Stuxnet - First weaponized malware?

The constant threat: viruses, trojans, spyware, ... the list goes on

Re: Stuxnet - First weaponized malware?

Post by fabianhjr on Fri Sep 24, 2010 9:37 am
([msg=46413]see Re: Stuxnet - First weaponized malware?[/msg])

mRmasteRful wrote:Well at least I have no direct threat from my little Caribbean island. A shame though when we reach apocalypse I have no useful skills for an end of the world scenario. Im only good as food.


Do you have some seasoning? All this mutant meat sucks.
Donate bitcoins to me! [1DhRP3hHgmSLQdRTZyT8VPTmzAj7Z2rsGA]
Dunno what bitcoins are? BitcoinMe
fabianhjr
Poster
Poster
 
Posts: 286
Joined: Tue Sep 21, 2010 7:48 pm
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by cilpolir on Fri Sep 24, 2010 10:30 am
([msg=46414]see Re: Stuxnet - First weaponized malware?[/msg])

damn it would be nice if the maker(s) of this mallware made the code open source :twisted:
Image
User avatar
cilpolir
Poster
Poster
 
Posts: 218
Joined: Sat Sep 12, 2009 10:46 am
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by sanddbox on Fri Sep 24, 2010 11:43 am
([msg=46416]see Re: Stuxnet - First weaponized malware?[/msg])

cilpolir wrote:damn it would be nice if the maker(s) of this mallware made the code open source :twisted:


And then have it get cracked in a day? The whole point is that people don't know what the virus is going to destroy.
Image

HTS User Composition:
95% Male
4.98% Female
.01% Monica
.01% Goat
User avatar
sanddbox
Expert
Expert
 
Posts: 2354
Joined: Sat Jul 04, 2009 5:20 pm
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by tgoe on Fri Sep 24, 2010 12:29 pm
([msg=46418]see Re: Stuxnet - First weaponized malware?[/msg])

Here's an interesting overview of how its main payload operates:
http://www.symantec.com/connect/blogs/exploring-stuxnet-s-plc-infection-process
I'd love to take a crack at it but I can't seem to find a sample anywhere.
User avatar
tgoe
Contributor
Contributor
 
Posts: 527
Joined: Sun Sep 28, 2008 2:33 pm
Location: q3dm7
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by cilpolir on Fri Sep 24, 2010 2:20 pm
([msg=46429]see Re: Stuxnet - First weaponized malware?[/msg])

sanddbox wrote:
cilpolir wrote:damn it would be nice if the maker(s) of this mallware made the code open source :twisted:


And then have it get cracked in a day? The whole point is that people don't know what the virus is going to destroy.

I meant after it has destroyed it's thing :P
Image
User avatar
cilpolir
Poster
Poster
 
Posts: 218
Joined: Sat Sep 12, 2009 10:46 am
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by fureto on Sat Sep 25, 2010 7:42 pm
([msg=46514]see Re: Stuxnet - First weaponized malware?[/msg])

Wikileaks asked through their Twitter account earlier today if anyone had a sample of Stuxnet (I think that's how they put it) to DM them. They just posted this:

@wikileaks Stuxnet situation is extraordinary, sec analysts come to https://chat.wikileaks.org/ channel #stuxnet

If anyone's interested--don't know if they got it, or they just want to have a chat.

-- Sat Sep 25, 2010 8:10 pm --

On the wikileaks chat, someone said a sample of Stuxnet can be obtained at http://www.4shared.com/dir/yXu7eYRG/Upload_Virus.html# -- the file called stuxnet.rar. There is a very simple password.
fureto
New User
New User
 
Posts: 21
Joined: Tue Sep 21, 2010 2:40 pm
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by tgoe on Sat Sep 25, 2010 8:54 pm
([msg=46515]see Re: Stuxnet - First weaponized malware?[/msg])

Yeah I caught that, thanks!
User avatar
tgoe
Contributor
Contributor
 
Posts: 527
Joined: Sun Sep 28, 2008 2:33 pm
Location: q3dm7
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by sanddbox on Sun Sep 26, 2010 12:32 am
([msg=46525]see Re: Stuxnet - First weaponized malware?[/msg])

A few interesting facts about Stuxnet:

-It targets factories that refine uranium, not the nuclear plant itself, IIRC. It disables the system by blocking any action from the system for a tenth of a second - enough to ruin the enrichment of the uranium.
-It's speculated that its target has already been hit, due to failure of a nuclear facility in Iran last year (which is also believed to be why the head of energy unexpectedly quit after 12 years).
-Stuxnet uses 4 different 0days to gain access to the systems.
-Stuxnet is almost certainly the product of a nation state - as of right now, it is presumed to be Israel.

I'm impressed with Stuxnet because it appears to be the first real cyber attack - perhaps cyber terrorism really isn't a joke. Sorry if I restated facts mentioned in the OP's article or got some info wrong - I was reciting those facts from what I read a few hours ago. I'd post links, but I'm short on time. I do have an unpacked stub of Stuxnet if anyone wants it.
Image

HTS User Composition:
95% Male
4.98% Female
.01% Monica
.01% Goat
User avatar
sanddbox
Expert
Expert
 
Posts: 2354
Joined: Sat Jul 04, 2009 5:20 pm
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by Dwere on Sun Sep 26, 2010 1:06 am
([msg=46530]see Re: Stuxnet - First weaponized malware?[/msg])

So, have any of you seen the movie Live Free or Die Hard? That was the one with Justin Long who was the code writer for a part of a cyber-attack against the United States right?
Well is it possible/probable/likely/maybe that whoever is "behind" this isn't just one person? I mean they say it's a team put together by a nation state... Yeah... but couldn't it be just about anyone with a lot of money, outsourcing particular parts of code work to different people, so that no one specific person knows what exactly they were doing? Like in that movie?

I mean maybe I've gone a bit hollywood, but when I read this, that's what I was thinking of.
-Dwere (David)
Goatboy wrote:
Dwere wrote:I'm not one to start some branch of religion though. Not my thing.

Of course if you wanted to, you could call it the Davidians!
User avatar
Dwere
New User
New User
 
Posts: 21
Joined: Fri Sep 24, 2010 8:21 pm
Location: Washington
Blog: View Blog (0)


Re: Stuxnet - First weaponized malware?

Post by fashizzlepop on Sun Sep 26, 2010 1:39 am
([msg=46536]see Re: Stuxnet - First weaponized malware?[/msg])

Dwere wrote:So, have any of you seen the movie Live Free or Die Hard? That was the one with Justin Long who was the code writer for a part of a cyber-attack against the United States right? <br>Well is it possible/probable/likely/maybe that whoever is "behind" this isn't just one person? I mean they say it's a team put together by a nation state... Yeah... but couldn't it be just about anyone with a lot of money, outsourcing particular parts of code work to different people, so that no one specific person knows what exactly they were doing? Like in that movie?<br><br>I mean maybe I've gone a bit hollywood, but when I read this, that's what I was thinking of.

When I read this, I was thinking "*triple facepalm*"

Yes, it was a good movie. No, it was completely jack shit when it comes to hacking.
Yes, that theory is theoretically possible. No, it's not rational AT ALL.
The glass is neither half-full nor half-empty; it's merely twice as big as it needs to be.
User avatar
fashizzlepop
Moderator
Moderator
 
Posts: 2147
Joined: Sat May 24, 2008 1:20 pm
Blog: View Blog (0)


PreviousNext

Return to Malware

Who is online

Users browsing this forum: No registered users and 0 guests