Linux ransomware in the wild
forums.gentoo.org
forums.gentoo.org
Take the data you can recover offline and then reinstall from scratch. Don't try to fix it, just recover what you can and throw the rest away.
My real concern would be them grabbing secrets, not losing any data.
not saying your idea is bad advice but you need the full picture to counter ransomware attacks
dd if=/dev/mem of=~/mem.img
to obtain an image dump which may contain the decryption key.It's worth noting that if you are really serious about doing forensics and investigating the attack, then shutting down can be pretty destructive.
> what data is recoverable.
Another point I'd make is that try to recover as little as possible from the infected system and prefer using clean backups instead.
I agree on the overall sentiment though, attempting to recover a infected system is unnecessarily risky. Nuke it from the orbit, it is the only way to be sure.
The reality is that decoders for complex file formats often have buffer overrun and code execution flaws. If such mechanisms were used in the original attack or if the malware has worm-like abilities to extend the attack from your compromised machine, then wouldn't it me likely that more such corrupted data is also being staged to your machine?
Also, a very real risk would be the huge number of little scripts and configuration files which offer embedded scripting syntaxes. A naive victim might think they can install a new OS and just "recover their custom configuration files", but they are really recovering the attacker's configuration which can include the actual malware activation or other fail-safe reinfection mechanisms.
> In the first demo, I just select the PDF document with one click. This is enough to exploit the vulnerability, because the PDF document is implicitly read to gather extra information.
> In the second demo, I change the view to Thumbnails view. In a thumbnail view, the first page of a PDF document is rendered to be displayed in a thumbnail. Rendering the first page implies reading the PDF document, and hence triggering the vulnerability.
> In the third demo, I use my special PDF document with the malformed stream object in the metadata. When I hover with the mouse cursor over the document (I don’t click), a tooltip will appear with the file properties and metadata. But with my specially crafted PDF document, the vulnerability is triggered because the metadata is read to display the tooltip…
https://blog.didierstevens.com/2009/03/04/quickpost-jbig2dec...
So you shouldn’t trust that this doesn’t happen again.
Really?
>> Best thing to do when dealing with this kind of stuff is disconnect the network, cold reboot off a livecd and and go from there.
>> That means that they got root. You can't clean that up, its a reinstall. [...] If you want to do forensics, make a disc image of the install and work on that. You need the filesystem free space too, as that's where the interesting stuff will be.
TL;DR: The user ran firefox as root and the attack happened through adobe-flash. Hardly a sophisticated attack.
Here's a detailed view on Angler exploit kit which spreads through ad networks[1].
What's a good way to browse safely without using something like tails? There's firejail[2] and obviously I can run it as a different user
[1]: https://news.sophos.com/en-us/2015/07/21/a-closer-look-at-th...
1. when pages don't work at all, try looking for cloudflare links. They might have their JS and CSS hosted there
2. When you want to play videos or audio look for *cdn domains (aliexpress has alicdn for example). These ones I tend to add to my whitelist.
3. If you have something like google apis you can add it to the whitelist and add a sitespecific conditional in adblock or ublock.
I started blocking all JS by default for security, but I've actually found it to be a much better user experience as well. You deal with the annoyance of having to whitelist domains, and sure a lot of SPAs don't work at all until you enable JS for the client-side rendering, but many, many websites work far better because all the content I care about is server-side rendered and JS is used to load ads that disrupt the experience (this is especially true on mobile. For that I highly recommend the Brave browser). You'd be surprised how much better it can make parts of the web tho to have no JS :-)
The uMatrix UI makes managing this a lot easier.
There are lots of services I would be glad to outright pay for, or have some sort of flattr-type service attached to. I don't feel one iota guilty for blocking ads, given the risks and costs.
I don't run JS at all except for very few webpages (think gmail log in page, etc).
EDIT: Now that I think about it, I haven't really stressed how good uMatrix is. It really has changed the way I use the internet.
I agree so much. I cannot recommend umatrix highly enough. It has put me completely back in control of what sites can and can't do. I block everything by default except for first-party CSS and images (e.g. *.ycombinator.com when I visit news.ycombinator). It's great, and not at all as bothersome as I thought.
No more HTML5 pop-ups, deceptive ads, no more auto loading videos, no more sneaky audio, no more weird javascript that slows my browser to a crawl, no more tracking.
Honestly people, give it a shot. It's amazing.
I find myself more and more liking to use my laptop for browsing, which makes me think I could block images by default on my desktop as well and rarely ever notice it anymore.
Most sites actually work better with this. They're faster, there's less clutter, no ads, less risk. Some need a little convincing by unblocking some CSS or images. Umatrix makes this super easy. If a site requires javascript to run, I just skip that content. It's different for web apps like trello or github of course. Those get much more permissions.
> How on earth do you navigate what to let through and what to block?
umatrix gives a nice matrix (duh) that shows exactly what's trying to load. I dont often need to unblock things, but when I do, it's usually obvious right away. Takes maybe two clicks. Worth the effort IMHO
On my macbook, I run Safari with no loading of JS or images at all, and firefox with uMatrix again. And again, if a page isn't readable without JS, then I don't read it, or I wait until I can use chromium on my desktop, assuming that I'm not going to allow the scripts in uMatrix, which I usually don't.
