Hi!
I have a question:
I’m sure people here have heard about this hacker attacks which infected 99 countries.
Does somebody know how they do it? I mean, can they really attack my computer without any file I need to run to get the virus. Are also Mac computers affected?
We are just a little bit afraid to get the virus. I’m sure it exists many really good programmers in this forum who can answer me.
They exploit bugs like this one. This one is Windows specific but all platforms get security fixes which generally you want to apply as soon as possible.
From what I’ve read; the “attack” was a shoddy virus using leaked NSA code to exploit a hole in old Windows O/S; namely XP and Vista that hadn’t been patched, and on machines with no up to date antivirus software.
It seems to have gotten in by staff viewing dodgy websites on these computers (probably porn), and then spreading in the local network.
These hacks are possible primarily because users are, in general, dumb.
What you do, is you find an exploit on a device’s OS or software running on that OS that will allow you to gain elevated priviledges over that device. From there, you run any code you like, basically- you’re running as if you were the system. This is basically how ‘rooting’ your phone works too.
Then, to actually use this exploit on the target, you need a way of transmitting it. So you embed your executable into a PDF’s slack space or something, and send that to somebody. That person opens the PDF, the exe code is executed in some way, et voila: they’re infected. Then, likely, that malicious exe sends an email blast to all the stored emails it can find on that machine (usually those things are available somewhere) and the process repeats.
This only really works because the person downloaded stuff from someone they didn’t know, an address they didn’t recognised, and allowed it to happen. But people conistently do make mistakes like these- basically everyone will at some point.
From what I understand, this recent attack works by first needing some way to get on a computer, such as being downloaded, but then once on a computer, it takes advantage of a windows SMBv1 vulnerability to spread the virus to all computers on that network. So even if you were smart and safe, if someone on your network wasnt, then you are at risk. Not completely sure though. I disabled SMBv1 for now, as advised, either that or download the patch that was released a month ago.
The bug I linked to earlier doesn’t need any user intervention. For an attack based on that flaw, just receiving the ransomware as an email attachment would be enough to infect the system if the fix hasn’t been applied. From the Register article:
“In other words, while Microsoft’s scanner is silently searching your incoming email for malware, it can be tricked into running and installing the very sort of software nasty it’s supposed to catch and kill.”
I doubt there was suddenly one day where a lot more users than normal decided to click on something dumb, so I am expecting this flaw to be involved. It might be coincidental that a patch for that was released May 8th and the biggest ever ransomware attack came within days (crackers reverse engineer patches), but if that flaw wasn’t the delivery mechanism then things might get worse. Microsoft annoying people with Windows 10 auto installs to the point where they disable updates won’t have helped.
Just being on an Apple device won’t protect you. You need active security measures like antivirus from reputable firms (Symantec/Norton is the oppositive of reputable for the record) and regular backups so you can revert back to a state when your system didn’t lose files.
Yes, if your computer is vulnerable to the exploit and connected to a network without a firewall or routing to protect it, then your computer can get hacked by this latest problem. The vulnerability is in part of the SMB network protocol, so a computer can be vulnerable to this attack simply by being connected to a network (either wired or wireless). The user does not need to open anything to get attacked.
There was a patch released in March that fixed the vulnerability for all supported versions of Windows. There was also a patch released Friday for unsupported/outdated versions of Windows (XP, 2003). Make sure you have your computer completely updated.
A lot of businesses (including hospitals and banks) still have outdated versions of Windows. That is at least part of the problem we are seeing right now in the IT sector with the WannaCry/WannaCrypt exploit. I even know of a hospital still running Windows 2000. As long as people choose to run outdated operating systems, this kind of stuff will keep being a big problem.
Also, it is very tacky that our own government knew about this vulnerability but chose not to share that information with security contacts at Microsoft, because our government wanted the option to use those security vulnerabilities to hack other people.
Yeah. This is something that needs to be discussed here in the US, but probably won’t be. The entire WannaCry/WannaCrypt situation could have been prevented if the US government had notified Microsoft about the vulnerability instead of keeping it for themselves to use.
Admittedly, I have no idea what other bad things the US government successfully prevented by using this vulnerability, so my assessment is one sided.
True. But I’m betting the US government wasn’t the only ones to know about the vulnerability. Isn’t there a big thing over there at the moment over Russian hackers getting places they shouldn’t do? I’m gonna go out on a limb and say that US security takes more damage from open vulnerabilities then it gains.
I see computer virus based warfare as similar to biological or chemical warfare. Its just too easy for the agents to get out of control and damage targets that they weren’t ever intended to hit. There was a targeted virus built to spread through the Iranian nuclear enrichment facilities and destroy their equipment. Except the nature of viruses is they seldom stay where they were originally put. That same virus has been detected outside of Iran. And there isn’t much stopping it getting into an antiquated chemicals factory somewhere else in the world and causing untold damage.
I’m not sure the ‘leak’ of the virus/trojan toolkits wasn’t intentional to coerce businesses and governments around the world to up their attentiveness to computer security and in the process knock out a lot of the computers that are already being used as abusive botnets. They tend to listen much more when they are told they’ll have to pay money to get control of their important files back.
As the Comey firing shows the media and government are overflowing with spies and double agents trying to control the world’s business and government leaders via ‘leaks’ to the press and now with computer code. They’ve created such a tangled web of lies it’s hard to try and figure out who is even exercising a modicum of truth telling instead of simply engaging in another crass manipulation of your feelings and emotions via forms of mudslinging and security breach claims.
To be fair, there has been a security update available from Microsoft which fixes this exploit for months now. The issue is people not keeping their OS up to date, that’s the reason this is so widespread.
Months in this case being exactly two. I have computers that I haven’t turned on in two months, it’s not unreasonable that people have unpatched systems. I hope this doesn’t turn into a Blaster/sasser situation, where the minute you connect an unpatched machine to the internet it gets infected.
The NHS systems are used daily. Cause of problem: Poor maintenance.
Yes there are going to be edge cases like yours, but I hardly expect that when you turn those systems on, you would choose to leave them unpatched? And if you haven’t used them in months, is there anything actually useful on it? Just wipe the drive and start over if it gets encrypted (should also mention, you have to actively open dodgy emails etc to get infected in this case).
Point is, it’s an easily avoided situation, and also a situation that any capable IT department should be able to recover from quickly.
Yes it’s easily avoided! Just because many organisations didn’t take the precautions doesn’t mean it isn’t easy to do. Like I said before it’s negligence of keeping systems up to date.
Your special case may be different, but those listed organisations very likely use their systems every day, and also likely have IT departments that should know better. All it takes is to keep the OS up to date…
It’s not that simple. netmarketshare shows over 8% are still browsing on Windows XP in 2017 (no updates for over 2 years). Some very expensive cad cam systems never got updated software for their Windows 98 control PCs, updating one of those can mean replacing a system that costs over half a million. Try running some old games on a modern PC and then consider whether the bespoke applications that say the UK’s NHS rely on might have similar problems. Keeping an os up to date isn’t always an option without considerable related expenses in hardware and application updates.