload — not detected in the Wild. Uploaded to virustotal MEANS found in the wild. That's what admins do when they discover things.
I don't know if this one was detected in the wild or not (99% chance it was), however, malware authors occasionally use Virustotal too.
Re: WannaCry – New Variants Detected
#157Earlier quoted context omitted.
"older Windows versions" Win 10 is vulnerable without the patch that came out in march.
>Win 10 is vulnerable without the patch that came out in march Microsoft clearly disputes this in their own posts on the subject. https://blogs.technet.microsoft.com/msrc/2017/05/12/customer... "Customers running Windows 10 were not targeted by the attack today." What's your source?
Re: WannaCry – New Variants Detected
#158What's special about WannaCry that has made this such a widespread thing? I presume there's has been plenty of malware for a while that can propagate itself around a network of unpatched old Windows machines and people have been trying to get users to clicks on emails to infect themselves for years. So why now? What's so special now?
Basically, this is a successful old-fashioned computer worm, operating at a scale we've not seen for more than 10 years. On modern operating systems most attack surfaces that were easy to crack in the past have been locked down at least to the point where it is nearly impossible to find an exploit in a common protocol like this that doesn't require user interaction (hence the popularity of phishing). Apart from that…
Re: WannaCry – New Variants Detected
#159What's special about WannaCry that has made this such a widespread thing? I presume there's has been plenty of malware for a while that can propagate itself around a network of unpatched old Windows machines and people have been trying to get users to clicks on emails to infect themselves for years. So why now? What's so special now?
I think it's because it's cool to use the word "cyber" now in the news. It makes news outlets appear edgy and with it. Infact these cyber attacks are nothing new, and have been an ongoing problem for organizations like the NHS, the only difference being there is a remarkable uptick in the scale of the attack. The reason it stands out is because it's a cluster, instead of a slow, trickling problem for the NHS and other organizations.
> What's so special now?
The sophistication and worm capabilities. Were it not for the Shadowbrokers leak, small time malware authors had to use tired old strains of malware to spread. Now they can draw upon the vast arsenal of the Shadowbrokers leak and appear like state actors, which they are not.
If anything, the leaks were a blessing, because now we can mitigate against such attacks. NSA's mantra 'NOBUS' (No-one-but-us) does not apply here.
Re: WannaCry – New Variants Detected
#160Earlier quoted context omitted.
The reality is, this is very common.
Then what, realistically, can be done when nation-state knowledge of vulnerable systems is hoarded for cyber-warfare purposes?
Laws must be passed to:
* Force the US government to report vulnerabilities to vendors
* Create a regulatory body to monitor the use of vulnerabilities in clandestine operations and ensure that mandatory reporting is upheld
I cannot see anything less working.
Get that through US and EU governments, and you'll likely have the vast majority of vulnerabilities being reported and patched.
Of course this is akin to asking the US and Russia to convert their nuclear stockpile into reactor fuel.