STUXNET

Message Bookmarked
Bookmark Removed
Not all messages are displayed: show all messages (19 of them)

60 Minutes' ran a story on Stuxnet several months ago and the smile from the former CIA guy they interviewed confirmed it for me. Forget exactly who it was, but he was on the Richard Clarke level of insiderness.

Elvis Telecom, Sunday, 3 June 2012 22:56 (eleven years ago) link

http://www.wired.com/threatlevel/2012/06/flame-microsoft-certificate/

It’s a scenario security researchers have long worried about, a man-in-the-middle attack that allows someone to impersonate Microsoft Update to deliver malware — disguised as legitimate Microsoft code — to unsuspecting users.

And that’s exactly what turns out to have occurred with the recent Flame cyberespionage tool that has been infecting machines primarily in the Middle East and is believed to have been crafted by a nation-state.

According to Microsoft, which has been analyzing Flame, along with numerous antivirus researchers since it was publicly exposed last Monday, researchers there discovered that a component of Flame was designed to spread from one infected computer to other machines on the same network. When uninfected computers update themselves, Flame intercepts the request to Microsoft Update server and instead delivers a malicious executable to the machine that is signed with a rogue, but technically valid, Microsoft certificate.

Milton Parker, Monday, 4 June 2012 22:14 (eleven years ago) link

four years pass...

anyone else seen the gibney doc?

sktsh, Thursday, 30 June 2016 08:16 (seven years ago) link

three weeks pass...

Watched Zero Days last night - thought it was well done, although on the long side. I've personally had my fill of "diving into cyberspace" graphic visualizations so most of my nitpicking is just that. Bias from someone who watches all the hacker documentaries.

Would wholeheartedly recommend it to anyone who hasn't followed the story closely.

Elvis Telecom, Wednesday, 27 July 2016 22:11 (seven years ago) link

apparently all the whizzy code visualisations were at least actually the real stuxnet code

sktsh, Thursday, 28 July 2016 10:39 (seven years ago) link

(I liked it too!)

sktsh, Thursday, 28 July 2016 10:40 (seven years ago) link

ten months pass...

https://www.wired.com/story/crash-override-malware

sktsh, Monday, 12 June 2017 15:31 (six years ago) link


You must be logged in to post. Please either login here, or if you are not registered, you may register here.