Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

31–40 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#31
I think another (real) windows zero day will be announced soon. I received an email from Rackspace giving advanced notice that they will be patching all Windows servers to fix a 0day. I'm not sure why they'd take such measures for an exploit involving opening powerpoint files...

Content of the email, for those interested: http://pastebin.com/AZBcQ2DF

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#34
post #31

I think another (real) windows zero day will be announced soon. I received an email from Rackspace giving advanced notice that they will be patching all Windows servers to fix a 0day. I'm not sure why they'd take such measures for an exploit involving opening powerpoint files... Content of the email, for those interested: http://pastebin.com/AZBcQ2DF

Pretty sure this is about this CVE.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#35
post #34
post #31

I think another (real) windows zero day will be announced soon. I received an email from Rackspace giving advanced notice that they will be patching all Windows servers to fix a 0day. I'm not sure why they'd take such measures for an exploit involving opening powerpoint files... Content of the email, for those interested: http://pastebin.com/AZBcQ2DF

Pretty sure this is about this CVE.

But I expect most servers don't have any software on them related to opening emails or Office files. I would've thought that Rackspace reserves mandatory server hotfixes for only the most serious vulnerabilities (E.G. shellshock).

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#36

Earlier quoted context omitted.

Maybe I'm reading into details too much, but they never said "open". They said: "specifically when handling Microsoft PowerPoint files". Outlook allows previews of office files and "handling" may be involved even before the presentation is actually opened / previewed. It's just speculation though.

It says "to convince a user to open it " in the description. If a preview was enough to execute, I'd think that is very important point and they'd definitely mention it - I remember distinctly "previews are sufficient" mentioned in the WMF exploit when it first came out.

Thanks, I missed that bit!

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#37

I'm a little annoyed that they called it worm. Malware with the description meant that the software could spread entirely under its own power from machine to machine. This is nothing more than your typical email attachment exploit which is entirely incapable of spreading without human intervention for each attacked host.

I think they're calling the described Russian group 'Sandworm', not this particular CVE.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#38
post #35
post #34

Earlier quoted context omitted.

Pretty sure this is about this CVE.

But I expect most servers don't have any software on them related to opening emails or Office files. I would've thought that Rackspace reserves mandatory server hotfixes for only the most serious vulnerabilities (E.G. shellshock).

Why not? Automated document processing, hosted desktop, and a few other ideas come to mind where the server would be affected.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#39
post #10

Earlier quoted context omitted.

This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.

Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.

I do see your point, however sometimes it is a good thing to let everyone know about it, so they're able to do something about it.

For example, my manager even heard about "shell shock" and prompted me to do something about it. Although, it was over a week after the outbreak, and we'd already established we weren't vulnerable (applied the patch anyway) - but even so!

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#40
post #3

Can't believe they designed a logo especially for this worm (and gave a fancy name). There's apparently a marketing campaign in vulnerability discoveries too.

I wonder if it's someone's job to come up with these titles and logos?
Post reply on HN