Flame is Lame
f-secure.com
f-secure.com
> "Agent.BTZ did something like this already in 2008. Flame is lame."
Flame's approach is different and more impressive. Agent.BTZ copied itself and used an easy-to-discover autorun.inf file in the root directory of attached disks or network shares. Flame exports its database by encrypting it and then writing it to the USB disk as a file called '.' (just a period, meaning 'current directory')
When you run a directory listing you can't see it. You can't open it. The windows API doesn't allow you to create a file with that name and Flame accomplishes this by opening the disk as a raw device and directly writing to the FAT partition. Impressive, right.
While a lot of these individual features alone are not impressive the sum of the parts, combined with the collision attack on the certificate signature are very impressive.
As for the main point of Mikko's post, I have never understood why so many folks in the netsec industry are arrogantly pessimistic about the innovation of others. I found Flame jaw-droppingly amazing.
Nobody knew about it for years, yet it was derided when discovered and documented.
People are unsure as to why it has such a large file size (do we know why yet?). One very common explanation is that it is bloated because of poor software engineering, some of the people that believe this explanation attempt to fit the facts to that narrative.
Also Consider the culture of the demo scene/exploit writers. The smaller code the better the programmer.
Personally I like to think that the flame authors intentionally exploited this prejudice and made it large so that: 1. it wouldn't look like malware, 2. if it was discovered no one would take it seriously and look deeper, 3. reverse engineering it would be complicated by it's large file size (cost > benefit from an AV perspective).
Rather than attempting to look like some badass in leather, flame/stuxnet dresses in a cheap ill-fitting suit with a bad microsoft tie so no one will suspect it.
Infosec is an inherently pessimistic enterprise, although spending time here makes me think it's not a perspective limited to security.
Just look at how almost every post here ends up littered with comments like "This isn't new. My XYZ already does all of this." People like to feel superior (it helps reinforce the individual nerd exceptionalism)
This is exactly the attitude used by some negative minded mediocre people to demotivate free thinkers. To be fair, to most of them it probably also doesn't seem new in reality, because their grey cells lack the sophistication required to understand the difference.
BIFF[4] is still remembered by many within the early niche group of hackers. It is likely that similar psychology has been driving the ridicule at hacker conferences in recent years towards mainstream reporting on “cyber” topics and use of buzz phases such as “Advanced Persistent Threat”.
[1] https://en.wikipedia.org/wiki/Cypherpunk#Noteworthy_cypherpu...
[2] http://www.catb.org/~esr/faqs/hacker-howto.html
[3] https://www.schneier.com/blog/archives/2006/09/what_is_a_hac...
You can find 8.3 '.' entry names by searching a partition for \x2e\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20
A file with an LFN of '.' could be found with (hopefully this is correct) \x00\x2e\x00\x00\x00\x00\xff\xff\xff\xff\x0f
It appears as if 8.3 file names starting with '.' are treated specially but LFNs starting with '.' carry no significant meaning.
I struggled to find references to other malware that has used a similar approach. Does anyone have more information?
Surely Windows does not attempt to automatically execute files with a LFN (UTF-16 name) of '.'?
[1] http://labs.bitdefender.com/2012/06/flame-the-story-of-leake...
[2] https://en.wikipedia.org/wiki/File_Allocation_Table#Director...
Security folks often lack development experience, specifically in products that ship, to appreciate the big picture. This is why certain people on HN were so fixated on a lack of code obfuscation to give credit to the massive QA effort behind making all of stuxnet work on such a complex target.
I say this as a security person who has previously done dev on product teams.
It doesn't really matter whether the nation state in question is Iran or the United States. Do not pick fights with people who can respond to a hacking incident by writing a check for $5 million dollars to a defense contractor and consider that low-intensity conflict resolution. It will not end well.
FTFY: "Do not pick fights with people who can fly black choppers"
If you read the papers you know that that option is neither a joke nor the fevered imaginings of a paranoid conspiracy theorist.
Honestly, "we" (the West) are best armed, best funded, most free peoples ever to walk the earth. If we cannot put aside assassination and torture, then the human race has no hope.
Here for an interesting review of legality of such assassinations:
http://www.kentlaw.edu/perritt/courses/seminar/jerry-bekkerm...
Assange / assassination http://en.wikipedia.org/wiki/Tom_Flanagan_%28political_scien...
edit: for clarity, before I become flamed as a woolly left winger, I think that there are many people in the world, that if they were hit by lightning today, the world would be much better off. but
a) I think the world is nett worse off if democracies 'arrange' that lightning, because it demeans the important point of a democracy - being a beacon of hope for the future generations.
b) the choice of targets, is not discussed in a democratic manner, and almost certainly would not be my choice. (Now thats a referendum I would love to see:-)
c) my guess is that, like crime, taking out the people committing the crime right now, magically someone else steps into their place. Sometimes someone who yesterday was not committing those crimes.
Hmm, still pretty left wing there...
The second paragraph and points a and c are non sequiturs.
In b it seems you are in favor of a lynch mob.
