Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

411–420 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#411

Earlier quoted context omitted.

Wait, the hardness of information security comes because it has to be built-in everywhere since everything is connected and so everything is a potential attack surface. It's not impossible but it requires a somewhat universal attitude change.

I want to agree with you in principle, but in practice it's not possible to be secure with just an attitude change. The attack surfaces have grown too large. Keeping track of all possible vectors is a full-time job in itself. You either need a dedicated security person or regular pentests. And honestly, regular pentests are probably more effective. It's a positive statement though: it is possible to be constantly sec…

> Big companies can even afford to make it a requirement of their release cycle.

Oh man. I have a peer who works for a very large international company. They require pentests in their release cycle. What could go wrong?

Turns out that pentesting isn't in the final portion of their release. They tag a release candidate (e.g. v5.7.0-rc), send that build to the pentesters, then fix other integration and user-acceptance bugs while the pentesters are working. The pentesters may greenlight v5.7.0-rc when it's really v5.7.3-rc that's shipping, and the pentesters are none the wiser.

Security only works when the culture supports it.

Re: Another Ransomware Outbreak Is Going Global

#412

Earlier quoted context omitted.

>will hopefully make people learn to distrust ransomware, in turn making it less lucrative. Ransomware will never ever not be lucrative. Preventing people from getting their data back doesn't discourage future campaigns and primarily hurts the victims of the ransomware.

[citation needed]

Seriously? The whole idea is so fundamentally stupid.

1) Ransomware authors have obvious economic incentive to decrypt, and no reason not to. This makes it a herculean task to convince the general public that they wouldn't do so.

2) By the time your data is encrypted, you'll be researching your specific ransomware strain and will find out if it's legit or not. Googling the onion address is an obvious choice and something the ransomware author can just tell you to do.

3) Most people will need someone more technical to arrange the bitcoin payment anyway, these people will verify if the ransomware seems to be legit or not.

4) People don't magically get smarter, phishing still works if you pass the spam filters.

5) Winlockers were immensely lucrative even before they started using crypto.

6) Unless you're going to run your fake-ransomware campaign at an immense scale you'll never drown out the real, working ransomware.

And then in the end, what the was your goal anyway? Good job, now you've deleted millions of peoples data on a retarded mission to "stop ransomware". But hey, at least you stopped those evil russians!!!

There are precisely zero good arguments for preventing people from decrypting their data.

Re: Another Ransomware Outbreak Is Going Global

#413

Earlier quoted context omitted.

Actually, I believe phishing / malicious attachment was debunked as the infection vector. Subsequent research found that WC starts scanning hosts and IP's on port 445 to try to find other machines to infect. Source: https://www.us-cert.gov/ncas/alerts/TA17-132A "Once the malware starts as a service named mssecsvc2.0, the dropper attempts to create and scan a list of IP ranges on the local network and attempts to conn…

That only happens after the initial infection into the network. Notice that it says it scans the "local network".

This is minutiae at this point, but it scans the "local" /24. My assumption is that it scans the /24 for any interface available, so if a machine is infected with a public IP, it will start scanning machines on the public Internet. Not to mention other variations may decide to scan more aggressively.

Re: Another Ransomware Outbreak Is Going Global

#414

Earlier quoted context omitted.

"What if they used a zero day and prevented a 9/11 size 3000 person, multi-billion-dollar terrorist attack?" What if terrorists use a zero day to blow up a nuclear plant?

I'm talking about hypothetical things in the past, you're making up hypotheticals about the future. Also, I provided a precise example of intelligence compromising ISIS for intelligence regarding airplane bombs, so my example isn't that outlandish.

When evaluating a risk it isn't a good idea to restrict yourself to scenarios which already have happened.

Re: Another Ransomware Outbreak Is Going Global

#415

Earlier quoted context omitted.

I'm talking about hypothetical things in the past, you're making up hypotheticals about the future. Also, I provided a precise example of intelligence compromising ISIS for intelligence regarding airplane bombs, so my example isn't that outlandish.

When evaluating a risk it isn't a good idea to restrict yourself to scenarios which already have happened.

But the subject isn't risk evaluation, it's the idea of a "score" where using NatSec state zero days get positive points for saving lives and saving money, and negative points for when terrorists use leaked zerodays or take advantage of unfixed holes.

The claim was "any terrorist attack using these proves it's a net loss"

My response was "the classified nature of positive points doesn't invalidate positive points, and you cannot call it a net loss without a full accounting"

Now it's just devolved into a game of hypotheticals where people try to disprove the idea of a full accounting by creating even sillier terrorist scenarios?

Re: Another Ransomware Outbreak Is Going Global

#416

(Sorry for the repost but I feel the pain of sysadmins so it might be useful to some people as everything melts down around them this evening)... Hey, FWIW we had to do some response for ransomware cases recently. There was a lack of decent stuff out there for how IT teams should deal with it. So we contributed to putting together this quick checklist: https://github.com/0xswap/guides/blob/master/ransomware-tria... W…

A minor nit: if you convert this over to markdown or ReStructuredText, it'll display more nicely on the page and be easier to move over to GitHub pages or the like.

Good idea! Will do that.

Re: Another Ransomware Outbreak Is Going Global

#417
post #28

Earlier quoted context omitted.

What a clickbait headline. A paltry $3k and yet the article calls this a "MASSIVE ransomware outbreak". I would be curious to see what a "minor" outbreak is.

There are reports of hundreds to thousands of machines infected across multiple firms in multiple countries. I'd bet >99% of people are never gonna send the $300 in bitcoin to decrypt their machine, instead they'll just clean and restore as much as they can. The $3k is 11 people desperate to restore all their data now, more may come in the future after people have exhausted other options, but the vast majority will n…

Seems like a better approach would be to have the ransom increase higher after every person that paid. Just so you'd have some competetion to pay sooner.

Re: Another Ransomware Outbreak Is Going Global

#418

Earlier quoted context omitted.

Do you have a source for that?

Not OP, but he is right. I just walked out of work, where I had to reverse the sample. It indeed uses EternalBlue (attacks by enumerating local network IPs with Windows APIs and randomly scanning the internet). Apart from that, it overwrites the MBR with a custom bootloader and schedules a restart ("shutdown /t /r") as SYSTEM in a random amount of time. After rebooting, it fakes a chkdsk and meanwhile, encrypts your…

can you share literature on what tools you used to reverse engineer and maybe other items worth reading if I am interested in this type of research?

Re: Another Ransomware Outbreak Is Going Global

#419

Earlier quoted context omitted.

@willlstrafach, Nothing you have said convinces me the commentator you are replying to is wrong. Especially since an NSL would prevent ANYONE who detected anything from speaking about it. Updates that tweak code to introduce vulnerabilities, is not something thats science fiction.

> Especially since an NSL would prevent ANYONE who detected anything from speaking about it Forced malicious updates would indeed be a reasonable concern if this was somehow actually the case. It is not, though, and I am not sure how that would even work. Are you saying that when it is detected, the government would somehow become aware of the detection and threaten the finder with an NSL before they could tell anyon…

Just because YOU cant figure out how it works, does not mean its not possible my friend. But I will say, that when you have a backdoor, and suddenly that backdoor stop providing intel/data/whatever, its usually a good indicator.

Re: Another Ransomware Outbreak Is Going Global

#420

Earlier quoted context omitted.

> Especially since an NSL would prevent ANYONE who detected anything from speaking about it Forced malicious updates would indeed be a reasonable concern if this was somehow actually the case. It is not, though, and I am not sure how that would even work. Are you saying that when it is detected, the government would somehow become aware of the detection and threaten the finder with an NSL before they could tell anyon…

Just because YOU cant figure out how it works, does not mean its not possible my friend. But I will say, that when you have a backdoor, and suddenly that backdoor stop providing intel/data/whatever, its usually a good indicator.

I do not know what you mean by this. Again, my point was that any backdoor is highly unlikely to stay hidden.
Post reply on HN