Leaked NSA Malware Threatens Windows Users Around the World
theintercept.com
theintercept.com
I feel the HN submission should point to that instead.
The Outlook Exchange, RDP, Kerberos, ... exploits are scary, even though some only seem to affect older Windows versions.
However, judging by https://technet.microsoft.com/en-us/library/security/ms17-01... it's likely somebody had some advance knowledge, somehow.
Oh, and hey: https://blogs.technet.microsoft.com/msrc/2017/04/14/protecti...
See following tweet by shadowbrokers from Jan 7.
https://twitter.com/shadowbrokerss/status/817960380815306752
2) Microsoft issued a statement that NSA did not tell them about any of the leaks [2]
3) NSA knew what was coming since Jan 7 [3]
[1] https://twitter.com/hackerfantastic/status/85303694234218905...
[2] https://twitter.com/samfbiddle/status/853025550096621568
[3] https://twitter.com/shadowbrokerss/status/817960380815306752
re: 2) You should reread that link and look at the correction. Microsoft was notified.
In this case, it seems (though I can't find confirmation) like standard firewalling of SMB (what you get if you click the "untrusted network" category on connecting to the cafe wifi or whatever) would be enough to protect a user.
Along these lines, I would expect the NSA to encourage the use of cryptography and encrypted software/Secure Boot/secure communications while they ensure the NSA have a set of extra keys and can sign software at will.
Deliberate introduction of hard to exploit 0days would be precisely how they would do it. All you need is one plant with commit access.
Note the date - 04. September 1999.
Most seasoned security folks know that the way to backdoor something is to leave an innocent bug in it. Plausible deniability, impossible to prove it was a backdoor because it looks just like any other exploitable bug.
Not that I'm suggesting that the NSA did leave these as backdoors. I don't believe that to be the case. But if you want one, that is how you do it.
If you ever find a blatant backdoor in some software, you're either dealing with an amateur, or someone who wanted to be found in order to send a message/misdirect you.
1) finding a bug and notifying the company
2) finding a bug and releasing/selling
3) finding a bug and using it
4) intentionally adding bugs to software without notifying anyone
5) intentionally adding bugs to software and claiming it's secure
This was level 5
Yes that was a devilishly well executed backdoor, on so many levels.
A backdoor is far too obvious for widespread use, which is the needed anyway. The NSA (and FVEY in general) instead spends a lot of money on programs like BULLRUN (Edgehill at GCHQ) that try to bypass the need for backdoors and weaken encryption. PSYOPS for nerds[1] is much cheaper and easier than direct backdoors or other technical methods.
Instead of a backdoor we have IPSEC standards that is overly complicated, had to implement, and mandated "null" encryption support[2]. Most communication channels remain in plaintext or encrypted with keys that are recoverable, too short, or easily MitMed.
[1] https://archive.fosdem.org/2014/schedule/event/nsa_operation...
[2] http://www.mail-archive.com/cryptography@metzdowd.com/msg123...
2. It'd probably be a method of last resort, so the NSA et al. would gather and use zero days anyway. Any use of the backdoor risks it being noticed, so using other entry points make sense if possible.
A less comforting interpretation would be that relying on zero days suggests they are confident in their ongoing ability to find them and/or have a sizeable cache of unknown exploits already, so adding a deliberate backdoor wouldn't provide any additional access.
I always wondered how that works. I am a full time employee at software company. Cannot imagine having extra time to report to another employer (NSA) and deal with their red tape and crap as well.
Or does NSA show up at their doorstep with a bag full of cash - "Here you go, have this, and install a backdoor in your company's software. And we never met <wink>, <wink>"
That sounds good on paper so to speak, I just have a hard time imagining a realistic scenario.
Now finding 0-days and hoarding them, I can see that.
So you monitor universities and you make contact with some of the brightest sparks. You promise them a good job in exchange for the possibility that, one day, they might have to act For The Good of The Country; and in the meantime they'll even be In The Know, which will place them above their peers - excitement! Ambition! Then you lobby a few higher-ups you're friend with, to hire these guys in this or that group. They are top-notch talent, immaculate credentials, so the hire is a slam dunk. They go about their business, being good kernel devs or whatnot, and every few months you give them a quick call to catch up - there is no need for extensive briefing, nobody really cares about the going-ons of Team Kernel A356. When "the favour" is required, the guy is comfortable in his position and doesn't want to leave it, so there is no chance he'll say no.
This applies to 0-days as well.
From what I have read one of the vulnerabilities seems to be a 0day targeting SMB on Windows. One commentator suggested it's enabled by default on the majority of Windows machines (of that I am sceptical). Presumably most people are behind a router which would stop this in its tracks?
