Round two.

JustUs

Power Member
Joined
May 6, 2012
Messages
626
Reaction score
598
Ready to knuckle up for Round two?

On Friday, a variation of the WannaCry ransomware ripped across the globe, infecting UK hospitals, a Spanish telecom company, and companies in various other sectors. After several hours, the attack was suddenly blocked from spreading much further when a security researcher registered a domain which ordered the malware to stop infecting new machines.

But, as many expected, that was only a temporary fix. Over Friday and Saturday, samples of the malware emerged without that debilitating feature, meaning that attackers may be able to resume spreading ransomware even though a security researcher cut off the original wave.

"I can confirm we've had versions without the kill switch domain connect since yesterday," Costin Raiu, director of global research and analysis team at Kaspersky Lab told Motherboard on Saturday.

On Friday, the researcher known as MalwareTech dug through the WannaCry variant used in the recent global attack and found an unregistered domain nestled in its code; a URL that the hackers seemingly used for testing purposes, or purposefully put in so they could remotely disable their malware. As it turned out, the malware was made in such a way that before every infection it would try to call out to this domain. If there wasn't a response, it would go ahead and lock down the victim machine with ransomware. But if the domain was up and running, as it was after MalwareTech registered it, the malware would stop in its tracks.

As he explained in a blog post, MalwareTech originally decided to register the domain himself in an attempt to sinkhole the malware; that is, take control of the hacker's domain, and use it to gather information about the attack.

But with other versions of WannaCry, that domain is irrelevant. If a hacker decides to launch another attack, they may be successful at infecting new machines.

The recent WannaCry variants take advantage of vulnerabilities that relate to exploits dumped by the group known as The Shadow Brokers earlier this year. Those exploits allegedly originate from the NSA, and Microsoft patched the relevant security issues for modern machines in March.

However, plenty of organisations still run legacy operating systems such as Windows XP, including the UK's National Health Service, which has already faced myriad WannaCry infections.

Late on Friday, Microsoft took the highly unusual step of pushing out a free patch for generally unsupported operating systems such as Windows XP Server 2003. CCN-CERT, the Spanish computer emergency response team, released its own tool that it says will stop WannaCry from infecting machines.

So, even though the first large wave of WannaCry may have halted, if organizations don't patch or take other mitigations, there's a chance it could just happen again.

Update: Originally, this piece included quotes from a second security researcher who tweeted he had found samples without the so-called killswitch. The researcher has since deleted those tweets and Motherboard has removed them from the article. Another researcher confirmed they have seen samples of the malware without the killswitch.
https://motherboard.vice.com/en_us/...acry-ransomware-that-struck-the-globe-is-back

The cure for the new variants is the same as the old variant: Install the security update MS17-010:
https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

Microsoft had a patch a month before the malware was released in the wild. If you have not installed the security patch, you should. This threat is serious enough that MS has released patches for Windows XP.
 
simple rule if u see an email with an attachment bin it even if its from a friend
as u wont no if there contacts where hacked sending out the email as well
 
Mac OS crew checking in. What's going on down there, guys?
 
Mac OS crew checking in. What's going on down there, guys?
Though Mac malware is comparatively rare, Apple computers are not immune, as this year’s SophosLabs malware forecast shows. Mac malware is often technically sneaky and geared towards harvesting data or providing covert remote access to thieves.
Two examples given are OSX/KeRanger-A and OSX/PWSSync-B. Both of these are ransomware for the mac
https://nakedsecurity.sophos.com/2017/02/15/rsa-2017-deconstructing-macos-ransomware/

Macworld.co.uk has a nice article for removal of malware, virus, and Trojans from your Mac:
"How to remove Mac viruses, malware and ransomware for free"
http://www.macworld.co.uk/how-to/mac-software/how-remove-mac-malware-free-viruses-attack-3594625/

The hubris of the Linux user when it comes to immunity from virus and other malware is only exceeded by the Mac user. In both cases, it is only hubris and not fact.

Just look:
Mac OS
https://packetstormsecurity.com/search/?q=mac+os
OSX
https://packetstormsecurity.com/search/?q=osx
Linux
https://packetstormsecurity.com/search/?q=linux

Be smug, be secure, and be easy to infect because you buy into hpye.
 
Though Mac malware is comparatively rare, Apple computers are not immune, as this year’s SophosLabs malware forecast shows. Mac malware is often technically sneaky and geared towards harvesting data or providing covert remote access to thieves.
Two examples given are OSX/KeRanger-A and OSX/PWSSync-B. Both of these are ransomware for the mac
https://nakedsecurity.sophos.com/2017/02/15/rsa-2017-deconstructing-macos-ransomware/

Macworld.co.uk has a nice article for removal of malware, virus, and Trojans from your Mac:
"How to remove Mac viruses, malware and ransomware for free"
http://www.macworld.co.uk/how-to/mac-software/how-remove-mac-malware-free-viruses-attack-3594625/

The hubris of the Linux user when it comes to immunity from virus and other malware is only exceeded by the Mac user. In both cases, it is only hubris and not fact.

Just look:
Mac OS
https://packetstormsecurity.com/search/?q=mac+os
OSX
https://packetstormsecurity.com/search/?q=osx
Linux
https://packetstormsecurity.com/search/?q=linux

Be smug, be secure, and be easy to infect because you buy into hpye.

This what we call "Searching For the fifth leg on a cat" where I live...
 
This is what you get when the NSA weaponizes exploits for their use in hacking anyone they want and then their shit got leaked. This is entirely the NSA's fault.
 
This is what you get when the NSA weaponizes exploits for their use in hacking anyone they want and then their shit got leaked. This is entirely the NSA's fault.

Isn't it ilegal to hack into someone else's computer without their consent, even if it comes from government institutions? What backs the N-S-A from not being demanded?
 
You would have to prove they hacked you in order to bring criminal charges and you'll never have that proof, so they continue to get away with it.
 
This is what you get when the NSA weaponizes exploits for their use in hacking anyone they want and then their shit got leaked. This is entirely the NSA's fault.

lol
 
This is what you get when the NSA weaponizes exploits for their use in hacking anyone they want and then their shit got leaked. This is entirely the NSA's fault.

lolwut? :D
 
You would have to prove they hacked you in order to bring criminal charges and you'll never have that proof, so they continue to get away with it.
was about to write the same thing :D
 
This what we call "Searching For the fifth leg on a cat" where I live...
To answer your silliness, I compiled a few things on the web (because I had to look up the meaning behind fifth leg on a cat) and conclude with my own words.

"Back home we have saying, “you are trying to find the cat’s 5th leg.”

We use the saying when people try really hard to find fault where there is none. In other words, you are looking for the one thing that will be a show stopper – like a 5th leg on a cat – so it will easier for you to defend the status quo.


To make a long story short, Chileans are known for what they call “finding the fifth leg on a cat” (looking for ways to bend the rules). I think that in today´s society, it is often not a matter of bending the rules anymore, but instead avoiding them all together."

Conclusion:
Looking into a database of exploits and vulnerabilities of an operating system is not looking for fault where there is none. It is finding known fault where it actually exists.
 
To answer your silliness, I compiled a few things on the web (because I had to look up the meaning behind fifth leg on a cat) and conclude with my own words.

"Back home we have saying, “you are trying to find the cat’s 5th leg.”

We use the saying when people try really hard to find fault where there is none. In other words, you are looking for the one thing that will be a show stopper – like a 5th leg on a cat – so it will easier for you to defend the status quo.


To make a long story short, Chileans are known for what they call “finding the fifth leg on a cat” (looking for ways to bend the rules). I think that in today´s society, it is often not a matter of bending the rules anymore, but instead avoiding them all together."

Conclusion:
Looking into a database of exploits and vulnerabilities of an operating system is not looking for fault where there is none. It is finding known fault where it actually exists.

This specific vulnerability target Windows computers only, in this case this vulnerability doesn't exist in Mac, yet you're trying to prove there are related vulnerabilities for Mac systems. Of course "If you search, you'll find". That's another saying, b-t-w. Hence, You're looking for fault where there is none.
 
Back
Top