Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

471–480 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#471

There's the bitcoin ransom aspect, but presumably a worm like this could extract a massive amount of data from infected servers and send that back to someone/somewhere? Bank transactions, patient medical data, stored passwords/keys/CA info, contacts, emails, configuration files, registry dumps for firewall rules etc etc. (I'm not that creative so there's probably a lot more that's been exfiltrated). Pretty hellish kn…

Right, the real money is not going to come from the bitcoin ransoms, but from the information on millions of patients which they surely made copies of.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#472
post #76

Earlier quoted context omitted.

Right, I'm sure the NSA doesn't currently take any effort to secure their trove of 0-days. It's not like they're valuable assets or anything. Edit: My point is that thinking that requiring the NSA to keep them "as secure as possible" as though that would eliminate risk is just silly. There will always be risk of breach or insider theft, as well as the requirement that the exploits actually be put to use outside some…

Wasn't the story behind the NSA leak that it explicitly wasn't well protected, and was passed relatively freely between contractors and without much in the way of oversight?

Not at all, you are thinking of the allegations regarding the CIA content from WikiLeaks.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#473
post #11

Earlier quoted context omitted.

If you run a large installation of computers, taking updates can be a huge risk. Often they can break things, and then you're in the position of being blamed for running an update. Not updating can often lead to much higher stability. In previous environments I've worked that were "regulated", any change to the environent, such as a firmware upgrade, triggered an entire re-regulation process (testing, paperwork, etc)…

Downloading Microsoft security updates is simple and safe. You just download the monthly rollup: http://www.catalog.update.microsoft.com/search.aspx?q=401221... Any competent sysadmin will have these available on their internal update server and push updates+restart during off-peak hours. Receptionist computers that can open websites with untrusted JavaScript can't reasonably be held to this certification. Certificat…

I'd like to hear r/sysadmin opinion on that.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#474

Earlier quoted context omitted.

The main one is to have _all_ machines patched through windows update. That is what will protect you. SMBv1 is an outdated protocol, in which there have been some severe vulnerabilities disclosed in the last few weeks, hence why I recommended to get rid of it at the same time. That being said, the vulnerability being exploited here is in SMBv2, hence why patching all machines is crucial.

If you are working with SCCM and 20,000+ clients (computers), you will know that all machines will never be patched. It just does not happen. On any given large network there will always be a certain number of unpatched clients. There are a myriad of reasons for patching to fail, from advertisement errors to installation issues, to machines simply being offline (and later coming back online).

Thanks for the info. I patched all client machines last night.

Here is the offline installer:

https://support.microsoft.com/en-us/help/3125574/convenience...

Prerequisites: must have installed SP1, along with the April 2015 convenience rollup. Links are provided in the prerequisites section.

Here's a direct link to the catalog download for the May 2017 security rollup (this supercedes all previous monthly rollups):

http://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB...

For more information on the monthly rollups and how they supersede each other, see:

https://blogs.technet.microsoft.com/windowsitpro/2016/08/15/...

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#475

The real world doesn't update in 2 months. (I wish it did.) The NSA should have responsibly disclosed the vulnerabilities they had been sitting on as soon as they were discovered. That protects national security - not this.

Wikileaks should have disclosed before dumping publicly. Burning down the house to prove that there are fire safety issues is the wrong approach.

This has nothing to do with Wikileaks, who have tried not to release any unpatched vulnerabilities in the Vault 7 documents and have been ignored by many companies they have approached offering to disclose vulnerabilities.

At least double check you've got the right person before labeling them an arsonist.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#476
post #3

We really are living in the future. My condolences to the NHS, but what a time to be alive.

Out of curiosity, what about this attacks feels futuristic? If anything it feels very retro, in that it hails back to the notorious worm attacks from the earliest days of networked computing.

the headline more than anything -- pilfered secret spy software stolen by (probably) a rival intelligence agency, released to the public without scrutiny, repurposed by cybercriminals, used to ransom data indiscriminately for decentralized software currency, bringing major institutions to their knees, and defeated by a guy in his bedroom at his parents' house who accidentally found a secret kill switch. it all feels very cyberpunk, and very much like a fictional plot, unfortunate circumstances aside

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#477

The real world doesn't update in 2 months. (I wish it did.) The NSA should have responsibly disclosed the vulnerabilities they had been sitting on as soon as they were discovered. That protects national security - not this.

I sort of wonder if Microsoft could create a mode for Windows where if it detects a security update available, it MUST update. I have spent a lot of the time trying to get Windows to just fucking STOP, but there are environments where security-before-use would seem ideal.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#478

Earlier quoted context omitted.

The IV drip machine is not plugged into the CoW (Computer on Wheels). That workstation is running a version of enterprise Windows primarily to allow the medical professional to view and update patient records. The IV drip machine is plugged into the wall, and is operated by buttons on the front.

In reality, a huge number of modern IV drip machines plug into the wall for power and get their network connectivity via 802.11. This is to allow remote configuration and status monitoring.

Are the IV drip machines running Windows CE or XP embedded? Was there a news report that claimed that IV drip machines were affected by malware?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#479
post #473

Earlier quoted context omitted.

Downloading Microsoft security updates is simple and safe. You just download the monthly rollup: http://www.catalog.update.microsoft.com/search.aspx?q=401221... Any competent sysadmin will have these available on their internal update server and push updates+restart during off-peak hours. Receptionist computers that can open websites with untrusted JavaScript can't reasonably be held to this certification. Certificat…

I'd like to hear r/sysadmin opinion on that.

Translation: "My feelings make me feel that the statement isn't right. Instead of finding out, I'm just going to say that I wish someone would tell this commenter they're wrong."

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#480

Earlier quoted context omitted.

Out of curiosity, what about this attacks feels futuristic? If anything it feels very retro, in that it hails back to the notorious worm attacks from the earliest days of networked computing.

the headline more than anything -- pilfered secret spy software stolen by (probably) a rival intelligence agency, released to the public without scrutiny, repurposed by cybercriminals, used to ransom data indiscriminately for decentralized software currency, bringing major institutions to their knees, and defeated by a guy in his bedroom at his parents' house who accidentally found a secret kill switch. it all feels…

aha, and i see i'm not the only one who thinks so: http://www.antipope.org/charlie/blog-static/2017/05/rejectio...

though a bit of it is in your camp as well:

> It's a worm — a boringly old-hat idea first introduced into fiction by SF author John Brunner in his 1977 novel "The Shockwave Rider".

Post reply on HN