A lot of people (who I would probably take seriously) suggest disconnecting Windows machines from the internet for the time-being. Is it really this bad? Are there millions of Windows (home-)users who are vulnerable (by default) today?
Trouble is there are millions of IoT devices with terrible security some of which are alway owned and inside the network. They could be used as a delivery tool to attack multiple machines inside of a network.
I'm not sure how many folks connect directly to the internet anymore. Hopefully not many.
It's been a while since I used windows but there used to be such a thing as the administrative share.
https://en.wikipedia.org/wiki/Administrative_share
So I don't find that hard to believe at all.
If your computer's network profile is set to Public, it will be firewalled off. In other cases YMMV.
On corporate networks, AD Domain Controllers are (usually) the most highly privileged servers on the network and they will always have SMB enabled and accessible to the entire domain network because Group Policy relies on SMB shares. Compromise the Domain Controllers and you own the entire (Windows) network because they can administer everything.
- https://twitter.com/Snowden/status/852950725881712640 - https://twitter.com/campuscodi/status/852885596221689856 - https://twitter.com/Snowden/status/852989758364147712 - https://twitter.com/josephfcox/status/852983848862461953 - https://twitter.com/Snowden/status/852987207170371587 - https://twitter.com/alexstamos/status/852984589463175169 - https://twitter.com/Snowden/status/852974864461963265 - https://twitter.com/TalBeerySec/status/852869388067844096 - https://twitter.com/Snowden/status/852967606088806401 - https://twitter.com/Snowden/status/852966739084275712 - https://twitter.com/josephfcox/status/852908421703753728
This is not a rhetorical question btw. I just want to get some insight into what the 'average American' thinks about Snowden.
http://www.newsmax.com/Newsfront/edward-snowden-rasmussen-po...
And now I feel ill.
Both tools in the demo video are SMB-based. I wonder how exploitable is a machine if it has SMB properly disabled and blocked.
Which is going to be Domain Controllers, the most highly privileged servers on most corporate networks. And accessible to the "entire" network too. Group Policy is distributed through SMB shares.
https://support.microsoft.com/en-gb/help/2696547/how-to-enab...
For my money, disable SMBv1 anyway and use a firewall and (V)LANs.
Samba, pop this under [global] to disable SMBv1 min protocol = SMB2
To disable it try "systemctl stop smbd" or "/etc/init.d/smbd stop" or ... 8)
RIP Windows users.
The only major zero days released for Windows in this bundle targeted SMB (SMBv1, SMBv2, & SMBv3). By default Windows firewalls SMB and has since Windows XP SP2. Many home and business users then typically have a NAT between the Windows Firewall and the internet, offering a second layer of protection.
Few companies intentionally expose SMB to the internet. Generally users are required to VPN in before then being able to contact an SMB endpoint.
The type of language in this article is designed to mislead non-technical readers into believing they're at risk e.g.:
> The software could give nearly anyone with sufficient technical knowledge the ability to wreak havoc on millions of Microsoft users.
So either the article author lacks the technical literacy to understand why this is untrue, or they know it to be untrue and are trying to implant fear into their readership. In either case, not a good look for The Intercept.
True, but in your average coffee shop setup if a user has SMB running you could reach them via a local IP if it isn't firewalled off on the machine itself.
2. There are other risks: pivoting, RDP, etc.
3. Greenwald's entire point of founding The Intercept was to capitalize on bombastic Snowden leak stories without intermediaries such as The Guardian. It seems like it would be counterproductive for the editors to write something measured or that give NSA any benefit of the doubt. Readers should expect alarmist journalism from The Intercept as much as they should expect anti-conservative viewpoints from the NYT.
But never let fact get in the way of hyperbole and clickbait, it doesn't matter that Windows is secure against this out of the box since XP SP2, it doesn't matter that a simple NAT "firewall" will protect you, all that matters is that some article told you to be afraid and no amount of technical facts is going to get in the way of that.
Too many of these types of articles and threads appearing today completely void of rationality about the scope of this because they don't understand the attack vector and "journalists" like The Intercept are not helping. But naturally outside of a few Netsec discussion boards the fear-party is in full swing, and people will downvote those not fully committed to that narrative.
And what did (and likely still does) the NSA possess? Exploits for Cisco gear, which many enterprises and universities use to provide VPN access.
> So either the article author lacks the technical literacy to understand why this is untrue, or they know it to be untrue and are trying to implant fear into their readership. In either case, not a good look for The Intercept.
Place a drive-by-infection malware on a news site, or a well done email, which contains a payload that exploits said SMB issue, and boom you've infected the entire network.
Also, many people don't upgrade their Windows servers if not absolutely neccessary.