On my phone, I run Safari with JS always disabled, which is actually perhaps surprisingly fine for the vast majority of mobile websites.
And I run firefox for iOS with JS enabled if I really really need to look at something that doesn't work on non-JS Safari.
You get used to it. Most JS on the web is junk anyway. I don't have any FOMO by avoiding JS almost entirely, but maybe that's just me (and people like me)?
A notch better would be running Qubes OS.
> Interesting to note that another system, also a sister, seems to have caught the same, and I can't recall ever having run anything but VirtualBox VMs on that one, it's turned off right now until I figure out a recovery plan, so at least 2 systems to recover, and have one clean one to do so from.
That said, it could easily be explained if SSH private keys weren't encrypted (passphrase protected) and allowed an easy hop from infected to sister. And if somebody is running Firefox as root, it doesn't seem too extreme to assume they might have unencrypted private keys...
So it may just be from running Firefox as root, but it's still possible it could be from other things.
If someone gets arbitrary code execution under your user, they can erase/encrypt your files. Who cares if the OS files are safe. All the data you really care about will be gone.
It is something the entire ecosystem would have to, at once, agree to make happen, and then standardize mandated MAC profiles in every package format. So basically never.
alias sudo='/usr/bin/sudo echo something evil && /usr/bin/sudo'
I don't think it matters that he used his root account.Edit: Maybe I'm wrong with my opinion, you can disable ASLR using your root rights... https://askubuntu.com/a/318476
Edit: Last exploit for Linux remote exploitation with Flash is from 2015 https://www.rapid7.com/db/modules/exploit/multi/browser/adob... or did I miss something here?
> alias \'sudo\'='ls -a'
> 'sudo'
. .. $ alias /usr/bin/sudo=whatever
bash: alias: `/usr/bin/sudo': invalid alias name -> alias /usr/bin/sudo='ls -a'
-> /usr/bin/sudo
. ..That has been speculated but far from proven. On the last page they are still talking about the point of entry and how they are in no way convinced it was FF/Flash.
While possible, this sounds so spectacularly unlikely that I can’t help but think that you’re just speculating.
Or maybe that was not the source of the infection, just ssh enabled with a weak password
Better would be easier ways to run browsers (and all applications) inside protected systems of some kind, so even if they are hacked they can't touch anything outside their own cache directory, and creating downloaded files.
Flash itself has been sandboxed inside Firefox's Plugin Container since forever and Firefox is getting a sandbox around tabs as we speak.
But you can break out of sandboxes. By either exploiting a bug in the OS that bypasses process permissions or by finding a hole in the sandbox that allows you to do things.
I imagine, for example, if you want to upload a file, then the tab-process has to talk to the less restricted main-Firefox-process, which has to then open up a file-chooser dialog and give control to the user.
But it could for example be possible to somehow malform this request to the main-Firefox-process, so that the file-chooser crashes and just hands over a random file, before the user has even seen the dialog. (Obviously, I'm not going to come up with an actual security vulnerability on the spot here.)
This kind of vulnerability can't be fixed with a sandbox. You need some way to upload files, for which you'll need filesystem access in some way and to pretty much the entire Home-directory.
Theoretically, you could require the user to copy the file into a separate "Upload"-directory and then only have read-permissions to that directory, but that's hardly user-friendly and would probably end up with some users keeping their entire Home-directory underneath that Upload-directory.
The OP on the Gentoo thread seems more than competent enough to know how to fix permissions issues though, so I agree it's a headscratcher.
Not sure if this is still a thing, but I remember Apple forums used to have people asking how to do that.
http://www.zdnet.com/article/crypto-ransomware-strikes-linux...
https://labs.bitdefender.com/2015/11/linux-ransomware-debut-...
probably "python based" and, as mentioned on the gentoo forums, the ransomware mesage is very similar to the one in: https://github.com/jdsecurity/CryptoTrooper
Friends don't let friends run Flash. Does Gentoo have Firejail readily available? That would have prevented this, I'm pretty sure.
Might be simplest to just create a user through the DE, then "su -c" from my main user to run the browser?
However it should be possible to configure your system such that it doesn't like such: https://wiki.archlinux.org/index.php/xorg#X_clients_started_...
And, of course, there's always the paranoid option of "run the browser within a virtual machine", so an attacker would have to break the browser, then get local root within the VM, and finally find an exploit for the VM, before getting to your files.
Mind that Firefox is also getting sandboxed tabs as we speak, so yet another layer that attackers would have to get through, which wasn't in place at the time of this attack.
Since few months ago I do almost all browsing in carefully set w3m. No javascript at all of course and certainly no flash. I am typing this in vim which is set as default form editor in w3m for me.
Edit: if you are wondering if w3m can work well try looking at HN using w3m, its a real beauty.
This malware is super thorough and super obnoxious. Keep your machines up-to-date.
Noooooooooooooo!
But it's still interest that they bother with making ransomware the first place for Linux.