[HN Gopher] Windows 0-day was exploited by North Korea to instal...
___________________________________________________________________
Windows 0-day was exploited by North Korea to install advanced
rootkit
Author : fortran77
Score : 151 points
Date : 2024-08-20 19:05 UTC (4 days ago)
(HTM) web link (arstechnica.com)
(TXT) w3m dump (arstechnica.com)
| graycat wrote:
| Been afraid of something like that:
|
| Mostly running Windows 7 Professional with latest patches from
| Microsoft. Had an HP Laptop with Windows 10 Home Edition where
| the hard disk failed. So, got another HP, with Windows 11 Home.
|
| I'm a _traditional_ Windows user and am writing software in .NET,
| IIS, ASP.NET, SQL Server. My most important tools are Rexx for a
| scripting language and KEdit for my text editor. I don 't want
| Windows to be more like a _smartphone_.
|
| Microsoft made a lot of changes from 10 to 11, and for my
| traditional usage made Windows too different to use. Bluntly I
| have to regard 11 as unacceptable for my traditional usage on 7
| and 10 and am eager to replace 11 with 10.
|
| Sooooo, I'm ready to pull hair and scream trying to find a way to
| install a genuine, 100% authentic, dyed in the wool, DVD, SSD,
| _SEO_ , whatever, I can use to install 10 on my new HP.
|
| HELP!!!!!
| lhamil64 wrote:
| I'm curious why you prefer Rexx as a scripting language on
| Windows over something like Python or even PowerShell. I use it
| quite a bit for work and find it pretty limiting. With a lack
| of built in libraries even some simple stuff like parsing JSON
| can be a huge pain.
| graycat wrote:
| Why Rexx? (A) Used it for decades. (B) The latest _Object
| Oriented Rexx_ has some nice things, e.g., SysFileTree to get
| a nice file of all the names in a directory tree. (C) Yup, I
| agree that could use more tools and not have to _roll my
| own_. (D) Sure, looked at PowerShell: Looks like it has some
| nice _powerful_ features but a, uh, _goofy_ syntax -- intend
| to do more, maybe a lot more, with it. (E) Lots of people are
| taking Python seriously, and for more than just a scripting
| language, e.g., maybe all the software for a significant Web
| site. Intend to devote a weekend to Python.
|
| One little thing I did recently with Rexx was take an email
| message, all in just text, that had a Web page, as a MIME
| (multi-media Internet Mail Extensions or some such) Part, get
| the MIME part with the HTML, fix the email '=' characters
| used for _splitting_ long lines, replaced some uses of
| special characters, and did get a Web page that Firefox would
| read. Worked? Yup. Elegant? Nope.
| wildzzz wrote:
| Here's some good news: your license for Windows 11 is probably
| good for Windows 10 as well. Grab a Windows 10 install media
| from Microsoft and do a clean install on the drive.
|
| https://www.microsoft.com/en-us/software-download/windows10I...
| jwrallie wrote:
| Still there is only one year left of support if you do that.
| graycat wrote:
| I still get "security updates" for Windows 7 Professional
| and am unsure what the lack of "support" might mean for my
| business.
| jborean93 wrote:
| Extended support ended in Jan 2020 and the paid ESU
| support ended in Jan 2023 [1]. Are you sure those updates
| aren't just defender/AV definition updates rather than
| actual OS updates?
|
| [1] - https://learn.microsoft.com/en-
| us/lifecycle/faq/extended-sec...
| graycat wrote:
| Perhaps: "Defender" is what I've noticed.
| bravetraveler wrote:
| Anti-virus definitions, not really exhaustive security
| maintenance. Defender is their AV. The firewall/kernel
| isn't included, for example
|
| How important that is, no idea! The firewall is probably
| passable but I generally don't know your risk profile.
|
| Applications and the rest of the system offer a lot of
| surface area
| pajko wrote:
| https://www.catalog.update.microsoft.com/Search.aspx?q=20
| 24-...
| hnuser123456 wrote:
| windows embedded standard
| dlachausse wrote:
| You should try Start11, it gives you a classic Windows UI
| on modern versions of Windows that are still actively
| receiving security patches.
|
| https://www.stardock.com/products/start11/
| ck2 wrote:
| Windows10 LTSC ftw, EOL 2032
|
| https://old.reddit.com/r/WindowsLTSC/wiki
| amaccuish wrote:
| But their license probably doesn't cover that...
| graycat wrote:
| Yes, thanks.
|
| My understanding from a lot of Google/browsing is that my new
| HP has will a Windows _Product Code_ in the BIOS (or UEFI)
| and, from that product code, will permit installing either of
| Windows 10 Home or Windows 11 Home.
|
| Right.
