Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.
Hi all, please see this major site announcement: https://www.boards.ie/discussion/2058427594/boards-ie-2026

Iran hit by strange virus!

2»

Comments

  • Banned (with Prison Access) Posts: 34,567 ✭✭✭✭Biggins


    ScumLord wrote: »
    With all the talk of Siemens that's probably for the best.
    :pac:


  • Banned (with Prison Access) Posts: 34,567 ✭✭✭✭Biggins


    Hackers Unleash Worm That Damages Real World
    Computer hackers have unleashed the first virus designed to damage targets in the real world - opening the door to a new era of cyber-warfare.

    The Stuxnet worm is the first known malicious software designed to destroy or sabotage factories, power plants, refineries or other industrial installations.

    We are used to Trojans and viruses roaming the internet harming computers and causing financial damage, but Stuxnet is in a league of its own.
    The worm targets closed and highly secure industrial networks.
    After being introduced with a USB key, Stuxnet slips past four previously unknown vulnerabilities in the Windows operating system, so-called "zero day" vulnerabilities.

    It is rare for malicious software to exploit even two of them.
    Each one can take months for hackers to identify and more time to write software to exploit.
    The worm then hunts for specific types of computers made by German company Siemens.

    Having found its host, it lies dormant, waiting for a certain moment to override the computer's control of industrial machinery, with potentially disastrous consequences.
    This new breed of malware could wreak the kind of damage only previously seen in Hollywood disaster films.

    Imagine a nuclear power station's cooling system being overridden, for example.
    Or a railway's signals system thrown into chaos.
    Experts estimate developing the Stuxnet worm would have taken a highly specialised team between six months to a year.

    Israeli cybersecurity strategist Gadi Evron says the worm is so advanced it is almost certainly state-sponsored.
    "This would require a lot of resources on the level of a nation state.
    "Taking into account the intelligence required to attack a specific target, it would be virtually impossible that this is a lone attacker sitting at home."

    Less impressive, though, is the spread of the worm's infection.
    "The attack managed to infect, over several months, something like 30,000 to 50,000 PCs in many facilities and corporations worldwide," Uri Rivner from internet security company RSA told Sky News.
    Such a wide dissemination has helped expose the worm's existence and helped efforts to neutralise it.

    It also raises questions about the likely target for the worm.
    Iran says computers at its nuclear plant in Bushehr have been compromised by the worm but will not reveal the extent of the damage.
    Some figures suggest 60% of the Stuxnet infections are in Iran.
    That has led to a highly speculative finger of blame being pointed at Israel.

    Is the Jewish state trying to disrupt Iran's alleged nuclear weapons programme?
    We will probably never know. Other unknowns also remain. Has the worm already achieved its goal, or is it lying in wait to carry out its sabotage? Is Iran the intended victim, are other countries at risk?
    And, more worryingly, the worm is a trailblazer.

    Other hackers can learn from its pioneering methods to produce more sophisticated malware threatening other networks in the future.

    Source: http://uk.news.yahoo.com/5/20100929/twl-hackers-unleash-worm-that-damages-re-3fd0ae9.html


  • Registered Users, Registered Users 2 Posts: 17,194 ✭✭✭✭IvySlayer


    Duggy747 wrote: »
    They should've installed AVG.

    AVG sucks.

    Avira where it's at.


  • Registered Users, Registered Users 2 Posts: 5,978 ✭✭✭Soby


    Pyr0 wrote: »
    I really shouldn't have coughed on that computer..

    Cough........


  • Registered Users, Registered Users 2 Posts: 1,228 ✭✭✭Chairman Meow


    What people dont realise about stuxnet is that its not a virus that can be removed. This isnt something iran will recover from in a few weeks, or even months, this has set them back about 9 years tech wise. The infected PLCs cannot be repaired, or have the worm removed, theyre completely dead now. Any announcements iran makes int he coming years regarding their progress with uranium enrichment, is going to be a complete fabrication


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 5,949 ✭✭✭A Primal Nut


    Biggins wrote: »
    I'd be more worried about such a virus effecting the Iranians nuclear launch capability.

    You'd be worried about the Iranian's inability to launch nuclear weapons? Why?


  • Registered Users, Registered Users 2 Posts: 16,624 ✭✭✭✭Fajitas!


    Needs more zombie virus.


  • Registered Users, Registered Users 2 Posts: 9,880 ✭✭✭Canis Lupus


    What people dont realise about stuxnet is that its not a virus that can be removed.

    Why?