Just explaining why I down-modded your comment
lynch mob - no, but I was struck with concern and amusement by the idea of a quarterly referendum on which world figures we should target for assassination, plus maybe a limit of civilian children whose collateral death would be acceptable in the voting list. In fact its the opposite of a lynch mob. A lynch democracy perhaps.
don't quite understand the non-sequiteur part... could you expand?
If we cannot put aside assassination and torture,
then the human race has no hope.
We can and should put aside torture. Assassination, however, is still a preferred tool, when often an alternative is a larger scale military conflict. A focused attack has a better chance of avoiding hitting innocent bystanders. important point of a democracy - being a beacon of hope
for the future generations
I do not think this is a point of "a democracy" at all. the choice of targets, is not discussed in a democratic manner,
and almost certainly would not be my choice.
This is a serious point. And it arises in any military conflict. How the democratic public controls its military is a matter of serious study; I am not competent in this, but perhaps someone could suggest a few links?This has been going on for far longer than we realize. (http://www.theatlantic.com/past/docs/unbound/bookauth/battle... -- excellent article on WWII linked on HN a couple of weeks back.)
Drone attacks, Apache missile strikes, and even dropping Navy SEALS on people with helicopters all seem to fall into some sort of "standard act of war" category when talked about in public. If you even merely refer to these things as assassinations you are written off as trying to use exaggerated or at least loaded language.
It's almost like people think "assassinations" are limited to snipers and James Bond figures breaking into your hotel room and making it look like a suicide.
Oh, you can't. They were assassinated by a western-backed democracy. (There have been many more, those were just the first two names that turned up of Iranian nuclear scientists who were assassinated by Israel.)
As much as you'd like to believe that assassination does not happen, it does. In the very same conflict that gave us Flame and Stuxnet. In fact I would not be surprised if information from Flame was used to target assassinations.
That said, I'm sure that if the US was involved there was some kind of backwards hoop jumping so as not to technically break the law. "I just had a chat with him on a park bench when we bumped into each other. He said he'd look into it."
And while politics may attract a disproportionate level of narcissists and sociopaths, I'm guessing CS doesn't.
That doesn't mean there aren't highly specialized and capable sociopaths out there.
Each individual hacker and each individual citizen is a much smaller target. Sure, as soon as you're identified, you're toast: they break in and install malware on your computer -- if you're lucky. But there's a lot of hackers and even more normal people, all of which can be made individually harder to identify through smart software.
Don't build circumvention tools. If you're lucky, they'll just turn out to be useless.
> It doesn't really matter whether the nation state in question is Iran or the United States. Do not pick fights with people who can respond to a hacking incident by writing a check for $5 million dollars to a defense contractor and consider that low-intensity conflict resolution. It will not end well.
Are you really saying that people should avoid writing software that could help people who are subject to evil regimes because said evil regime might be upset at them? There's an uncertain level of personal risk associated with doing such things, but there's definite moral hazard in total self-interest.
Either way, if Flame was written by the US or Israel a lot of us on here are already complicit in such a project. We live in a democracy. Those are our tax dollars, hard at work.
I totally agree with you otherwise; governments are not stupid.
No, I'm saying that "my software helps people who are subject to evil regimes" is approximately as irresponsible as "my homeopathic remedy solves cancer" except in this case cancer has essentially infinite computational resources, arbitrarily high numbers of very savvy domain experts, and an army. Any hacker who believes their software, or their community's software, will hold up to dedicated adversarial interest from a nation-state is dangerously delusional.
If somebody writes a tool that helps 100 million Chinese people access the unfiltered internet, a percentage of them will be caught and punished in devastating and inhumane ways. Some fraction of the illicit traffic will be blocked and the holes sealed up.
The remaining people will have access to material that, as far as the Chinese government is concerned, poses a tremendous risk to the state's continued authority. If this - as the state obviously believes - would help speed along the atrophy of an authoritarian state, net human suffering would be reduced overall.
There's no personal risk to writing regime circumvention tools. Iran isn't going to have you assassinated for your work on Tor.
There is serious risk to using Tor in Iran. Death squads and disappearances aren't a conspiracy theory in Iran; they are the regime's well-understood M.O. When circumvention tools like Tor work, they hide your traffic from the regime. When they stop working, or are turned, they do exactly the opposite: they attach a statistical marker to your traffic that says "whether or not you can read these packets, the person sending them is interesting".
The people working on circumvention tools are mostly well-intentioned (many of them are friends of mine), but they are delusional about the SWOT analysis at play here. None of them have any unique skills that aren't available to an organization willing to shell out 6-7 figures to a team in a month. Money buys competence. A lot of money buys a lot of competence. Iran has a lot of money. Circumvention projects do not.
Kickstarter hasn't seen the amount of money that a world government could spend without director-level approval on a project to turn a circumvention tool against its users.
And that's before you get to the fact that many, if not most, of the computers in authoritarian regimes are probably already rootkitted.
The playing field between Alice and Bob on the one hand and Eve on the other hand is inherently asymmetrical. Given equal competence and time to work on it, Alice and Bob are going to come up with an encryption scheme that Eve won't be able to break. You seem to be convinced that given almost unlimited resources, Eve can break any scheme Alice and Bob can come up with. I'm not sure I see any evidence for that.
