The CCleaner Malware Fiasco Targeted at Least 20 Specific Tech Firms (wired.com)
An anonymous reader shares a report: Hundreds of thousands of computers getting penetrated by a corrupted version of an ultra-common piece of security software was never going to end well. But now it's becoming clear exactly how bad the results of the recent CCleaner malware outbreak may be. Researchers now believe that the hackers behind it were bent not only on mass infections, but on targeted espionage that tried to gain access to the networks of at least 20 tech firms. Earlier this week, security firms Morphisec and Cisco revealed that CCleaner, a piece of security software distributed by Czech company Avast, had been hijacked by hackers and loaded with a backdoor that evaded the company's security checks. It wound up installed on more than 700,000 computers. On Wednesday, researchers at Cisco's Talos security division revealed that they've now analyzed the hackers' "command-and-control" server to which those malicious versions of CCleaner connected. On that server, they found evidence that the hackers had attempted to filter their collection of backdoored victim machines to find computers inside the networks of 20 tech firms, including Intel, Google, Microsoft, Akamai, Samsung, Sony, VMware, HTC, Linksys, D-Link and Cisco itself. In about half of those cases, says Talos research manager Craig Williams, the hackers successfully found a machine they'd compromised within the company's network, and used their backdoor to infect it with another piece of malware intended to serve as a deeper foothold, one that Cisco now believes was likely intended for industrial espionage.
If you never read this essay here it is
https://www.ece.cmu.edu/~gange...
Malware is slowly moving up the software chain to where this is becoming increasingly plausible.
Some drink at the fountain of knowledge. Others just gargle.
One or the other... taking bets...
My money is on China.
...for outlining why I thought specific 32 bit platforms, like those used by corporate computing because they tend to maintain their existing image over time even if they have 64 bit machines rather than migrating to a 64 bit OS. Home computers have been sold with essentially only 64 bit OSes preinstalled for several years. Only ancient home computers and business computers are still 32 bit. Natural filter, reduces the amount of unwanted communications to the Command and Control servers.
Do not look into laser with remaining eye.
Ben Kenobi: ...so you can see it was cleaning them...from a certain point of view.
(-1: Post disagrees with my already-settled worldview) is not a valid mod option.
Seems weird that major tech firms would even bother with the likes of CCleaner... I'd assume they'd just re-image the PC's once they start getting fucky. In fact, I"m not even sure that most people use CCleaner.
You clearly overestimate the intelligence of management, supervisors, and service technicians.
We had a lead technician still trying to use Regclean a few years ago. On Windows 7 and Windows 8.1 computers. Same technician kept setting ethernet interfaces to 10Mbit Half Duplex because he somehow interpreted the time that 10/half was needed to push far beyond the 100m channel-length for a waaaaay overlength data drop as the Setting That We Should All Set.
My point is that a lot of myth and misunderstanding goes into IT, and often we get good results despite the stupidity, rather than because of it. I have no doubt that some technicians swore by CCleaner and used it in the corporate setting, and some IT departments even routinely used it in lieu of reimaging infected computers.
Do not look into laser with remaining eye.
My rule of thumb is never trust a source with foreign ties. We learned this from Kaspersky that its hard to distinguish if they are completely above board or not. Experts have said since Windows 7 that a registry cleaner is absolutely not recommended and could do more harm then good. Obviously they were not thinking in terms of malware. But don't install stuff on your PC that isn't needed.
Yes, in your case, is this the chair you mean?
Yes, in your case, is this the chair you mean?
Were you born retarded or does being in the presence of fat people make you retarded?
because judging from the description, this is exactly how America uses NSA to spy on Europe etc.
Needs extra spyware to make it operate smoothly.
I blame the enterprise-level IT department that's too fucking stupid to revoke admin privileges from their users. As well as being too fucking stupid to maintain a list of what's being installed on systems for review and audit purposes. As well as being too fucking stupid to provide a suite of self-service installers for the software users actually do have legitimate business needs for, without granting admin privileges to the users for installing anything they think looks shiny and exciting.
Maybe creimer wrote the enterprise-level IT department standards that allowed it. This is what happens when your ditch digging infosec miracle workers are pulling triple duty as IT, Custodial, and Security staff!
I only vaguely familiar with RegClean. It's an MS util, yes? What does using it foul up?
Hatstand. That is all.
Are you in my office? Then I am not in your presence. Phew!
Does being fat make you unable to buy pants that fit, Chris?
