| Author |
Message |
 |
|
|
 |
|
Advert
|
Forum adverts like this one are shown to any user who is not logged in. Join us by filling out a tiny 3 field form and you will get your own, free, dakka user account which gives a good range of benefits to you:
- No adverts like this in the forums anymore.
- Times and dates in your local timezone.
- Full tracking of what you have read so you can skip to your first unread post, easily see what has changed since you last logged in, and easily see what is new at a glance.
- Email notifications for threads you want to watch closely.
- Being a part of the oldest wargaming community on the net.
If you are already a member then feel free to login now. |
|
 |
![[Post New]](/s/i/i.gif) 2010/09/23 21:10:07
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
!!Goffik Rocker!!
(THIS SPACE INTENTIONALLY LEFT BLANK)
|
Stuxnet worm 'targeted high-value Iranian assets'
By Jonathan Fildes
Technology reporter, BBC News
One of the most sophisticated pieces of malware ever detected was probably targeting "high value" infrastructure in Iran, experts have told the BBC.
Stuxnet's complexity suggests it could only have been written by a "nation state", some researchers have claimed.
It is believed to be the first-known worm designed to target real-world infrastructure such as power stations, water plants and industrial units.
It was first detected in June and has been intensely studied ever since.
"The fact that we see so many more infections in Iran than anywhere else in the world makes us think this threat was targeted at Iran and that there was something in Iran that was of very, very high value to whomever wrote it," Liam O'Murchu of security firm Symantec, who has tracked the worm since it was first detected, told BBC News.
Some have speculated that it could have been aimed at disrupting Iran's delayed Bushehr nuclear power plant or the uranium enrichment plant at Natanz.
However, Mr O'Murchu and others, such as security expert Bruce Schneier, have said that there was currently not enough evidence to draw conclusions about what its intended target was or who had written it.
Initial research by Symantec showed that nearly 60% of all infections were in Iran. That figure still stands, said Mr O'Murchu, although India and Indonesia have also seen relatively high infection rates.
'Rare package'
Stuxnet was first detected in June by a security firm based in Belarus, but may have been circulating since 2009.
Unlike most viruses, the worm targets systems that are traditionally not connected to the internet for security reasons.
Instead it infects Windows machines via USB keys - commonly used to move files around - infected with malware.
Once it has infected a machine on a firm's internal network, it seeks out a specific configuration of industrial control software made by Siemens.
The worm searches out industrial systems made by Siemens
Once hijacked, the code can reprogram so-called PLC (programmable logic control) software to give attached industrial machinery new instructions.
"[PLCs] turn on and off motors, monitor temperature, turn on coolers if a gauge goes over a certain temperature," said Mr O'Murchu.
"Those have never been attacked before that we have seen."
If it does not find the specific configuration, the virus remains relatively benign.
However, the worm has also raised eyebrows because of the complexity of the code used and the fact that it bundled so many different techniques into one payload.
"There are a lot of new, unknown techniques being used that we have never seen before," he said These include tricks to hide itself on PLCs and USB sticks as well as up to six different methods that allowed it to spread.
In addition, it exploited several previously unknown and unpatched vulnerabilities in Windows, known as zero-day exploits.
"It is rare to see an attack using one zero-day exploit," Mikko Hypponen, chief research officer at security firm F-Secure, told BBC News. "Stuxnet used not one, not two, but four."
He said cybercriminals and "everyday hackers" valued zero-day exploits and would not "waste" them by bundling so many together.
Microsoft has so far patched two of the flaws.
'Nation state'
Mr O'Murchu agreed and said that his analysis suggested that whoever had created the worm had put a "huge effort" into it.
"It is a very big project, it is very well planned, it is very well funded," he said. "It has an incredible amount of code just to infect those machines."
His analysis is backed up by other research done by security firms and computer experts.
"With the forensics we now have it is evident and provable that Stuxnet is a directed sabotage attack involving heavy insider knowledge," said Ralph Langner, an industrial computer expert in an analysis he published on the web.
"This is not some hacker sitting in the basement of his parents' house. To me, it seems that the resources needed to stage this attack point to a nation state," he wrote.
Mr Langner, who declined to be interviewed by the BBC, has drawn a lot of attention for suggesting that Stuxnet could have been targeting the Bushehr nuclear plant.
In particular, he has highlighted a photograph reportedly taken inside the plant that suggests it used the targeted control systems, although they were "not properly licensed and configured".
Mr O'Murchu said no firm conclusions could be drawn.
However, he hopes that will change when he releases his analysis at a conference in Vancouver next week.
"We are not familiar with what configurations are used in different industries," he said.
Instead, he hopes that other experts will be able to pore over their research and pinpoint the exact configuration needed and where that is used.
'Limited success'
A spokesperson for Siemens, the maker of the targeted systems, said it would not comment on "speculations about the target of the virus".
He said that Iran's nuclear power plant had been built with help from a Russian contractor and that Siemens was not involved.
"Siemens was neither involved in the reconstruction of Bushehr or any nuclear plant construction in Iran, nor delivered any software or control system," he said. "Siemens left the country nearly 30 years ago."
Siemens said that it was only aware of 15 infections that had made their way on to control systems in factories, mostly in Germany. Symantec's geographical analysis of the worm's spread also looked at infected PCs.
"There have been no instances where production operations have been influenced or where a plant has failed," the Siemens spokesperson said. "The virus has been removed in all the cases known to us."
He also said that according to global security standards, Microsoft software "may not be used to operate critical processes in plants".
It is not the first time that malware has been found that affects critical infrastructure, although most incidents occur accidentally, said Mr O'Murchu, when a virus intended to infect another system accidently wreaked havoc with real-world systems.
In 2009 the US government admitted that software had been found that could shut down the nation's power grid.
And Mr Hypponen said that he was aware of an attack - launched by infected USB sticks - against the military systems of a Nato country.
"Whether the attacker was successful, we don't know," he said.
Mr O'Murchu will present his paper on Stuxnet at Virus Bulletin 2010 in Vancouver on 29 September. Researchers from Kaspersky Labs will also unveil new findings at the same event.
So was it the U.S., Israel, or China?
|
-- -- -- -- -- -- -- --
Do you remember that time that thing happened?
This is a bad thread and you should all feel bad |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 22:57:04
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
[MOD]
Anti-piracy Officer
Somewhere in south-central England.
|
One day we will all die because of malware.
The recent Twitter mouseover exploit shows the dangers.
|
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 22:59:23
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Legendary Master of the Chapter
|
US
|
From whom are unforgiven we bring the mercy of war. |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 23:10:07
Subject: Re:Histories most advanced malware attack seems to have been directed at Iran
|
 |
Fixture of Dakka
|
Iran. It was an inside job.
|
|
This message was edited 1 time. Last update was at 2010/09/23 23:10:35
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 23:11:41
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Longtime Dakkanaut
|
I don't understand why they didn't just nuke it from orbit.
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 23:15:05
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
[DCM]
.
|
KK - what was that?
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 23:17:24
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Fixture of Dakka
|
rubiksnoob wrote:I don't understand why they didn't just nuke it from orbit.
Look, those two specimens are worth millions to the bio-weapons division, right? Now, if you're smart, we can both come out of it as heroes, and we will be set up for life.
|
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 23:31:25
Subject: Re:Histories most advanced malware attack seems to have been directed at Iran
|
 |
Fixture of Dakka
Manchester UK
|
George Spiggott wrote:Iran. It was an inside job.
Suicide-hacker.
|
Cheesecat wrote:
I almost always agree with Albatross, I can't see why anyone wouldn't.
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/23 23:38:17
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Decrepit Dakkanaut
Mesopotamia. The Kingdom Where we Secretly Reign.
|
rubiksnoob wrote:I don't understand why they didn't just nuke it from orbit.
Agreed. It's the only way to be sure.
OT:
I blame 4chan.
|
Drink deeply and lustily from the foamy draught of evil.
W: 1.756 Quadrillion L: 0 D: 2
Haters gon' hate. |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 00:11:43
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Calculating Commissar
|
Monster Rain wrote: OT: I blame 4chan. Some Iranian Tech worker must've been caught at work browsing the PROMOTIONS section
|
|
This message was edited 1 time. Last update was at 2010/09/24 00:11:52
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 00:13:28
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Longtime Dakkanaut
|
Iran, US or most likely Is'we can do no wrong us, we're the victims when you think about it'rael.
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 00:17:35
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Decrepit Dakkanaut
|
Mr Mystery wrote:Iran, US or most likely Is'we can do no wrong us, we're the victims when you think about it'rael.
Im going out on a limb here, and saying it was Israel backed by the US. I can explain further but youd have to get out your tinfoil hats to stay with me
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 00:19:41
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Sybarite Swinging an Agonizer
The Ministry of Love: Room 101
|
Alpharius wrote:KK - what was that? Someone found out you could execute JavaScript in tweets, and it was exploited by using the mouseOver function to call porn popups apparently. I find it heartily amusing as I don't use or read twitter Edit: I may have the details wrong, the article where I read about it was the same place that also had an article on the topic of this thread that mostly talked about the fact that it was from a USB DRIVE and it was aimed at NUCLEAR POWER....I should read a better news site
|
|
This message was edited 1 time. Last update was at 2010/09/24 00:21:25
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 00:56:10
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Napoleonics Obsesser
|
I hope it was us. Those iranians are just asking to be destroyed. Automatically Appended Next Post: KingCracker wrote:Mr Mystery wrote:Iran, US or most likely Is'we can do no wrong us, we're the victims when you think about it'rael.
Im going out on a limb here, and saying it was Israel backed by the US. I can explain further but youd have to get out your tinfoil hats to stay with me
I agree. The Israeli's have every reason to terrorize Iran.
|
|
This message was edited 1 time. Last update was at 2010/09/24 00:57:44
If only ZUN!bar were here... |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:03:08
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Fixture of Dakka
Manchester UK
|
Samus_aran115 wrote:I hope it was us. Those iranians are just asking to be destroyed.
Why?
Quiet, everyone - I want to see what he says.
|
Cheesecat wrote:
I almost always agree with Albatross, I can't see why anyone wouldn't.
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:10:50
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Napoleonics Obsesser
|
Albatross wrote:Samus_aran115 wrote:I hope it was us. Those iranians are just asking to be destroyed.
Why?
Quiet, everyone - I want to see what he says.
You know....Being all sneaky over there..Across the ocean....with their nukes just ready to blow off....You don't know what they'll do next!
|
If only ZUN!bar were here... |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:14:30
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Fixture of Dakka
Manchester UK
|
You have no idea, do you?
|
Cheesecat wrote:
I almost always agree with Albatross, I can't see why anyone wouldn't.
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:18:44
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Napoleonics Obsesser
|
I don't like the looks of them is all  What with their hats...and beards....Why do they cover up their women?
I kid, I kid. Isn't Iran what's left of the safavid empire?
|
If only ZUN!bar were here... |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:19:06
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Sybarite Swinging an Agonizer
The Ministry of Love: Room 101
|
You know....Being all sneaky over there..Across the ocean....with their nukes just ready to blow off....You don't know what they'll do next! Sort of like....America? Except you guys will probably eventually start selling your Nuclear capability to boost the economy. Australia on the other hand has no nukes, and we believe that nuclear power and dangerous and scary and new-fangled. But well sell you plenty of uranium! *This post brought to you with zero references or real facts*
|
|
This message was edited 1 time. Last update was at 2010/09/24 01:19:42
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:20:20
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Secret Force Behind the Rise of the Tau
USA
|
What with their hats...
Whoa there! There's no need to drag the innocent little hats into this. They're just following orders!
|
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:24:10
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Napoleonics Obsesser
|
del'Vhar wrote:You know....Being all sneaky over there..Across the ocean....with their nukes just ready to blow off....You don't know what they'll do next!
Sort of like....America?
Except you guys will probably eventually start selling your Nuclear capability to boost the economy.
Australia on the other hand has no nukes, and we believe that nuclear power and dangerous and scary and new-fangled.
But well sell you plenty of uranium!
*This post brought to you with zero references or real facts*
Australia thinks everything is scary and new-fangled. Like squirrels. Do you have squirrels? What about transistors? Are those scary to you too? I'm sure you guys are totally comfortable with the fact that your country was a giant prison until recently
Australia's pretty cool though. But seriously, do you have squirrels?
|
If only ZUN!bar were here... |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:31:41
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Sybarite Swinging an Agonizer
The Ministry of Love: Room 101
|
We have possums...theyd kick a squirrels backside all day!
