Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

201–210 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#201
post #65

Earlier quoted context omitted.

Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…

> But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to security exploits even after they've been disclosed and patched. You are correct about this. Patches were released in March, but many seem to have put off security-critical patching.

> Patches were released in March, but many seem to have put off security-critical patching.

In fairness to some of the unpatched - the last round of Windows 10 updates refused to install on some machines (well, mine and some others on Twitter), and trapped me in an endless loop of download-install-fail-download. When this happened my landline internet was down, so this was happening over 4G tethering, and burning up $20/day in cellphone data until I just turned off my internet/tethering.

I'm not saying don't patch (you should!), just that even people trying to stay patched and do the right thing can find they're unable to do so.

Re: Another Ransomware Outbreak Is Going Global

#202
post #149
post #61

Earlier quoted context omitted.

"Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised." March 14 of what year ? I would say 2000 but I am open to discussion ...

People who don't run Windows shouldn't get cocky! There are many, many attacks on Linux: Here's one in the news from just last week. A ransomware where the victim agreed to pay the equivalent of US$1MM in bitcoin. https://arstechnica.com/security/2017/06/web-host-agrees-to-...

That would be akin to running Windows XP. People running Anfient Monftrosities should not get cocky in general, attacks on old systems are only getting worse with time.

Re: Another Ransomware Outbreak Is Going Global

#203

Idea: What if the purpose of these WannaCry style ransomware attacks isn't to get people to pay in Bitcoin, but to drive up the price of Bitcoin?

WannaCry caused the price to drop, rather sharply. If anything, the purpose would be to buy cheap Bitcoins and hope the price later corrects back upwards after the news has blown over. I suspect the price drop is due to some trading algorithms using sentiment analysis. They see all the negative press around these ransomware, see the included word Bitcoin, assume the negative article is about Bitcoin, and automaticall…

It would certainly have a cascading effect, however, because the news soon follows about Bitcoin/all crypto dropping and both bots and watchful traders take their profits out and either get scared out of the market, or hope to capitalize on the dip.

Re: Another Ransomware Outbreak Is Going Global

#206
post #135

Does anyone know if any tools exist on Linux which can be used for early detection of ransomeware? Something that monitors file access, disk activity, etc. for suspicious behavior and can trigger some action or alert? I think I remember some discussion about using a 'canary file' - some innocent looking file with known contents which should never be modified. If a modification is detected, you know something fishy is…

Aide is a popular utility to monitor for changes to files on Linux systems. http://aide.sourceforge.net You could also use the built in audit subsystem if you wanted to watch a specific canary file, directory, filesysyem, etc. https://www.linux.com/learn/customized-file-monitoring-audit...

I thought tripwire was the standard.. happy to know another name.

Re: Another Ransomware Outbreak Is Going Global

#208

Earlier quoted context omitted.

> But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to security exploits even after they've been disclosed and patched. You are correct about this. Patches were released in March, but many seem to have put off security-critical patching.

> Patches were released in March, but many seem to have put off security-critical patching. In fairness to some of the unpatched - the last round of Windows 10 updates refused to install on some machines (well, mine and some others on Twitter), and trapped me in an endless loop of download-install-fail-download. When this happened my landline internet was down, so this was happening over 4G tethering, and burning up…

You are absolutely correct, people are even still wary after the aggressive Windows 10 update tricks, so it is extremely unfortunate yet does make some sense.

I hope Microsoft can find a way to earn trust back, this problem is going to get much worse if people do not install security patches ASAP when released.

Re: Another Ransomware Outbreak Is Going Global

#209

Earlier quoted context omitted.

Because now we can watch those funds and know how much money they made, we can watch them to see if they make a mistake. If every address was different we'd have no idea how much money they're making and only funds paid by people who also reported them would be tainted by the long eyeball of the law.

It does not seem like something wrong directly. I also think showing off might be intention.

They should have pre-loaded more onto the wallet to give the impression that most people are paying.

Less than £10K USD gives the impression that nobody is paying.

It is the same psychology as a product only getting a couple of two star reviews - you don't buy it, you go for the product with hundreds of 4-5 star reviews instead.

Re: Another Ransomware Outbreak Is Going Global

#210
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

The article doesn't say that it's using a 0-day vulnerability, nor does it say the NSA is involved.
Post reply on HN