  • Registered Users, Registered Users 2 Posts: 3,409 ✭✭✭old_aussie


    Biggins wrote: »

    I started a thread about this several days ago, mods should combine threads.

    http://www.boards.ie/vbulletin/showthread.php?p=68196654#post68196654


  • Registered Users, Registered Users 2 Posts: 8,758 ✭✭✭Stercus Accidit


    What people dont realise about stuxnet is that its not a virus that can be removed. This isnt something iran will recover from in a few weeks, or even months, this has set them back about 9 years tech wise. The infected PLCs cannot be repaired, or have the worm removed, theyre completely dead now. Any announcements iran makes int he coming years regarding their progress with uranium enrichment, is going to be a complete fabrication

    My idea is this, cut the nuclear facilitys ethernet cables, remove the hard drives, smash them up with a hammer, and throw them in a waste paper basket, get new snazzy SSD drives (atm machine) and reinstall windows 95.
    Then, don't have ****in usb ports, fill em with glue and paper clips, and the same for the lan connections, glue in the ones you need, gum up the ones you don't and don't have an internet connection, what are you looking at, plutonium rod on rod action?

    Have an 'OFF' switch somewhere.

    Iran, my fee is 1 million dollars for which you can fix all your woes.


  • Advertisement
  • Banned (with Prison Access) Posts: 6,797 ✭✭✭karma_


    I wonder how we would react if this attack was against a station like, say.. Sellafield, and it's cooling system was overridden. New hymn-sheets please.


  • Registered Users, Registered Users 2 Posts: 11,178 ✭✭✭✭NothingMan


    ScumLord wrote: »
    There's a disappointing lack of Zombies in this Virus storey. :(
    Biggins wrote: »
    Disappointing lack of Jelly Babies too! :(


    Sorted.


  • Banned (with Prison Access) Posts: 34,567 ✭✭✭✭Biggins


    You'd be worried about the Iranian's inability to launch nuclear weapons? Why?
    Thats is not what I said.
    What I said was:
    I'd be more worried about such a virus effecting the Iranians nuclear launch capability, if they have eventually quietly progressed that far.
    It might in fact have the opposite effect and knock their whole systems out in that area - which is not a bad thing.

    ...which if read right, will make better sense.


  • Registered Users, Registered Users 2, Paid Member Posts: 2,427 ✭✭✭ressem


    Why?

    Don't see why it couldn't be removed either.
    Tricky of course, a job for the manufacturer.

    Analysis of the windows install process is ...
    http://www.symantec.com/connect/blogs/w32stuxnet-installation-details

    Once it gets onto a windows machine it replaces Step7 software with it's own version to write to the PLC and prevent other software from detecting and overwriting the PLC.
    It communicates with other clients to transfer updates using RPC.
    http://www.symantec.com/connect/blogs/stuxnet-p2p-component
    And it attempts to connect with http port 80 to communicate with the control server.

    A clean windows client should be able to rewrite the PLC to it's original state. No description of it being able to recopy itself running on the machine.

    You might wonder whether corrupt employees at JMicron or Realtek might have sold the private certs to the black market.

    There are all sorts of theory about the target systems. Belarus to Indonesia.

    There's plenty of industrial machinery in this country running NT4 with realtime kernel patches, which is maintained by the manufacturer using a logmein style system over the internet.
    External IT people aren't even aware of them in some cases until the network cable is connected up by staff. They are just told that all the computers are in the offices.


  • Banned (with Prison Access) Posts: 949 ✭✭✭maxxie


    American handy work


  • Registered Users, Registered Users 2 Posts: 1,479 ✭✭✭Notorious97


    I don’t see it as any harm setting back their nuclear program a few years, i wouldn’t trust them with nuclear weapons. If its a civilian nuclear program then thats fine.


  • Banned (with Prison Access) Posts: 34,567 ✭✭✭✭Biggins


    Well now, who would have guessed it!
    Many its seems!
    A computer worm designed to cripple Iran’s uranium enrichment programme was the result of a joint operation between the US National Security Agency and a secret Israeli cyberwarfare unit, American officials have confirmed for the first time.

    The officials, interviewed by a reporter from the New York Times, say that the Stuxnet worm was originally commissioned by President Bush but has been enthusiastically embraced by his successor, Barack Obama.
    The journalist, David Sanger, says that President Obama decided to step up cyber-attacks on Iran’s Natanz enrichment facility, even after the existence of the worm became public in 2010 after it leaked out onto the internet.

    That event was reported around the world at that time, with most experts describing it as the brainchild of the Israeli military.

    http://www.thetimes.co.uk/tto/news/world/middleeast/article3433284.ece
    The project was a success and the next step was to set experts from the National Security Agency and Israel’s Unit 8200 to work designing the complex computer worm that could attack the plant from within.

