Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

21–30 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#21

but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it What's next, "Zero-day Impacting All Versions of All Operating Systems - allows users to download and execute arbitrary code"? I suppose if you're a fan of user-hostile walled-garden trusted-computing models you might consider that a vulnerability, but I think it's safe to assume that…

Kinda depends under what level of privilege the code runs.

Also secure environments often strip down the ability to download and run arbitrary code, but might still allow theoretically-data-only formats to be downloaded and opened (such as .ppt files), in which case this is definitely relevant.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#25
post #10
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

It also helps spreading the news and thus fixing the problem.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#26

but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it What's next, "Zero-day Impacting All Versions of All Operating Systems - allows users to download and execute arbitrary code"? I suppose if you're a fan of user-hostile walled-garden trusted-computing models you might consider that a vulnerability, but I think it's safe to assume that…

I'm curious if this "vulnerability" also exists in XP

I was curious as well. Elsewhere the article says it's not vulnerable:

...a zero-day vulnerability impacting all supported versions of Microsoft Windows (XP is not impacted)

Are there any significant Windows vulnerabilities for XP since the EOL? I was waiting for the first one that isn't patched, will be interesting to see how the bad guys use it.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#27
I'm a little annoyed that they called it worm. Malware with the description meant that the software could spread entirely under its own power from machine to machine. This is nothing more than your typical email attachment exploit which is entirely incapable of spreading without human intervention for each attacked host.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#28
post #10

Earlier quoted context omitted.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.

Unfortunatly, it is not really new. It was already the case in the Windows 98/XP-era when the antivirus business started to grow quickly.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#29
post #25
post #10

Earlier quoted context omitted.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

It also helps spreading the news and thus fixing the problem.

Until the scare-tactics wear off and fancy names for vulnerabilities no longer trigger my "this is big" response.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#30
post #4

> An attacker can exploit this vulnerability to execute arbitrary code but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it So, it's a remote exploit, but requires the user to open a document.

Maybe I'm reading into details too much, but they never said "open". They said: "specifically when handling Microsoft PowerPoint files". Outlook allows previews of office files and "handling" may be involved even before the presentation is actually opened / previewed. It's just speculation though.

It says "to convince a user to open it" in the description. If a preview was enough to execute, I'd think that is very important point and they'd definitely mention it - I remember distinctly "previews are sufficient" mentioned in the WMF exploit when it first came out.
Post reply on HN