|
| Thanks for the URL. That is for
|
| "Create Windows 10 installation media"
|
| and
|
| "...download and run the media creation tool."
|
| Believe I did try that. Soooo, tried to run that "tool" on
| Windows 7 Professional, taking the option to create media for
| "another computer", but got a message that now that tool
| won't run on 7.
|
| So, looks like I should try running the "media creation tool"
| on my new HP with Windows 11. Then use that "media" just
| created to install 10 on the new HP.
|
| While doing that work, also create install media for Windows
| 11 _just in case_ at some point would be glad to have it.
|
| Thanks.
| fuzzfactor wrote:
| I think a more ultimate "just in case" is downloading the
| ISO image file which is what you would need if you were
| going to burn a traditional Windows installation DVD-ROM.
|
| The ISO file just sits in a folder like a last resort
| installation backup, but it can then be used to create a
| fresh bootable Windows installation USB stick (or DVD) any
| time from then on without need to access the internet after
| that.
|
| Well you might want to use a program called Rufus which
| will more conveniently turn a Windows installation ISO into
| a bootable USB drive than the Media Creation Tool anyway.
|
| Plus IIRC, Rufus would run under Windows 7, but you will
| need to use last year's version of Rufus, look at this page
| of current and past versions:
|
| https://rufus.ie/downloads/
|
| You will see that rufus-3.22.exe from 2023 is the newest
| thing that was intended to run on W7, so download that,
| download the W10 ISO from Microsoft, and you can then run
| Rufus to choose the ISO from your own filesystem that you
| would like to turn into a bootable USB stick.
|
| That USB stick would then be the Windows 10 installation
| media like you probably wanted to begin with. It also has
| some recovery functions and a powerful command line on its
| own if you need it.
|
| Really still functions this way not much different than the
| original W7 installation DVDs up to W11 so far.
| password4321 wrote:
| All you need for an .ISO is fido (from rufus). But since
| nowadays Windows 10 is too large for a standard DVD, USB
| is the way (I prefer Ventoy). Not sure the best way to
| get 'hold of an .ISO from back in the reasonable size
| days.
|
| https://github.com/pbatard/Fido
|
| https://www.ventoy.net/en/download.html
| giancarlostoro wrote:
| I also do .NET but I went with Linux instead. Something Ubuntu
| based like POP OS or just plain any of the official Ubuntu
| flavors did the trick for me.
|
| Heck for fun I migrated a .NET 3.5 project thats been untouched
| for centuries all the way to the latest all on Linux, and it
| looks like it worked with barely any issues.
| graycat wrote:
| Versions of Linux seem to have a lot of value and are real
| competition for all the versions of Windows.
|
| But I decided to concentrate on just one operating system and
| there picked Windows. Otherwise I want to concentrate on my
| needed software development, the inevitable system
| management, and, then most of all, the business itself.
|
| I'm guessing that, whatever frustrations, Windows will be
| able to support the computing for my business.
| giancarlostoro wrote:
| I agree, I gave up on Windows since the deployment target
| for .NET services (web, etc) are now fully Linux, at least
| in my case. Linux is a known OS and there's thousands of
| experts. We can see under the covers and get a deep
| understanding. I highly recommend you install Linux on an
| older laptop and try it on your time off. As for package
| management, in terms of .NET its just nuget still, in terms
| of installing packages, there's UIs for them, but yeah you
| do need to sit down and read about it so you have some
| familiarity for when something goes wrong, which in the
| case of Ubuntu / Debian is only really the case if you're
| installing packages not maintained by them, Debian has
| insanely strict rules on what they consider stable, which
| means you get a slightly "dated" set of packages, but the
| confidence that your OS will not blow up out of the blue.
|
| What pushed me over the edge to Linux was Windows Defender
| sends files to Microsoft for analysis, but there's no audit
| trail for what those files are. It could be my PII for
| taxes, could be highly proprietary documents for my
| employer / company. I have no way to know what the heck
| their heuristics or whatever has seemingly found suspicious
| and uploaded.
| graycat wrote:
| > What pushed me over the edge to Linux was Windows
| Defender sends files to Microsoft for analysis, but
| there's no audit trail for what those files are.
|
| Gads. I should look into that. Yup, one more item on my
| system management TODO list.
| stackskipton wrote:
| >I'm guessing that, whatever frustrations, Windows will be
| able to support the computing for my business.
|
| Azure/.Net SRE/DevOps whatever person here. I wouldn't be
| that confident in that bet.
|
| Windows Server, if you look at change log for each version,
| it's not a ton and IIS hasn't seen any love for a while.
| While Microsoft will continue to offer it, it's mostly in
| maintenance mode.