    Alternative reading: http://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html?_r=1&hp

    No wonder American Anti-Virus companies were not saying who was responsible -for it was their own people!


  • Registered Users, Registered Users 2 Posts: 3,372 ✭✭✭glynf


    maxxie wrote: »
    American handy work

    And they nabbed the IT guy as well.


  • Registered Users, Registered Users 2 Posts: 33,779 ✭✭✭✭Princess Consuela Bananahammock


    Can't believe you only had 15,000 posts back then... sees like only yesterday.

    Everything I don't like is either woke or fascist - possibly both - pick one.



  • Registered Users, Registered Users 2 Posts: 7,161 ✭✭✭af_thefragile


    Hah, i knew it was an american-israeli invention from the moment i read this.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 15,257 ✭✭✭✭Rabies


    Ikky Poo2 wrote: »
    Can't believe you only had 15,000 posts back then... sees like only yesterday.

    Less than two years to almost double it :eek:

    That is still more than my 10yrs of posting on Boards. Fec


  • Registered Users, Registered Users 2 Posts: 228 ✭✭jimmymal


    http://www.ted.com/talks/lang/en/ralph_langner_cracking_stuxnet_a_21st_century_cyberweapon.html

    AVideo on ted.com with one of the interpol investigators telling the world what they found. Vid released in March 2011


  • Registered Users, Registered Users 2 Posts: 3,404 ✭✭✭Lone Stone


    Israel


  • Registered Users, Registered Users 2 Posts: 3,135 ✭✭✭fifth


    This virus Israeli old news!


  • Registered Users, Registered Users 2 Posts: 10,291 ✭✭✭✭Standard Toaster


    The new 'Flame'virus probably has the same origins. A 20mb virus.
    Would make for a great movie


  • Closed Accounts Posts: 2,515 ✭✭✭LH Pathe


    Was this a different one, says ere in the Indo "Obama orders cyber attack on Nuclear Facility". But I heard on sky news they are also crippling businesses? And in the Hollywood blockbuster Transformers 3 the decepticons are working alongside the Iranians? why are the Iranians working with the decepticons.. :(


  • Registered Users, Registered Users 2 Posts: 33,779 ✭✭✭✭Princess Consuela Bananahammock


    Rabies wrote: »
    Less than two years to almost double it :eek:

    That is still more than my 10yrs of posting on Boards. Fec

    I've just done the the maths and, at my current rate of psting, it would take me until August of 2021 to catch up with him. And that's based on the assumption that he didn't post at all in the meantime...

    Everything I don't like is either woke or fascist - possibly both - pick one.



  • Banned (with Prison Access) Posts: 34,567 ✭✭✭✭Biggins


    UPDATE:

    The Americans are not too pleased!

    After much time of the world wondering who was creating these viruses (didn't take much guessing to be honest) and virus companies (the American ones anyway) saying that they 'suspect' who the culprits was - but refused to actually say all the time (I wonder why!), well now that its officially leaked out that it was the American government - now they are not too pleased that someone grassed them up.

    They have decided to go on a witch-hunt for the culprit.
    Feds investigate who leaked classified Stuxnet cyberattack details to NYT

    The FBI is investigating who spilled national security secrets, this time about Stuxnet and the classified cyberattack program the U.S. launched against Iran nuclear facilities. Senator Feinstein has called for Capitol Hill hearings into the leak since 'disclosures of this type endanger American lives and undermine America's national security.'

    It's not every day you "officially" learn that America and Israel not only created Stuxnet, but also ordered cyberattacks against Iran, so now it's being considered a "national security leak." It moved from conspiracy theory to a cybersecurity bombshell when the New York Times reported that the Bush administration authorized the cyber weapon program codenamed Olympic Games and President Obama continued increased cyberattacks on Iran nuclear facilities.

    The NSA and CIA also allegedly had a hand in disrupting Iran's nuclear program. Now the FBI is investigating who leaked the Stuxnet "cyber-sabotage" story to the New York Times. Additionally, Senator Dianne Feinstein, chairwoman of Intelligence Committee, wants Capitol Hill hearings into the leak.
    Source: http://www.networkworld.com/community/blog/cyber-sabatoge-feds-investigate-who-leaked-stuxnet-cyberattack-iran

    Never mind that some of their virus creations might have seeped into other systems and networks... O' no, they are just pissed that they were caught doing it, exposed for it and the world found out!

    As the saying goes "You couldn't make this stuff up!"


Advertisement
Advertisement