Showing posts with label Stuxnet. Show all posts
Showing posts with label Stuxnet. Show all posts

Tuesday, February 26, 2013

More Stuxnet 0.5 News

Symantec original detailed paper Stuxnet 0.5: The Missing Link [PDF] http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/stuxnet_0_5_the_missing_link.pdf

Ars article on it Revealed: Stuxnet “beta’s” devious alternate attack on Iran nuke program, http://arstechnica.com/security/2013/02/new-version-of-stuxnet-sheds-light-on-iran-targeting-cyberweapon/

Symantec's main page http://www.symantec.com/index.jsp

Lots of interesting tidbits, including fact that there are now samples dating back to at least 2005, 2 years prior to previously known oldest sample.

Thursday, November 29, 2012

Security & Hacking: International Atomic Energy Agency (IAEA) Hacked

http://nakedsecurity.sophos.com/2012/11/29/atomic-energy-hack/

"The hackers claimed the security breach was in response to what the group said was Israeli aggression, including the Stuxnet worm and the assassination of a senior Iranian nuclear scientist."

The Hackers are claiming to be from Iran, but AFAIK no evidence to support that, it could be an anti Iran group pretending to be Iran in an attempt to provoke more attacks or sanctions against Iran.

Not saying that it is, but that is a factor that always needs to be remembered in situations like these.

I do wonder though if this is one of the first visible signs of fallout of Stuxnet & Flame, something I am concerned about, have blogged about those concerns before http://cliffsesportcorner.blogspot.com/2012/11/security-hacking-chevron-was-victim-of.html

Tuesday, November 13, 2012

Security & Hacking: "CNN: Cyber Security and the Aurora Vulnerability "





Note this Aurora test was done 5 years ago, 2007

Also note the similarities to Stuxnet http://en.wikipedia.org/wiki/Stuxnet

Similar in using software hack to destroy expensive, and not easily replaced hardware.

Security & Hacking: "Chevron was a victim of Stuxnet"

http://www.livehacking.com/2012/11/12/chevron-was-a-victim-of-stuxnet/

In case you missed this news, Chevron has admitted they got Stuxnet on their machines.

This is one of the things I am really concerned about with Nationally Sponsored Cyber Warfare, the Collateral damage.

The other big concern I have is that it provides Blackhat Hackers everywhere, even low skilled ones with little target discrimination, with extremely powerful tools that they would never have had access to otherwise.

Since once an attack like Stuxnet is discovered, it doesn't take very long for people to analyze and incorporate it into Malware programs and other tools that can be bought online.

You can think about it like a Script Kiddie with a little money, being able to get the equivalent in cyber warfare destructive power to eight Fighter Jets, F-15 cost $30 million apiece while the F-16 costs $18.8 million, based on what Israel has done in the past http://www.newyorker.com/reporting/2012/09/17/120917fa_fact_makovsky.

That is what it would have taken to disrupt Iran's Nuclear Enrichment program with conventional means.