Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
51–60 of 69 posts
Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#52Earlier quoted context omitted.
He didn't know it was the kill-switch domain. He expected it would enable him to kill the malware, though, and was trying to figure out how to send the kill command before it turned out that simply sitting a server behind the domain was enough to kill it.
What a pointlessly flippant argument. Hutchins discovered, and engaged, the WannaCry killswitch. Irrevocable fact.
He was still selling banking trojans the year before, so who knows?
Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#53Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#54Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#55This is a bit over the top. He is not a master hacker who "saved the Internet"; He accidentally neutered WannaCry by registering a domain he found in the binary, which as it turned out, acted as a kill switch.
> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…
https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#56Earlier quoted context omitted.
>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.
His goal was to kill the malware. Registering the (unclaimed) domain in the binary was supposed to be step 0 to this. Such a domain would almost certainly act as a control center of some sort. You can claim it while it's still available and analyze the malware or even just the traffic reaching your domain to try and neuter it. Even if there's no killswitch, maybe sending invalid data will cause the malware to malfunc…
Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#57This is a bit over the top. He is not a master hacker who "saved the Internet"; He accidentally neutered WannaCry by registering a domain he found in the binary, which as it turned out, acted as a kill switch.
> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…
- Act as a centralised C2.
- Act as a kill-switch (this is what happened)
- Act as a dead-man-trigger, destroying the host system.
Even if the third option is not as likely as the first one, the repercussions had he been wrong would have been severe.
Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#58Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#59Earlier quoted context omitted.
His goal was to kill the malware. Registering the (unclaimed) domain in the binary was supposed to be step 0 to this. Such a domain would almost certainly act as a control center of some sort. You can claim it while it's still available and analyze the malware or even just the traffic reaching your domain to try and neuter it. Even if there's no killswitch, maybe sending invalid data will cause the malware to malfunc…
"Would almost certainly", yeah, in most cases. But, and this is something that didn't get talked about enough, what if registering the domain actually caused the malware to nuke the host system instead? Think of it as a kill-switch to deter malware researchers that only superficially reverse-engineered a sample before jumping to action. Viewed from that light, just registering the domain because you saw your sandbox…
Besides, history tells us that those malwares won't really have such "nuking" functionality. Gating it on the presence of a server is ridiculous, and would be found out eventually when the virus runs in a weird environment where, for instance, every DNS queries resolve (e.g. hotel WiFi).
Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
#60It's a long piece, and quite interesting. Thanks for sharing @Malwaretech.