Stuxnet Questions and Answers
f-secure.com
f-secure.com
Other than "jacking in" and other fluff Stuxnet does pretty much exactly the kinds of things that CyberPunk Sci-fi described a decade ago.
I flippin love living in the future.
I'd love to know what it's supposed to do when it reaches its target. Surely the creator would have had to have some sort of blueprints for the target system to successfully set it up to create more than collateral damage.
"Hey, the VFDs are programmed to skip through this frequency band during the accel ramp to 25k RPM, but every once in a while they hickup and then the bearings rub. What's up with that?"
So it seems that there is one factory layout Stuxnet is looking for. I.e. it will know what point 35 is.
If the main fan control gives a fairly standard reading, it shouldn't be too difficult figuring out what the particular factory it has infiltrated has wired that point to, for example.
Also, I haven't heard any definitives on what kind of factory this is targeting. I do know that there aren't many companies that develop and design high tech industrial facilities. Despite StuxNet having infected thousands (millions) of personal PCs, it really is only looking for maybe a few dozen or so in the world that are of the right type. Combine that with a low number of factory designs, and it could very well have a pre-determined database of how its intended targets are wired.
On the other hand, if you solve the puzzle, maybe you can sell your story to Hollywood.
The link between the word "Myrtus" and the Old Testament seems really strained. It's the name of a plant. It features prominently in Greek mythology -- maybe the Greeks did it?
1) Eshter's born name is Hadassah, which means myrtle (http://en.wikipedia.org/wiki/Esther#Origin_and_meaning)
2) When Eshter asked the king if Jews can kill their enemies, king granted the permission (http://www.biblegateway.com/passage/?search=esther%208:11-8:...)
"The Chilean Guava (Ugni molinae, also called Myrtus ugni or Eugenia ugni)"
There are countries with DD-MM-YYYY or MM-DD-YYYY, so you really do have to put the year first to avoid ambiguity. However the 79 in 1979 cannot be a month or a day.
Subtlety, obfuscation, and misdirection; welcome to the Middle East.
I would say that if this is the best we have, then it's pretty certain it's not the Israelis who did this.
That one caught me off guard.
I've been reading pretty much everything I can find about Stuxnet so far, but haven't heard this before. If it's true Stuxnet might really be living up to the hype that it's the "first malware of it's kind."
[1] http://en.wikipedia.org/wiki/Zero-day_attack [2] http://weis2007.econinfosec.org/papers/29.pdf
However, at such a price point you're still well within the remit of organised gangs; they, for example, will spend a fortune on viruses and other malware - it's big big business.
I can only comment on the US Government's NSA, which has thousands of highly trained and highly intellectual programmers already under their employ. These are people that do their job to protect and assist in the affairs of the government. Probably already under highly classified labels. For some, it is just another job assignment.
However, I am also speculating. The truth: No one capable of telling the truth knows.
U3 enabled devices have been known to override the default settings in order to emulate CD-ROM drives.
Double clicking the flash-drive icon can also force execution of binaries, but I am unsure of how that works and if it is related to the user's autorun settings or not.
"The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed."