Categorized | AVG

Comment on Stuxnet and more Windows 0-days

Hi folks,

Over the last few days, some news organizations have been saying that Stuxnet source code is available on the black market, and that clearly therefor there is an impending Internet armageddon.

This is patently silly, on a number of levels, but silly none-the-less.

First thing is that I flat-out don’t believe Stuxnet source is available for sale on the black market or anywhere. Remember how often I say that if something sounds too good to be true, it’s not true? Well, the opposite applies too. If something sounds too bad to be true, it’s not true either. We really don’t know who built Stuxnet, or who the intended target was, be we may rest assured that whoever put that much work into it, isn’t selling it, at any price. It’s actually more probable that some no-honor-among-thieves bad guy is scamming fellow bad guys. “Sure, this is Stuxnet source code. Prove otherwise.”

Second thing is that even if it was for sale, it would require a huge amount of expertise to make it work on something other than the original target. We can be comfortable that all process controllers work differently enough that one bit of malicious code simply won’t work on all systems.

Thirdly, all avs now detect Stuxnet, so it would have to be changed significantly to evade anyone, something that again requires a large amount of expertise.

I could go on and on, but you get the idea. The fundamental concept exposed by Stuxnet can’t be ignored, but selling Stuxnet source, and bringing the world to it’s knees ain’t gonna happen.

 

The other item deserving of a comment is the current Windows 0-day, which involves an Elevation of Privilege. EoP is much less dangerous than Remote Code Execution. You still have to get the malicious code executing on this system to take advantage of the EoP.

Yes, it’s a problem, but it’s easily correct, and I’d expect it corrected in the next patch rollout.

Relax, and enjoy your weekend.

Cheers

Roger

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago