This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.
Another Ransomware Outbreak Is Going Global
171–180 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#172Earlier quoted context omitted.
There is no proof of means or motivation to use 0-days at scale. In fact, using EternalBlue "at-scale" would have caused it to not stay a 0-day for very long.
That's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment. If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.
Re: Another Ransomware Outbreak Is Going Global
#173Earlier quoted context omitted.
Depends on The ransomware. Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet
> Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet That's not at all what a 0-day means, it just means a previously unknown vulnerability. We've never seen a ransomware attack anywhere close to as sophisticated at Stuxnet. This latest attack is nothing new and is only affecting people who haven't kept their systems up to date.
Please don't assume I don't know what 0-day actually means. I chose my words carefully as not not imply that I was saying the definition of the term.
Re: Another Ransomware Outbreak Is Going Global
#174Earlier quoted context omitted.
Yep, forced updates + NSL = they don't need 0days anymore.
That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.
https://twitter.com/craiu/status/879690795946827776
>only "this could possibly happen" theories
Pre-Snowden a lot of things had been considered "could possibly happen" tinfoil hat theories, turned out a lot of them had not been mere theories.
Re: Another Ransomware Outbreak Is Going Global
#175Earlier quoted context omitted.
Depends on The ransomware. Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet
"0-day" does not mean without human intervention. That just means "previously undisclosed".
Typically when we see news using the term 0-day it's because there was no human element needed in the infection of machines. Thinking back in recent memory (17~ years) I can't remember a time when 0-day was used when it didn't mean autonomous infection.
Although. I fully understand that the term means that it's a previously unknown issue. Which is why I chose my words as carefully as I did.
Re: Another Ransomware Outbreak Is Going Global
#176Earlier quoted context omitted.
Probably via their smart phones
Is it common to have a list of every employee's mobile phone? I would guess a lot of firms just have informal lists of phone numbers held by managers and colleagues. Plus if there was a list, wouldn't it be on a computer that's currently off?
Re: Another Ransomware Outbreak Is Going Global
#177Earlier quoted context omitted.
Distrusting Windows was the wisest thing you did since you climbed off your horse. [1] No, seriously. How is it paranoia to think the NSA was/is surveilling your Windows installation if we already have proof that they have the means [2] and motivation [3] to do it at scale? [1] http://www.quotes.net/show-quote/34121 [2] https://en.wikipedia.org/wiki/EternalBlue [3] https://en.wikipedia.org/wiki/PRISM_(surveillance_pr…
There is no proof of means or motivation to use 0-days at scale. In fact, using EternalBlue "at-scale" would have caused it to not stay a 0-day for very long.
Re: Another Ransomware Outbreak Is Going Global
#178Maybe this is the year of Linux on desktop.
(You may or may not be joking; let's assume you're not for this response.) This is a dangerous argument. I'm a free software activist, and I firmly believe that security without free software is a facade, but that doesn't mean that free software is more always more secure; it's an open source argument that's been fairly easily refuted lately with high-profile bugs in software like OpenSSL. It's easier to hide secrets…
So while indeed, open source is not a guarantee for better security, the results are in its favor. It might also be because it's not such an attractive target to hackers due to its low share in the desktop market. But still there millions of linux servers online 24h/24h and I assume they have a bigger potential for monetisation.
Re: Another Ransomware Outbreak Is Going Global
#179Earlier quoted context omitted.
That would never happen. A network tap would be able to detect a malicious update even if the main PC was implanted very well, and a Microsoft-signed malicious update would be worldwide news. Please correct me if I am wrong, but I don't think there has ever been a single instance of this actually occurring, only "this could possibly happen" theories. I am definitely interested to hear more if this is not the case.
>a Microsoft-signed malicious update would be worldwide news https://twitter.com/craiu/status/879690795946827776 >only "this could possibly happen" theories Pre-Snowden a lot of things had been considered "could possibly happen" tinfoil hat theories, turned out a lot of them had not been mere theories.
1. That screenshot clearly shows the certificate is being treated as not valid. I assume it is being shared for IOC purposes.
2. I am referring to a software update, in the context of revmoo's "forced updates + NSL" comment.
> Pre-Snowden a lot of things had been considered "could possibly happen" tinfoil hat theories, turned out a lot of them had not been mere theories.
I could believe that is the case for those outside of the information security community, but nothing novel/tinfoil-hat-worthy was in the leaks, just confirmations of predictable sources/methods used for intelligence gathering and CNE work. Forcing a company to issue a blessed update containing malicious code is very different, and again, I am very interested to hear of any proof of such a thing occurring without detection (It doesn't seem possible for that to happen without it being detected and being discussed very loudly).
Re: Another Ransomware Outbreak Is Going Global
#180Earlier quoted context omitted.
Something to keep in mind. They were running: Apache version 1.3.36 and PHP version 5.1.4 It's not like a brand new Ubuntu installation connected to the open Internet will suddenly be pwned. The owners of this company were beyond inept.
Seeing Apache 1 in the wild makes me a bit nostalgic. What kind of utter lunatic would use that for their company today?