[HN Gopher] Windows 0-day was exploited by North Korea to instal...
       ___________________________________________________________________
        
       Windows 0-day was exploited by North Korea to install advanced
       rootkit
        
       Author : fortran77
       Score  : 151 points
       Date   : 2024-08-20 19:05 UTC (4 days ago)
        
 (HTM) web link (arstechnica.com)
 (TXT) w3m dump (arstechnica.com)
        
       | graycat wrote:
       | Been afraid of something like that:
       | 
       | Mostly running Windows 7 Professional with latest patches from
       | Microsoft. Had an HP Laptop with Windows 10 Home Edition where
       | the hard disk failed. So, got another HP, with Windows 11 Home.
       | 
       | I'm a _traditional_ Windows user and am writing software in .NET,
       | IIS, ASP.NET, SQL Server. My most important tools are Rexx for a
       | scripting language and KEdit for my text editor. I don 't want
       | Windows to be more like a _smartphone_.
       | 
       | Microsoft made a lot of changes from 10 to 11, and for my
       | traditional usage made Windows too different to use. Bluntly I
       | have to regard 11 as unacceptable for my traditional usage on 7
       | and 10 and am eager to replace 11 with 10.
       | 
       | Sooooo, I'm ready to pull hair and scream trying to find a way to
       | install a genuine, 100% authentic, dyed in the wool, DVD, SSD,
       | _SEO_ , whatever, I can use to install 10 on my new HP.
       | 
       | HELP!!!!!
        
         | lhamil64 wrote:
         | I'm curious why you prefer Rexx as a scripting language on
         | Windows over something like Python or even PowerShell. I use it
         | quite a bit for work and find it pretty limiting. With a lack
         | of built in libraries even some simple stuff like parsing JSON
         | can be a huge pain.
        
           | graycat wrote:
           | Why Rexx? (A) Used it for decades. (B) The latest _Object
           | Oriented Rexx_ has some nice things, e.g., SysFileTree to get
           | a nice file of all the names in a directory tree. (C) Yup, I
           | agree that could use more tools and not have to _roll my
           | own_. (D) Sure, looked at PowerShell: Looks like it has some
           | nice _powerful_ features but a, uh, _goofy_ syntax -- intend
           | to do more, maybe a lot more, with it. (E) Lots of people are
           | taking Python seriously, and for more than just a scripting
           | language, e.g., maybe all the software for a significant Web
           | site. Intend to devote a weekend to Python.
           | 
           | One little thing I did recently with Rexx was take an email
           | message, all in just text, that had a Web page, as a MIME
           | (multi-media Internet Mail Extensions or some such) Part, get
           | the MIME part with the HTML, fix the email '=' characters
           | used for _splitting_ long lines, replaced some uses of
           | special characters, and did get a Web page that Firefox would
           | read. Worked? Yup. Elegant? Nope.
        
         | wildzzz wrote:
         | Here's some good news: your license for Windows 11 is probably
         | good for Windows 10 as well. Grab a Windows 10 install media
         | from Microsoft and do a clean install on the drive.
         | 
         | https://www.microsoft.com/en-us/software-download/windows10I...
        
           | jwrallie wrote:
           | Still there is only one year left of support if you do that.
        
             | graycat wrote:
             | I still get "security updates" for Windows 7 Professional
             | and am unsure what the lack of "support" might mean for my
             | business.
        
               | jborean93 wrote:
               | Extended support ended in Jan 2020 and the paid ESU
               | support ended in Jan 2023 [1]. Are you sure those updates
               | aren't just defender/AV definition updates rather than
               | actual OS updates?
               | 
               | [1] - https://learn.microsoft.com/en-
               | us/lifecycle/faq/extended-sec...
        
               | graycat wrote:
               | Perhaps: "Defender" is what I've noticed.
        
               | bravetraveler wrote:
               | Anti-virus definitions, not really exhaustive security
               | maintenance. Defender is their AV. The firewall/kernel
               | isn't included, for example
               | 
               | How important that is, no idea! The firewall is probably
               | passable but I generally don't know your risk profile.
               | 
               | Applications and the rest of the system offer a lot of
               | surface area
        
               | pajko wrote:
               | https://www.catalog.update.microsoft.com/Search.aspx?q=20
               | 24-...
        
               | hnuser123456 wrote:
               | windows embedded standard
        
               | dlachausse wrote:
               | You should try Start11, it gives you a classic Windows UI
               | on modern versions of Windows that are still actively
               | receiving security patches.
               | 
               | https://www.stardock.com/products/start11/
        
             | ck2 wrote:
             | Windows10 LTSC ftw, EOL 2032
             | 
             | https://old.reddit.com/r/WindowsLTSC/wiki
        
               | amaccuish wrote:
               | But their license probably doesn't cover that...
        