A torture cell will do just peachy at decrypting the actual packets.
While there certainly is a chance of getting in trouble for using Tor, I wouldn't classify it as "serious risk." The government in Iran faces a situation w.r.t. filter circumvention similar to what the US faces when cracking down on illegal file-sharers. From my (admittedly limited) experience in Tehran last year, anyone with even a little computer know-how will have either some proxy service or Tor installed on their computers. The more knowledgeable ones have their own VPNs. Most use it to get through to Facebook and chat with their friends. It would be impossible to persecute everyone who's used circumvention tools without emptying half of Tehran.
The government certainly doesn't shy away from the measures you mentioned, but they generally go after for more grievous "offenses" than browsing the internet through Tor. Being gay, for example.
Judging from the recent actions in the middle east, the leadership there have no problem with going precisely that far, and further if they see fit.
That said, there is a history of people who have done that, paid the ultimate price, and later been honored for their sacrifice. Seems like history can go either way sometimes in judging the act, hero or idiot.
I'm all in favor of people keeping their eyes open though as they walk into it.
For me things like Flame just tell me that what I knew as an engineer could be done, actually have been done. And that is always a bit of a wake up call.
If non-government hackers were building offensive tools, vs. defensive, and only had to win periodically vs. essentially all the time, they'd be able to put up a better fight. Government doesn't have a particular monopoly on competence, and internal politics and budget issues probably would allow a relatively capital-poor non-governmental enterprise to do pretty well vs. a contractor/government team.
So what cryptanalytical capabilities do they have which are considered too sensitive to expose via malware?
Combine this with the fact that we're now dating the creation of the virus to at latest summer 2008 [1], and you've got a sophisticated surveillance mechanism that has been installed on thousands of computers and evaded detection for at least 5 years.
I'm sure there's lots more tricks that advanced virus authors like this have up their sleeve, but they're only useful to someone if they actually get used, and this seems to have paid off for whoever was behind this.
[1] http://www.nation.com.pk/pakistan-news-newspaper-daily-engli...
It's a terrible title. Fine for a media site trying to sell stories based on sensationalism but I thought we were building a brave new online community here.
Access to signing keys is very relevant, and I think there is a very real chance (p>0.2) that the huge oversight MS did with the terminal server keys happened because they were ordered to do it.
US Govt: we want source code access
MS: That is propiatory information
US Govt: give us access or we wont allow MS products to be used by govt. departments
MS: how quick do you want that access?
Enterprises w/ 10k+ seats, OEMs, MVPs and governments can get access to Windows source these days. Microsoft launched the program in 2006 or so to dampen the "Linux is more secure because we can see the source!!" FUD.
Government Security Program: Addressing the unique security requirements of governments worldwide by helping government actively participate in ensuring the security of their critical systems. We help enhance system security by providing access to Microsoft Windows and Office source code, prescriptive and authoritative security guidance, technical training, security information, and Microsoft security experts.
You can view the results for the Windows 7 accreditation at [1]. The website also has comprehensive documentation on the methodology used to accredit the software (including visibility of the source code).
I suspect a polite request (perhaps backed by a threat including the L-word) will get them far further than a virus.
Edit: Others have pointed to public documentation of this program. I believe the two cases I was aware of at the time were the governments of China and Germany.
There is a reason we have programming languages, and we don't all write directly in machine code. Just because it's techincally possible to do things in a more difficult way doesn't mean they would be done that way with a faster, easier option readily available.
Stop being silly. :P
The point is there's not a /significant/ difference; understanding code at a high level doesn't really help to attack it (it can make it harder, since the edges that you look for to exploit are precisely those parts you try and abstract away in a higher-level language), and the windows codebase is well-understood with lots of publicly available information describing in, even without the source code.
It is a cogent reminder of the fragility of the Internet's security infrastructure.
>9. Latest research proves that Flame is indeed linked to Stuxnet....
Whats the chance that this "Resource 207" is some 3rd party module that more than 1 developer had access to? I concede that placing the same resource in the same resource location in 2 different unrelated applications is a bit of a long shot, but I dont see it as a smoking gun either.
I had the same reaction, then I thought they did this on purpose to downplay how really impressive Flame is. I imagine the people writing these blogs are actually thinking "Holy S%$&!" behind closed doors or within other security circles.
(discussed on HN here: http://news.ycombinator.com/item?id=4087914)
http://idealab.talkingpointsmemo.com/2012/05/flame-malware-m... "The hype surrounding Flame may be partially the result of the ITU"
http://www.thetechherald.com/articles/Is-the-hype-surroundin... "None of the methods of this malware are particularly new."
http://xato.net/malware/flame-is-kind-of-lame/ "It’s just not that impressive as far as features go. In fact, 10 years ago it really wouldn’t have been that impressive."
Mikko
People don't normally refer to themselves or people they love as "lame." Not so for "gay" or "retarded."
A modern equivalent of "lame" might be "handicapped," even though it is not as specific.