Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

161–170 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#161
post #141

I'm afraid that this attack demonstrates that the old PC architecture: Side-loading any app, userspace, privilege escalation, low level file sharing functionality just isn't for purpose. If malware can exploit a 0-day, 100-day, 1000-day security hole in a corporate network of 2000 machines, its too easy for that malware to share itself across the network and send emails attachments to AllUsers (every single company I…

It's clear that nothing bad can happen on a machine where you can't do anything.

Re: Another Ransomware Outbreak Is Going Global

#162

Earlier quoted context omitted.

I sent my first packet-of-death to an unprotected Windows machine in 1996, so...

1997 here :-) hat was that XP xploit app from back then... I cant recall what it was called...

teardrop?

Re: Another Ransomware Outbreak Is Going Global

#164
post #79
post #75

Can someone provide a simple (but not overly so) explanation of how the current generation of ransomware operate i.e., A) spread and B) lock up the computer? Does it always require human intervention for A. ? Thank you.

Depends on The ransomware. Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet

"0-day" does not mean without human intervention. That just means "previously undisclosed".

Re: Another Ransomware Outbreak Is Going Global

#165

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

It's always seemed like the best way to end ransomware is to launch hundreds of variants that demand money but don't actually decrypt anything. Unethical, to be sure, but eventually people would learn not to give them money.

All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.

Re: Another Ransomware Outbreak Is Going Global

#166
post #85
post #59

Earlier quoted context omitted.

Probably via their smart phones

So a smartphone is not a computer anymore? The world we live in..

A smartphone is not a computer any more than your electric toothbrush, which happens to have a CPU and Bluetooth for whatever reason, is a computer.

In this context "computer" means "desktop computer" or "laptop computer".

Re: Another Ransomware Outbreak Is Going Global

#167

Earlier quoted context omitted.

There is no proof of means or motivation to use 0-days at scale. In fact, using EternalBlue "at-scale" would have caused it to not stay a 0-day for very long.

That's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment. If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.

Any use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.

Re: Another Ransomware Outbreak Is Going Global

#169

Earlier quoted context omitted.

Yeah, and the Department of Defense is capable of nuking major cities. And it's about as relevant to this discussion.

It's relevant because it's like the nukes were stolen and that it will continue to happen

I'd argue its relevant because you can't CTRL+C CTRL+V a nuke.

Re: Another Ransomware Outbreak Is Going Global

#170

FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)

English version: https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa...
Post reply on HN