           | graycat wrote:
           | Yes, thanks.
           | 
           | My understanding from a lot of Google/browsing is that my new
           | HP has will a Windows _Product Code_ in the BIOS (or UEFI)
           | and, from that product code, will permit installing either of
           | Windows 10 Home or Windows 11 Home.
           | 
           | Right.
           | 
           | Thanks for the URL. That is for
           | 
           | "Create Windows 10 installation media"
           | 
           | and
           | 
           | "...download and run the media creation tool."
           | 
           | Believe I did try that. Soooo, tried to run that "tool" on
           | Windows 7 Professional, taking the option to create media for
           | "another computer", but got a message that now that tool
           | won't run on 7.
           | 
           | So, looks like I should try running the "media creation tool"
           | on my new HP with Windows 11. Then use that "media" just
           | created to install 10 on the new HP.
           | 
           | While doing that work, also create install media for Windows
           | 11 _just in case_ at some point would be glad to have it.
           | 
           | Thanks.
        
             | fuzzfactor wrote:
             | I think a more ultimate "just in case" is downloading the
             | ISO image file which is what you would need if you were
             | going to burn a traditional Windows installation DVD-ROM.
             | 
             | The ISO file just sits in a folder like a last resort
             | installation backup, but it can then be used to create a
             | fresh bootable Windows installation USB stick (or DVD) any
             | time from then on without need to access the internet after
             | that.
             | 
             | Well you might want to use a program called Rufus which
             | will more conveniently turn a Windows installation ISO into
             | a bootable USB drive than the Media Creation Tool anyway.
             | 
             | Plus IIRC, Rufus would run under Windows 7, but you will
             | need to use last year's version of Rufus, look at this page
             | of current and past versions:
             | 
             | https://rufus.ie/downloads/
             | 
             | You will see that rufus-3.22.exe from 2023 is the newest
             | thing that was intended to run on W7, so download that,
             | download the W10 ISO from Microsoft, and you can then run
             | Rufus to choose the ISO from your own filesystem that you
             | would like to turn into a bootable USB stick.
             | 
             | That USB stick would then be the Windows 10 installation
             | media like you probably wanted to begin with. It also has
             | some recovery functions and a powerful command line on its
             | own if you need it.
             | 
             | Really still functions this way not much different than the
             | original W7 installation DVDs up to W11 so far.
        
               | password4321 wrote:
               | All you need for an .ISO is fido (from rufus). But since
               | nowadays Windows 10 is too large for a standard DVD, USB
               | is the way (I prefer Ventoy). Not sure the best way to
               | get 'hold of an .ISO from back in the reasonable size
               | days.
               | 
               | https://github.com/pbatard/Fido
               | 
               | https://www.ventoy.net/en/download.html
        
         | giancarlostoro wrote:
         | I also do .NET but I went with Linux instead. Something Ubuntu
         | based like POP OS or just plain any of the official Ubuntu
         | flavors did the trick for me.
         | 
         | Heck for fun I migrated a .NET 3.5 project thats been untouched
         | for centuries all the way to the latest all on Linux, and it
         | looks like it worked with barely any issues.
        
           | graycat wrote:
           | Versions of Linux seem to have a lot of value and are real
           | competition for all the versions of Windows.
           | 
           | But I decided to concentrate on just one operating system and
           | there picked Windows. Otherwise I want to concentrate on my
           | needed software development, the inevitable system
           | management, and, then most of all, the business itself.
           | 
           | I'm guessing that, whatever frustrations, Windows will be
           | able to support the computing for my business.
        
             | giancarlostoro wrote:
             | I agree, I gave up on Windows since the deployment target
             | for .NET services (web, etc) are now fully Linux, at least
             | in my case. Linux is a known OS and there's thousands of
             | experts. We can see under the covers and get a deep
             | understanding. I highly recommend you install Linux on an
             | older laptop and try it on your time off. As for package
             | management, in terms of .NET its just nuget still, in terms
             | of installing packages, there's UIs for them, but yeah you
             | do need to sit down and read about it so you have some
             | familiarity for when something goes wrong, which in the
             | case of Ubuntu / Debian is only really the case if you're
             | installing packages not maintained by them, Debian has
             | insanely strict rules on what they consider stable, which
             | means you get a slightly "dated" set of packages, but the
             | confidence that your OS will not blow up out of the blue.
             | 
             | What pushed me over the edge to Linux was Windows Defender
             | sends files to Microsoft for analysis, but there's no audit
             | trail for what those files are. It could be my PII for
             | taxes, could be highly proprietary documents for my
             | employer / company. I have no way to know what the heck
             | their heuristics or whatever has seemingly found suspicious
             | and uploaded.
        
               | graycat wrote:
               | > What pushed me over the edge to Linux was Windows
               | Defender sends files to Microsoft for analysis, but
               | there's no audit trail for what those files are.
               | 
               | Gads. I should look into that. Yup, one more item on my
               | system management TODO list.
        
