Slashdot Mirror


Stuxnet Analysis Backs Iran-Israel Connection

Trailrunner7 writes "Liam O'Murchu of Symantec, speaking at the Virus Bulletin Conference, provided the first detailed public analysis of the worm's inner workings to an audience of some of the world's top computer virus experts. O'Murchu described a sophisticated and highly targeted virus and demonstrated a proof of concept exploit that showed how the virus could cause machines using infected PLCs to run out of control. Though most of the conversation about Stuxnet is still based on conjecture, O'Murchu said that Symantec's analysis of Stuxnet's code for manipulating PLCs on industrial control systems by Siemens backs up both the speculation that Iran was the intended target and that Israel was the possible source of the virus. O'Murchu noted that researchers had uncovered the reference to an obscure date in the worm's code, May 9, 1979, which, he noted, was the date on which a prominent Iranian Jew, Habib Elghanian, was executed by the new Islamic government shortly after the revolution. Anti-virus experts said O'Murchu's hypothesis about the origins of Stuxnet were plausible, though some continue to wonder how the authors of such a sophisticated piece of malware allowed it to break into the wild and attract attention." Symantec has also issued a lengthy and detailed dossier on Stuxnet (PDF).

11 of 307 comments (clear)

  1. KGB ! by bubbakja · · Score: 3, Funny

    In Russia you don't blame code, code blames somebody else !

  2. Re:Wait a minute. by Patch86 · · Score: 5, Funny

    So are we claiming that development on Stuxnet started on 9/5/1979 in reaction to this execution? (Did Siemans even make industrial control computers in the 70s?) Or are we claiming that the "authors of such a sophisticated piece of malware" decided to plant a trail of clues, like some sort of cartoon villains?

    They would have got away with it too, if it weren't for those meddling Symantec engineers.

  3. Re:Wait a minute. by Anonymous Coward · · Score: 2, Funny

    This is exactly what I would expect an agent of the Israeli government to say to throw people off the trail...

    That's exactly what I would expect a pedophile terrorist puppy-kicker to say.

  4. Re:Wait a minute. by Anonymous Coward · · Score: 3, Funny

    This is exactly what I would expect an agent of the Israeli government to say to throw people off the trail...

    Careful. What if that's what they want you to think?

  5. Re:It's called circumstantial evidence by Moryath · · Score: 4, Funny

    admittedly a bit of a stretch as you note, there are also references to "Myrtus" within a path left in the code. Myrtus, a type of myrtle, is possibly a biblical reference to the Book of Esther (Esther was originally called Hadassah - similar to the Hebrew word for myrtle)

    So now we're working off the "this word sounds like this word which is another word for this word" theory?

    Lessee. "May" is a synonym with "shall"... which sounds a lot like "challa"... which is a lovely tasty breadstuff usually eaten by... JEWS! AAAUGH! RUN FOR YOUR LIVES!

    Of course, that's the point of all this meaningless bullshit. You're looking for obscure connections trying to "prove" your own biases. Nothing more.

  6. Re:Wait a minute. by PopeRatzo · · Score: 4, Funny

    Israel definitely has motive and means to be behind the worm.

    You better be careful. Rick Sanchez just said that Jews control all the ISPs and you might have your Internet connecti...{NO CARRIER}

    --
    You are welcome on my lawn.
  7. Re:Wait a minute. by The+Ultimate+Fartkno · · Score: 5, Funny

    Now that's just being anti-Symantec.

    (alt: anti-Siemantic. You pick.)

  8. Re:It's called circumstantial evidence by Jah-Wren+Ryel · · Score: 2, Funny

    there are also references to "Myrtus" within a path left in the code. Myrtus, a type of myrtle,

    Which is very close to Yertle the Turtle.

    OH
    MY
    GOD

    Dr Seuss authored the virus from beyond the grave!!!!

    --
    When information is power, privacy is freedom.
  9. Re:Wait a minute. by dr2chase · · Score: 3, Funny

    Yeah, we're pretty much in "Never go in against a Sicilian when death is on the line" territory here. My money is on the Gilderians.

  10. Re:Really?!? This is front-page quality? by Black+Parrot · · Score: 2, Funny

    Talk about "confirmation bias"!

    Yes - exactly what I was thinking!

    --
    Sheesh, evil *and* a jerk. -- Jade
  11. Re:Wait a minute. by Dthief · · Score: 3, Funny

    You're starting from your bias and trying to justify your conclusion later. It doesn't work.

    Works 100% of the time for me.....which is based on my bias against you being right, thus further supporting my stance.

    --
    www.RacquetUp.org - Helping Detroit Youth