Earlier quoted context omitted.
This is brand new. After Heartbleed, people realized that branding vulnerabilities is great for driving business. A year ago, this was unheard of.
Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.
iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
71–78 of 78 posts
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#72TL;DR: Don't open attachments. Didn't we all learn this 15 years ago?
Obviously I can't confirm if this works but: > How to embed PowerPoint presentations in your web pages. > Once you've created the PowerPoint presentation, embedding it on a Web page is as easy as saving it to the Web, grabbing the embed code and pasting it onto your page - no code required. Visitors to your site will then be able to page through the presentation and interact with it directly on your Web page, from wi…
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#73"On Tuesday, October 14, 2014, iSIGHT Partners – in close collaboration with Microsoft – announced the discovery of a zero-day vulnerability..." "Over the past 5 weeks, iSIGHT Partners worked closely with Microsoft to track and monitor the exploitation of this vulnerability..." I'm sorry, I feel you should lose the right to call this a zero day when both you and Microsoft have known not only its existence, but the fa…
Perhaps they could have phrased it more clearly, but considering that it sounds like a full exploit on opening a powerpoint document, some alarm is appropriate.
I also think it was a little brash to name it "Sandworm" when it is not, as far as we know, a worm. It certainly has the potential to be used as the key exploit in a worm though.
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#74Earlier quoted context omitted.
Yes. This absolutely fucking sickens me. It instantly gives news agencies an excuse to pick up every little hole and scare all the mortals into submission. Security has become a marketing and media circus now which in turn desensitizes people to real concerns and rational thought.
I do see your point, however sometimes it is a good thing to let everyone know about it, so they're able to do something about it. For example, my manager even heard about "shell shock" and prompted me to do something about it. Although, it was over a week after the outbreak, and we'd already established we weren't vulnerable (applied the patch anyway) - but even so!
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#75The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#76The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#77The article is filled with fluff about iSIGHT and they buried the lead. Here are the high level details they posted: * An exposed dangerous method vulnerability exists in the OLE package manager in Microsoft Windows and Server (Vista SP2 to Windows 8.1, Windows Server versions 2008 and 2012) * When exploited, the vulnerability allows an attacker to remotely execute arbitrary code * The vulnerability exists because Wi…
Seeing how all of the other articles about this exploit are basically regurgitating iSight's announcement, I thought I'd provide something a little bit more useful.
https://www.virustotal.com/en/file/70b8d220469c8071029795d32...
Re: iSIGHT discovers vulnerability used in Russian cyber-espionage campaign
#78Earlier quoted context omitted.
This might just be anti-microsoft bias but I think the thing here is that with a Windows vuln you can't see the source code so you really have no idea how severe the vuln is, the people who find it can simply make shit up with no one able to call them out other than Microsoft. Also maybe the average windows user will be less tech savy than a linux user and fall prey to scare tactics like these.
The "average windows user" will not even read this. Nevertheless there are many tech savvy windows users in absolute numbers.