             | stackskipton wrote:
             | >I'm guessing that, whatever frustrations, Windows will be
             | able to support the computing for my business.
             | 
             | Azure/.Net SRE/DevOps whatever person here. I wouldn't be
             | that confident in that bet.
             | 
             | Windows Server, if you look at change log for each version,
             | it's not a ton and IIS hasn't seen any love for a while.
             | While Microsoft will continue to offer it, it's mostly in
             | maintenance mode.
             | 
             | .Net (Core) team is clearly over Windows. I've talked to
             | Microsoft developers on this several times, they have been
             | extremely upfront about it. Linux is preferred operating
             | system for running .Net. Performance is much better,
             | testing is better and it's cheaper which is massive
             | positive. .Net powers a ton of Azure and Linux is first
             | choice.
             | 
             | Speaking of other Microsoft Technologies, SQL Server is
             | getting worse and worse and I'm seeing more and more .Net
             | convert to MySQL or PostGres. Proget, the king of .Net
             | Software Packaging is moving to PostGres:
             | https://blog.inedo.com/inedo/so-long-sql-server-thanks-
             | for-a...
        
           | zamalek wrote:
           | Linux is also a much nicer desktop OS to boot, pun intended.
        
         | lewispollard wrote:
         | I used to work at the IBM lab where Rexx was created, funnily
         | enough I've never heard of anyone using it in the wild!
        
           | daghamm wrote:
           | Wasn't the Amiga version pretty big back in the day?
        
             | drsopp wrote:
             | Yes, ARexx was big. A lot of popular software had an ARexx
             | API so you could script across programs. Pretty awesome. I
             | haven't seen anything like that since.
        
           | graycat wrote:
           | "Wild"? I used to work at IBM!
        
             | lewispollard wrote:
             | Aha!
        
         | jiggawatts wrote:
         | The weird thing about rants like this is I tell customers that
         | there are very few business-oriented new features in Windows 11
         | that justifies the upgrade, but there are quite a few
         | developer-oriented features that are unique to it.
         | 
         | Windows Terminal is a nice example, but proper support for
         | Windows Containers is huge. It was "technically possible" to
         | containerise workloads on Windows 10 but you had to maintain
         | the exact same patch level as the server OS the containers
         | would run on! Windows 11 removed this restriction.
         | 
         | There's also Dev Drive and a bunch of other small things like
         | HTTP/3 and TLS 1.3 support and whatnot.
         | 
         | At $dayjob I have to hold the hand of helpless devs mired in
         | corporate miasma complete with out-of-date Windows 10 desktops.
         | I regularly have the issue of trying to show them something and
         | failing because I forgot I have Windows 11 and they don't.
        
       | hulitu wrote:
       | > Windows 0-day was exploited by North Korea to install advanced
       | rootkit
       | 
       | Only by North Korea ? /s
        
       | ec109685 wrote:
       | Somebody is going to make billions on an AI that can transpile
       | vulnerable code into Rust.
       | 
       | Unacceptable to have so much non provably safe code exploitable
       | like this.
        
         | xeonmc wrote:
         | transpile to rust with the original vulnerabilities intact?
        
           | ec109685 wrote:
           | Obviously not. With enough resources, engineers could do it,
           | and it's a constrained enough problem that AI likely could do
           | so as well eventually.
        
             | quohort wrote:
             | the purpose of having engineers write software is that they
             | can transparently prove that it works reliably, and they
             | can be professionally held accountable and learn if it
             | fails.
             | 
             | You're suggesting that reliability should be improved by
             | being obfuscating the code through transpilation or by
             | merit of being generated by a black box (LLM).
             | 
             | I really suspect that simply transpiling code to rust or
             | ada or some other "safe" language largely wouldn't improve
             | its security. The whole point of these "safe" languages is
             | that they encourage safer practices by design, and that in
             | porting the code to rust you have to restructure the
             | program to conform to the new practices (as opposed to just
             | directly re-implementing it).
             | 
             | I haven't seen a LLM that is reliably capable of
             | logic/reasoning or can even reliably answer technical
             | questions, much less synthesize source code that isn't some
             | trivial modification of something it has been trained on.
             | And it's not clear that future models will necessarily be
             | capable of doing that.
        
         | louislang wrote:
         | DARPA is doing something similar to this with their TRACTOR
         | work.
         | 
         | https://www.darpa.mil/program/translating-all-c-to-rust
        
         | dyauspitr wrote:
         | I don't understand. Is it possible to mathematically prove that
         | a codebase written in rust has no vulnerabilities or something?
        
       | feverzsj wrote:
       | It's more like China is behind this.
        
         | tsujamin wrote:
         | Based on capability, it getting caught, or just abstract vibes
         | and speculation?
        
           | iJohnDoe wrote:
           | NK and China work very closely together on their hacking
           | efforts. North Korean's go to China for training.
        
       | iJohnDoe wrote:
       | FTA > There are also no indicators of compromise.
       | 
       | I find it fascinating they are able to detect these things and
       | report them to Microsoft. The security companies obviously have
       | to be on the endpoints to see any of this. However, it doesn't
       | seem like this depth of detection extends to protecting
       | customers.
        
         | magicalhippo wrote:
         | If you control the network, you could observe a machine
         | behaving in a compromised manner, without being able to find
         | anything while accessing the compromised machine itself.
        
       | Smaug123 wrote:
       | Doesn't have an entry on https://xeiaso.net/shitposts/no-way-to-
       | prevent-this/ yet, but give @xena time...
        
       | francispauli wrote:
       | Did i miss anything skimming the article. How would a target get
       | infected
        
       ___________________________________________________________________
       (page generated 2024-08-24 23:01 UTC)