|
| .Net (Core) team is clearly over Windows. I've talked to
| Microsoft developers on this several times, they have been
| extremely upfront about it. Linux is preferred operating
| system for running .Net. Performance is much better,
| testing is better and it's cheaper which is massive
| positive. .Net powers a ton of Azure and Linux is first
| choice.
|
| Speaking of other Microsoft Technologies, SQL Server is
| getting worse and worse and I'm seeing more and more .Net
| convert to MySQL or PostGres. Proget, the king of .Net
| Software Packaging is moving to PostGres:
| https://blog.inedo.com/inedo/so-long-sql-server-thanks-
| for-a...
| zamalek wrote:
| Linux is also a much nicer desktop OS to boot, pun intended.
| lewispollard wrote:
| I used to work at the IBM lab where Rexx was created, funnily
| enough I've never heard of anyone using it in the wild!
| daghamm wrote:
| Wasn't the Amiga version pretty big back in the day?
| drsopp wrote:
| Yes, ARexx was big. A lot of popular software had an ARexx
| API so you could script across programs. Pretty awesome. I
| haven't seen anything like that since.
| graycat wrote:
| "Wild"? I used to work at IBM!
| lewispollard wrote:
| Aha!
| jiggawatts wrote:
| The weird thing about rants like this is I tell customers that
| there are very few business-oriented new features in Windows 11
| that justifies the upgrade, but there are quite a few
| developer-oriented features that are unique to it.
|
| Windows Terminal is a nice example, but proper support for
| Windows Containers is huge. It was "technically possible" to
| containerise workloads on Windows 10 but you had to maintain
| the exact same patch level as the server OS the containers
| would run on! Windows 11 removed this restriction.
|
| There's also Dev Drive and a bunch of other small things like
| HTTP/3 and TLS 1.3 support and whatnot.
|
| At $dayjob I have to hold the hand of helpless devs mired in
| corporate miasma complete with out-of-date Windows 10 desktops.
| I regularly have the issue of trying to show them something and
| failing because I forgot I have Windows 11 and they don't.
| hulitu wrote:
| > Windows 0-day was exploited by North Korea to install advanced
| rootkit
|
| Only by North Korea ? /s
| ec109685 wrote:
| Somebody is going to make billions on an AI that can transpile
| vulnerable code into Rust.
|
| Unacceptable to have so much non provably safe code exploitable
| like this.
| xeonmc wrote:
| transpile to rust with the original vulnerabilities intact?
| ec109685 wrote:
| Obviously not. With enough resources, engineers could do it,
| and it's a constrained enough problem that AI likely could do
| so as well eventually.
| quohort wrote:
| the purpose of having engineers write software is that they
| can transparently prove that it works reliably, and they
| can be professionally held accountable and learn if it
| fails.
|
| You're suggesting that reliability should be improved by
| being obfuscating the code through transpilation or by
| merit of being generated by a black box (LLM).
|
| I really suspect that simply transpiling code to rust or
| ada or some other "safe" language largely wouldn't improve
| its security. The whole point of these "safe" languages is
| that they encourage safer practices by design, and that in
| porting the code to rust you have to restructure the
| program to conform to the new practices (as opposed to just
| directly re-implementing it).
|
| I haven't seen a LLM that is reliably capable of
| logic/reasoning or can even reliably answer technical
| questions, much less synthesize source code that isn't some
| trivial modification of something it has been trained on.
| And it's not clear that future models will necessarily be
| capable of doing that.
| louislang wrote:
| DARPA is doing something similar to this with their TRACTOR
| work.
|
| https://www.darpa.mil/program/translating-all-c-to-rust
| dyauspitr wrote:
| I don't understand. Is it possible to mathematically prove that
| a codebase written in rust has no vulnerabilities or something?
| feverzsj wrote:
| It's more like China is behind this.
| tsujamin wrote:
| Based on capability, it getting caught, or just abstract vibes
| and speculation?
| iJohnDoe wrote:
| NK and China work very closely together on their hacking
| efforts. North Korean's go to China for training.
| iJohnDoe wrote:
| FTA > There are also no indicators of compromise.
|
| I find it fascinating they are able to detect these things and
| report them to Microsoft. The security companies obviously have
| to be on the endpoints to see any of this. However, it doesn't
| seem like this depth of detection extends to protecting
| customers.
| magicalhippo wrote:
| If you control the network, you could observe a machine
| behaving in a compromised manner, without being able to find
| anything while accessing the compromised machine itself.
| Smaug123 wrote:
| Doesn't have an entry on https://xeiaso.net/shitposts/no-way-to-
| prevent-this/ yet, but give @xena time...
| francispauli wrote:
| Did i miss anything skimming the article. How would a target get
| infected
___________________________________________________________________
(page generated 2024-08-24 23:01 UTC)