An wombats...those things will feth you up.
But yeah, from what I understand the powers that be in Australia are basically dead set against Nuclear power "just in case" and point to the few times something bad has actually happened.
That and the fact that AFAIK theres no good way to get rid of the waste, since we cant just pump it into the atmosphere like we do with coal power, then argue that glabal warming probably isnt anything to be worried about
And Australia isnt a giant prison, we turn other countries into prisons with offshore processing for asylum seekers!
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:37:53
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Gore-Soaked Lunatic Witchhunter
Australia (Recently ravaged by the Hive Fleet Ginger Overlord)
|
Why would Australia build Nuclear Weapons when it can give all the Uranium away at low, low prices on to yoouuuu!
|
Smacks wrote:
After the game, pack up all your miniatures, then slap the guy next to you on the ass and say.
"Good game guys, now lets hit the showers" |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:42:51
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Napoleonics Obsesser
|
What about koala's? I'm sure no one would care if they all dropped off the face of the earth
What a confusing animal. It serves no real 'niche' in the food web, nor is it a major prey animal...It's a wonder they've managed to survive!
|
If only ZUN!bar were here... |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:46:17
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Gore-Soaked Lunatic Witchhunter
Australia (Recently ravaged by the Hive Fleet Ginger Overlord)
|
Samus_aran115 wrote:What about koala's? I'm sure no one would care if they all dropped off the face of the earth
What a confusing animal. It serves no real 'niche' in the food web, nor is it a major prey animal...It's a wonder they've managed to survive!
Do you mean the passive koalas located in the temperate regions, or their larger cousins in the sub-tropics?
|
|
This message was edited 1 time. Last update was at 2010/09/24 01:47:25
Smacks wrote:
After the game, pack up all your miniatures, then slap the guy next to you on the ass and say.
"Good game guys, now lets hit the showers" |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:47:57
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Sybarite Swinging an Agonizer
The Ministry of Love: Room 101
|
Because they can kill damn near anything that would think of attacking them. Good ole' Australia, even the cuddly critters can tear your face off. Also, the noises they can make are terrifying the first time you hear them at night. Edit: Thats a great pic EF! consider it stolen
|
|
This message was edited 1 time. Last update was at 2010/09/24 01:48:43
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:50:26
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Gore-Soaked Lunatic Witchhunter
Australia (Recently ravaged by the Hive Fleet Ginger Overlord)
|
Rangers have the hardest jobs. They're actually the ones who are most often attacked, despite the preventative measures taken. Those outlets in the Northern Territory, and even Queensland, are the hardest hit.
|
Smacks wrote:
After the game, pack up all your miniatures, then slap the guy next to you on the ass and say.
"Good game guys, now lets hit the showers" |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:50:33
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Longtime Dakkanaut
|
del'Vhar wrote:Because they can kill damn near anything that would think of attacking them.
Good ole' Australia, even the cuddly critters can tear your face off.
Also, the noises they can make are terrifying the first time you hear them at night.
Edit: Thats a great pic EF! consider it stolen
Peacocks make the most blood curdling noises. . . not a nice thing to be woken up by in the middle of the night.
|
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:53:01
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Gore-Soaked Lunatic Witchhunter
Australia (Recently ravaged by the Hive Fleet Ginger Overlord)
|
del'Vhar wrote:
Edit: Thats a great pic EF! consider it stolen
I don't see why a Governmental warning is any laughing matter, like these drinking adds.
|
Smacks wrote:
After the game, pack up all your miniatures, then slap the guy next to you on the ass and say.
"Good game guys, now lets hit the showers" |
|
|
 |
 |
![[Post New]](/s/i/i.gif) 2010/09/24 01:57:48
Subject: Histories most advanced malware attack seems to have been directed at Iran
|
 |
Sybarite Swinging an Agonizer
The Ministry of Love: Room 101
|
Oh I wasnt laughing....Im going to print them out poster size, and hang them up wherever the international student residences are in the Uni I work near! Those poor guys gotta be warned that you can't just walk around near trees over here
|
|
This message was edited 1 time. Last update was at 2010/09/24 01:58:17
|
|
|
 |
 |
|
|