 {"id":56,"date":"2010-07-20T14:46:01","date_gmt":"2010-07-20T14:46:01","guid":{"rendered":"http:\/\/www.garfnet.org.uk\/wordpress\/?p=56"},"modified":"2013-11-24T03:03:14","modified_gmt":"2013-11-24T03:03:14","slug":"stuxnet-another-slash-in-microhafts-death-of-a-thousand-cuts","status":"publish","type":"post","link":"https:\/\/garfnet.org.uk\/wordpress\/2010\/07\/20\/stuxnet-another-slash-in-microhafts-death-of-a-thousand-cuts\/","title":{"rendered":"Stuxnet, another slash in Microsoft&#8217;s death of a thousand cuts?"},"content":{"rendered":"<p><strong>Micro$haft<\/strong><strong> operating systems hit by yet another &#8220;zero-day&#8221; malware strike is hardly news. But this latest attack in the guise of &#8220;<em>Stuxnet<\/em>&#8221; is different. Seems from my albeit limited reading on the subject that the Stuxnet  concept strikes right at the very heart of the &#8220;<em>Windows way of doing  things<\/em>&#8220;.<\/strong><\/p>\n<p style=\"text-align: center;\"><strong><a href=\"http:\/\/www.garfnet.org.uk\/wordpress\/wp-content\/uploads\/2010\/07\/scutigera-coleoptrata.gif\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-112\" title=\"scutigera-coleoptrata\" src=\"http:\/\/www.garfnet.org.uk\/wordpress\/wp-content\/uploads\/2010\/07\/scutigera-coleoptrata.gif\" alt=\"scutigera coleoptrata animation\" width=\"400\" height=\"177\" srcset=\"https:\/\/garfnet.org.uk\/wordpress\/wp-content\/uploads\/2010\/07\/scutigera-coleoptrata.gif 400w, https:\/\/garfnet.org.uk\/wordpress\/wp-content\/uploads\/2010\/07\/scutigera-coleoptrata-300x132.gif 300w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/a><\/strong><\/p>\n<p><strong>For example:-<\/strong><\/p>\n<ol>\n<li>Windows 7 64bit insists on so-called &#8220;<em>signed  drivers<\/em>&#8221; &#8211; the excuse being that it makes the system much more secure.  But Stuxnet worm uses stolen digital certificates (from Realtek &amp;  JMicron). So it can freely install its payload ( a.sys file rootkit) as a<em> legitimate<\/em> driver.<\/li>\n<li>Whilst Verisign has now withdrawn one  of these stolen certificates, it is clear that digital signing can no  longer be relied upon as a means of verifying the integrity of Windows  software or drivers.<\/li>\n<li>Microsoft has been crowing about its  &#8220;<em>better than Unix<\/em>&#8221; UAC (user access control) system. Stuxnet completely  bypasses that. In fact, it appears that in this context that the &#8220;.lnk&#8221;  files that MS uses for its short-cuts are not subject to any form of UAC  at all!<\/li>\n<li>This does not only spread by USB sticks as some would  have us believe. Infected machines can spread the worm via ethernet  connections too. In fact, you don&#8217;t have to open a file. You merely need  to use Microsoft&#8217;s file Explorer to view a directory! So external SMB  connections and Sharepoint are both vulnerable now.<\/li>\n<li>Now it is  &#8220;<em>in the wild<\/em>&#8221; and currently infecting roughly 1000 Windows PCS a day,  other &#8220;<em>copycat<\/em>&#8221; criminals will use the same or similar techniques.<\/li>\n<\/ol>\n<p>So, if your computing is important to  you, then please don&#8217;t put all your proverbial &#8220;eggs in one basket&#8221; by  relying solely on Micro$oft&#8217;s poor quality, over-priced operating systems. Or better still, dump M$ completely! It is perfectly achievable and will save you a small fortune:-<a title=\"Vista woes may lead us to better things\" href=\"http:\/\/www.garfnet.org.uk\/joomla\/index.php?option=com_content&amp;task=view&amp;id=66&amp;Itemid=16\"><\/a><\/p>\n<blockquote><p><a title=\"Vista woes may lead us to better things\" href=\"http:\/\/www.garfnet.org.uk\/joomla\/index.php?option=com_content&amp;task=view&amp;id=66&amp;Itemid=16\">http:\/\/www.garfnet.org.uk\/joomla\/index.php?option=com_content&amp;task=view&amp;id=66&amp;Itemid=16<\/a><\/p><\/blockquote>\n<p>Some further  reading:-<\/p>\n<blockquote><p><a rel=\"nofollow\" href=\"http:\/\/news.softpedia.com\/news\/New-Stuxnet-Related-Malware-Signed-Using-Certificate-from-JMicron-148213.shtml\" target=\"_blank\">http:\/\/news.softpedia.com\/news\/New-Stuxnet-Related-Malware-Signed-Using-Certificate-from-JMicron-148213.shtml<\/a><\/p>\n<p><a rel=\"nofollow\" href=\"http:\/\/www.controlengeurope.com\/article.aspx?ArticleID=35267\" target=\"_blank\">http:\/\/www.controlengeurope.com\/article.aspx?ArticleID=35267<\/a><\/p><\/blockquote>\n<p>Probably  most easily digested Stuxnet analysis I have read so far:- <a rel=\"nofollow\" href=\"http:\/\/www.theregister.co.uk\/2010\/07\/20\/win_shortcut_vuln_exploit_code\/\" target=\"_blank\"><\/a><\/p>\n<blockquote><p><a rel=\"nofollow\" href=\"http:\/\/www.theregister.co.uk\/2010\/07\/20\/win_shortcut_vuln_exploit_code\/\" target=\"_blank\">http:\/\/www.theregister.co.uk\/2010\/07\/20\/win_shortcut_vuln_exploit_code\/<\/a><\/p><\/blockquote>\n<p><em><strong>Honk! Honk!<\/strong><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Micro$haft operating systems hit by yet another &#8220;zero-day&#8221; malware strike is hardly news. But this latest attack in the guise of &#8220;Stuxnet&#8221; is different. Seems from my albeit limited reading on the subject that the Stuxnet concept strikes right at the very heart of the &#8220;Windows way of doing things&#8220;. For example:- Windows 7 64bit &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/garfnet.org.uk\/wordpress\/2010\/07\/20\/stuxnet-another-slash-in-microhafts-death-of-a-thousand-cuts\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Stuxnet, another slash in Microsoft&#8217;s death of a thousand cuts?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,2,1],"tags":[],"class_list":["post-56","post","type-post","status-publish","format-standard","hentry","category-grumble","category-information","category-weblog"],"_links":{"self":[{"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/posts\/56","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/comments?post=56"}],"version-history":[{"count":18,"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/posts\/56\/revisions"}],"predecessor-version":[{"id":337,"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/posts\/56\/revisions\/337"}],"wp:attachment":[{"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/media?parent=56"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/categories?post=56"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/garfnet.org.uk\/wordpress\/wp-json\/wp\/v2\/tags?post=56"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}