Live data from Hacker News

iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

isightpartners.com

61–70 of 78 posts

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#61
The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted:

* An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012)

* When exploited, the vulnerability allows an attacker to remotely execute arbitrary code

* The vulnerability exists because Windows allows the OLE packager (packager .dll) to download and execute INF files. In the case of the observed exploit, specifically when handling Microsoft PowerPoint files, the packagers allows a Package OLE object to reference arbitrary external files, such as INF files, from untrusted sources.

* This will cause the referenced files to be downloaded in the case of INF files, to be executed with specific commands * An attacker can exploit this vulnerability to execute arbitrary code but will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it

TL;DR - A vulnerability exists in INF processing and untrusted, 3rd party INF files can be included by PowerPoint files. This is not a worm.

Also these little gems:

> Further information will be provided in a live briefing to any interested parties on Thursday, October 16th at 2:00...

> iSIGHT is making available a broader technical report – inclusive of indicators – through a formal vetting process.

Fuck you iSIGHT. This is being used in the wild and a patch has been released. Post the details publicly. This isn't responsible disclosure, this is PR and lead gen.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#62
"On Tuesday, October 14, 2014, iSIGHT Partners – in close collaboration with Microsoft – announced the discovery of a zero-day vulnerability..."

"Over the past 5 weeks, iSIGHT Partners worked closely with Microsoft to track and monitor the exploitation of this vulnerability..."

I'm sorry, I feel you should lose the right to call this a zero day when both you and Microsoft have known not only its existence, but the fact that it's being actively exploited for five freaking weeks. Also, am I the only one that feels this reads as a sensationalist article? I think the phrase "weaponized PowerPoint file" was what ended up pegging my meter, but the fact it's not a worm and barely fits the category of remote code execution helps.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#63
post #48
post #7

How does > When exploited, the vulnerability allows an attacker to remotely execute arbitrary code go along with > [...] will need a specifically crafted file and use social engineering methods (observed in this campaign) to convince a user to open it [...] Is this a fucking joke? Looks like some company just want to push their name out there and get some free media exposure.

Calling it remotely exploitable indeed seems misleading. A lot of the article is just fluf without real content.

[deleted]

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#64
post #6

Is it me or is the linked article remarkably content free given the about of security babble it contains? The nice aspect of the Heartbleed branding was its simple and clear message, not having opaque sentences such as "Visibility into this campaign indicates targeting across the following domains" and self serving platitudes such as "As part of our normal cyber threat intelligence operations, iSIGHT Partners is trac…

This might just be anti-microsoft bias but I think the thing here is that with a Windows vuln you can't see the source code so you really have no idea how severe the vuln is, the people who find it can simply make shit up with no one able to call them out other than Microsoft. Also maybe the average windows user will be less tech savy than a linux user and fall prey to scare tactics like these.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#65

The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…

It is marketing at it's finest: create fear and uncertainty and have a product ready to ease the pain (even though it won't likely help in any way).

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#66
Dear security researchers: Please stop taking time to come up with a clever name and a logo for your vulnerability. This is not a marketing event for you or your company. You are disclosing a vulnerability, not promoting your fly-by-night "consulting" company.

Trust me, if the vulnerability is important and has merit, you'll get the street cred among other security researchers and the potential employers that would hire you because of the work you did and your skills.

See Mike Lynn's massively bad RCE vuln in Cisco Routers or Dan Kaminsky's huge DNS vulnerability as examples on disclosing terrible problems with class.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#67
post #6

Is it me or is the linked article remarkably content free given the about of security babble it contains? The nice aspect of the Heartbleed branding was its simple and clear message, not having opaque sentences such as "Visibility into this campaign indicates targeting across the following domains" and self serving platitudes such as "As part of our normal cyber threat intelligence operations, iSIGHT Partners is trac…

This might just be anti-microsoft bias but I think the thing here is that with a Windows vuln you can't see the source code so you really have no idea how severe the vuln is, the people who find it can simply make shit up with no one able to call them out other than Microsoft. Also maybe the average windows user will be less tech savy than a linux user and fall prey to scare tactics like these.

The "average windows user" will not even read this. Nevertheless there are many tech savvy windows users in absolute numbers.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#69
Use of the exploit in the wild is "attributed to Russia", but I can't see any evidence stated to support that other than "Many of the lures observed have been specific to the Ukrainian conflict with Russia and to broader geopolitical issues related to Russia." Is there actually good evidence to point the finger at Russia? It plays quite nicely in to the Western agenda, so it seems an easy one to play off even if it's rooted only in suspicion.

Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign

#70

TL;DR: Don't open attachments. Didn't we all learn this 15 years ago?

Obviously I can't confirm if this works but:

> How to embed PowerPoint presentations in your web pages.

> Once you've created the PowerPoint presentation, embedding it on a Web page is as easy as saving it to the Web, grabbing the embed code and pasting it onto your page - no code required. Visitors to your site will then be able to page through the presentation and interact with it directly on your Web page, from within the browser and without having to have PowerPoint installed.

http://www.microsoft.com/web/solutions/powerpoint-embed.aspx

Post reply on HN