Why don't you update your author blog?
So, how's the video production business coming along? I see you have an amazing three subscribers to your youtube channel. Are you planning on expanding your home office?
Obvious creimer is obvious.
This is yet another example of the anti-virus being the virus. Seen it many times and thatâ(TM)s why I donâ(TM)t use any anti virus products
The CCleaner Malware Fiasco Targeted at Least 20 Specific Tech Firms
None of them were Linux companies.
I think you're forgetting that one of the reasons to stick with 32 bit is external software (that includes drivers) that doesn't have a 64 bit version and will not work in a 64 bit OS.
CCleaner was always garbage that hosed the registry and "cleaned up" /TEMP. Completely useless and in many cases caused problems due to removal of placeholder registry items.
I only vaguely familiar with RegClean. It's an MS util, yes? What does using it foul up?
RegClean is a third-party application. I used it all the time for WinXP. Never found a need to use it with Vista/7/8/10.
You lazy technicians.
There is absolutely no reason to leave CCleaner on a computer - period.
It is a cleaning tool. It does not need to always be running. Why leave a program installed that really only needs to be ran once every 6 months for maintence purposes.
Go find a hobby, you simp.
"How to Hack a Turned-Off Computer, or Running Unsigned Code in Intel Management Engine"
https://www.blackhat.com/eu-17/briefings/schedule/#how-to-hack-a-turned-off-computer-or-running-unsigned-code-in-intel-management-engine-8668
"It allows an attacker of the machine to run unsigned code in PCH on any motherboard via Skylake+. The main system can remain functional, so the user may not even suspect that his or her computer now has malware resistant to reinstalling of the OS and updating BIOS."
"New FinFisher surveillance campaigns: Are internet providers involved?"
https://www.welivesecurity.com/2017/09/21/new-finfisher-surveillance-campaigns/
"What’s new – and most troubling – about the new campaigns in terms of distribution is the attackers’ use of a man-in-the-middle attack with the “man” in the middle most likely operating at the ISP level. We have seen this vector being used in two of the countries in which ESET systems detected the latest FinFisher spyware[...]. When the user – the target of surveillance – is about to download one of several popular (and legitimate) applications, they are redirected to a version of that application infected with FinFisher."
Yeah, this exact same post has never been made by creimer. It's clear that you're totally separate people.
You use exactly the same stale jokes, idiosyncratic expressions, and bad grammar, Chris. Put some zing into your comments next time.
The AC never recommended ILoveFatCashews.
Anyone who thought that CCleaner was "security software" has no business using it, let alone submitting an article to Slashdot about it.
It's a junk/orphan file cleanup utility. Not "security software". Not antivirus or anti-malware. Where do these idiots come from reporting this shit?
you sound bitter, spam tits
Yeah, this exact same post has never been made by creimer. It's clear that you're totally separate people.
creimer pwned your sorry ass, now you think everyone is creimer
Comment removed based on user account deletion
If you simply wish to verify you are not getting a trojan embedded into your binary by a compiler then you simply need to cross-compile a compiler from multiple compilers on multiple architectures and then compare the binaries each of the cross-compiled compilers produce. An example of this would be building GCC for x86 using itself and using Clang/LLVM on ARM (targetting x86). If the resulting builds of the GCC for x86 compiler produce identical binaries then it's extremely unlikely that either compiler is compromised. With each additional compiler and architecture used, it become exponentially less likely that the compile has been compromised.
It would require a sophisticated AI to create a self-perpetuating trojan that would run on all modern platforms and embed itself in all modern compilers. However, if your "Hello World" program starts producing a 10MB binary, you may want to be concerned.
Anons need not reply. Questions end with a question mark.
Comment removed based on user account deletion
You sound diabetic, creimer tits.
He also owns boxes of cliff and power bars. They are healthy for y
whatever you say, creimer
More Creimer affiliate spam. You ain't fooling us Chris. It's too late. We are locked in now, expect it to get worse, much worse.
Comment removed based on user account deletion
The code and techniques look like APT17 aka DeputyDog - hacking into tech firms, military and governments for the Chinese government for at least 10 years.
They realized CCleaner was a fantastic indirect vector into a whole lot of firms, and god knows what else they've got their fingers in that people haven't noticed since most firms are Equifax level incompetent with security.
There you are you disgusting fat sexist tube of lard, Christopher Dale Reimer!
You can be sure I will be watching this fake account too. I know this is you because you told me several times all I need is windows defender since after windows XP.
