Cisco's Talos team analysis of WannaCry worm
blog.talosintelligence.com
blog.talosintelligence.com
Phewww! Good thing I'm using .tex to write my thesis and write most of my code in .py... lol
Refusing to listen to what people have been telling you since the inception of email does not make you right, though.
You put the stick in someone else's machine and print the files. The stick might be infected after this use.
You don't put the stick back in your machine, because it might be infected.
Do you continue to put it in other people's machines to keep printing?
Don't run or open anything off the stick on your machine and you'll be fine.
Not only can you trivially make such a thing with an arduino but there are also some commercial USB sticks which have a persistent "background" filesystem that cannot be formatted away.
Anything that is run automatically in the background, like the thumbnail services.
Autorun hasn't been a thing in ages.
The amount of rage the customers will feel towards the makers of whatever non-secure self-driving or "connected" cars receive the ransomware should give those car makers a nice kick in the behind to get their act together.
Then we'll see how quick the car makers will be about implementing features such as "unlocking your car remotely from the beach."
Individual cars doing their own thing, no problem. Cars talking to cloud, big privacy problem, potential security problem. Cars talking to each other locally, smaller privacy problem, but bigger security problem.
https://blockchain.info/address/115p7UMMngoj1pMvkpHijcRdfJNX...
The lack of highly available and remotely exploitable vulnerabilities have made them less common.
Back in 2003, most people were on dialup or had a single machine plugged directly into the Internet. Microsoft had no firewall out of the box. So by default you exposed all your Microsoft networking services to the whole Internet.
NAT changed that, it made it so no one could directly connect to all the vulnerable machines floating around. Your phone is unable to infect other phones on your providers network or the wider internet in this same way.
No one is out mass exploiting those IOT light bulbs with default telnet passwords because they're not exposed directly to the Internet. There are a few however exploiting vulnerable NAT routers... probably the only sort of worm to see widespread success in recent years.
I don't remember that happening with any other type of infection.
> In cases where the system has not been previously compromised and implanted with DOUBLEPULSAR, the malware will use ETERNALBLUE for the initial exploitation of the SMB vulnerability. This is the cause of the worm-like activity that has been widely observed across the internet.
This is not really any different from Blaster from 2003.
In that case, it was supposedly because of the patch:
> According to court papers, the original Blaster was created after security researchers from the Chinese group Xfocus reverse engineered the original Microsoft patch that allowed for execution of the attack
The patch was
ms03-026: Buffer Overrun In RPC Interface Could Allow Code Execution Published: July 16, 2003
(could, hah)
> The worm was first noticed and started spreading on August 11, 2003
It was a huge problem at college campuses well into September. Students would arrive with their brand new laptops running XP and get hit with the worm 30 seconds after connecting to the network.
Really the main difference is blaster was just an annoyance and mostly just broke random things like the DHCP service, but was easily fixed.
From the article:
The above subroutine attempts an HTTP GET to this domain, and if it fails, continues to carry out the infection. However if it succeeds, the subroutine exits. The domain is registered to a well known sinkhole, effectively causing this sample to terminate its malicious activity.
I'm not super well versed in crypto, but is this possible? I assume they use symmetric encryption and then RSA encrypt the symmetric keys?
Get the private key when you pay...
Seems strange that an article as important as this wouldn't be served securely.