Slashdot Mirror


Stuxnet Analysis Backs Iran-Israel Connection

Trailrunner7 writes "Liam O'Murchu of Symantec, speaking at the Virus Bulletin Conference, provided the first detailed public analysis of the worm's inner workings to an audience of some of the world's top computer virus experts. O'Murchu described a sophisticated and highly targeted virus and demonstrated a proof of concept exploit that showed how the virus could cause machines using infected PLCs to run out of control. Though most of the conversation about Stuxnet is still based on conjecture, O'Murchu said that Symantec's analysis of Stuxnet's code for manipulating PLCs on industrial control systems by Siemens backs up both the speculation that Iran was the intended target and that Israel was the possible source of the virus. O'Murchu noted that researchers had uncovered the reference to an obscure date in the worm's code, May 9, 1979, which, he noted, was the date on which a prominent Iranian Jew, Habib Elghanian, was executed by the new Islamic government shortly after the revolution. Anti-virus experts said O'Murchu's hypothesis about the origins of Stuxnet were plausible, though some continue to wonder how the authors of such a sophisticated piece of malware allowed it to break into the wild and attract attention." Symantec has also issued a lengthy and detailed dossier on Stuxnet (PDF).

5 of 307 comments (clear)

  1. Wait a minute. by Moryath · · Score: 5, Insightful

    So the entire idea of the "Israel created this to attack Iran" idea is based on finding the date May 9, 1979 hidden in the code - and that because it's the first day the current theocratic asshats running Iran beheaded the first Jew of their despotic regime? Really?

    This is like playing Nostradamus. Pluck something vague, go hunting, and see what you can say later to claim you "predicted it." For instance, in Eastern bloc countries, May 9 1945 is "Victory Day." I'm sure some prominent politician somewhere in there also died on May 9, 1979. A google search for that date came back with 196,000 results just on the precise phrase "May 9, 1979".

    Ridiculous.

    1. Re:Wait a minute. by Moryath · · Score: 5, Insightful

      Dozens of regimes have the motivation, capability and demonstrated willingness to do things like this.

      Hell, thousands of hackers across the world have the motivation, capability, and demonstrated willingness to do things like this. And that's not even before we get to the professional virus-writers that are tied in with outfits like yakuza and russian mafia gangs these days operating various blackmail/extortion gambits.

      It sounds more like the "idea" is based on someone who has some grudge against Israel and found a convenient outlet for it, just like all the other "waah the jews did it" conspiracy theories that always sprout up - including the dork who posted a "jews also did wtc" in the first post (thankfully probably trollmarked down to -1 by now) to this article.

    2. Re:Wait a minute. by Patch86 · · Score: 5, Funny

      So are we claiming that development on Stuxnet started on 9/5/1979 in reaction to this execution? (Did Siemans even make industrial control computers in the 70s?) Or are we claiming that the "authors of such a sophisticated piece of malware" decided to plant a trail of clues, like some sort of cartoon villains?

      They would have got away with it too, if it weren't for those meddling Symantec engineers.

    3. Re:Wait a minute. by The+Ultimate+Fartkno · · Score: 5, Funny

      Now that's just being anti-Symantec.

      (alt: anti-Siemantic. You pick.)

  2. Proof??? by ArieKremen · · Score: 5, Insightful

    They were smart enough to write and deploy a complex virus, but stupid enough to include a reference to an obscure execution date of a prominent Iranian Jew; the first .Google hit conveniently pointing to the relevant Wikipedia entry. That screams red herring (en.wikipedia.org/wiki/Red_herring_(idiom)), not proof.

    --
    -- Cave quid dicis, quando, et cui