Now, I told you I was out of meds last week and you didn't even care to contact me you lazy fucker.
How many time do I have to express the emergency of the situation??????
The python click script you wrote for my pheromone revenue stream web site suddently stopped to work!!!!!!
You fucking incompetent python script writer!!!
When it works, I get 4000+ clicks a day on my pheromone revenue stream web site but only 5 or 6 without it!!!!
Now, it seems like you dont care and that you have abandoned me you heartless fucking pig!
Bonus:
Here is a story that creimer told me when convincing me what a hard life he had:
The tree was him and the tree knot was his butt hole!
So, his uncle packed his fat ass with lard and with his cock! Not that it makes much of a difference but anyway, there it is!
Signed:
The girl that used to love you and now hates you, burn in hell where you belong you sexist pig!
Glad I use a mac.
AV software? LOLOLOLOL.
Information about land whales, Christopher Dale Reimer and autistic people:
Autistic people have obsessions about things normal people don't care. For example, one of our autistic patient went haywire when he realized that there was a penny missing in his pocket change.
To calm him down, one of our educator pretended to have found it on the floor and gave a penny to him.
The autistic patient condition went even worse because he realized it wasn't the same penny!
Chris has an obsession with budgeting every penny. He doesn't understand that most people do not budget to the penny and have a flexible amount they allow for miscellaneous items.
I am Nancy Guerrero and I am Director of Special Education for the Santa Clara County Office of Education. We use Chris' (a.k.a. creimer,cdreimer) picture in our document because he is the hardest case we have ever had to handle:
http://www.sccoe.org/depts/stu...
Our artists were inspired by the low carb diet that Christopher follows scrupulously for the small lunch box and by the picture linked below for the rest. I am sure that you will notice the similarities such as the bump on the side of his chest and more:
https://www.cdreimer.com/slash...
Please be easy on Christopher although, I am aware that some of our staff handling Chris post joke comments here and obvoiusly, the Santa Clara County Office of Education disapprove that behavior vehemently:
https://school.discoveryeducat...
But it isn't Chris' fault if he is the way he is. We do the best we can do with him and he is partially integrated into society. We try to cure his abnormal need for attention but he is kind of stubborn and won't listen to anybody.
Thank You dear users,
-Nancy Guerrero
Tell me about it!
Creimer's siblings all had CCleaner installed on their computer!:
https://www.youtube.com/watch?...
That's no surprise if you look at creimer picture:
https://school.discoveryeducat...
Comment removed based on user account deletion
I use Avast free for a lot of my clients. Since CCCleaner is run by them, does that imply that I shouldn't trust Avast either?
shut up, creimer!
They give the illusion of security behind the wall.
If everything was exposed naked to the internet, it would have to be designed properly to be secure in the first place.
"Sneaking behind a corporate firewall" only works if the machines behind that wall are not properly protected from each other.
I have tried to act like creimer on other sites to annoy people.
He's so well known and annoying I'm sure people do it here too.
You're almost definitely creimer.
You're violating AUP on sock puppets as well as the personal deal you made with slashdot staff when they tried to help you sort all this out by wiping your 100 accounts and renaming your embarrassing primary account.
I don't know why they help you at all I would have banned your whole C class and called it problem solved.
Following someone around on Slashdot to troll them is a new level of sad that I never knew existed. Eew.
Jesus you are one desperately sad prick. Get a fucking life.
Hey creimer!
A condition to join the creimer's merry band of wanker trolls is to score a good one replying to you.
We are an underground organization with ties with everything your empty head could imagine and more.
I am the chief representative AC handling your case and I would like to advice you that the GP has made it.
Therefore, in further official posts from our organization, his link will be added, so, it will go like this in the future:
creimer siblings:
https://www.youtube.com/watch?...
creimer himself:
https://school.discoveryeducat...
creimer's chair:
http://www.keynamics.com/image...
Thanks for your time my dear friend.
Sincerely,
The chief representative AC.
If you're looking for a TL;DR it's "I'm a simple cunt who blames all his problems on jews, blacks, women, and other favored objects of hate for neckbeard dickheads."
Right spot on dude!
Humpty-Dumpty, with his tiny cyclist legs wouldn't need that high tech chair.
But then again, if you look above the waist, it is sure required so he doesn't crack open forcing himself in a normal chair nor fall over trying to get into the chair!
Like they have taught us in orientation:
Safety first!
Congratulations to the GGP again!
Let's make /. great again! ;-)