ASUS Releases Fix For ShadowHammer Malware Attack (engadget.com)
Iwastheone shares a report from Engadget: ASUS may have inadvertently pushed malware to some of its computers through its update tool, but it at least it has a fix ready to go. The PC maker has released a new version of its Live Update software for laptops that addresses the ShadowHammer backdoor attack. It also promised "multiple security verification mechanisms" to reduce the chances of further attacks, and started using an "enhanced end-to-end encryption mechanism." There are upgrades to the behind-the-scenes server system to prevent future attacks, ASUS added.
The company simultaneously reiterated the narrow scope of ShadowHammer, noting that the malware targeted a "very small and specific user group." It's believed to be an Advanced Persistent Threat -- that is, a state-backed assault against organizations rather than everyday users. Other ASUS devices weren't affected, according to a notice. While the fix is reassuring, it also raises questions as to why the systems weren't locked down earlier. Update tools are prime targets for hackers precisely because they're both trusted and have deep access to the operating system -- tight security is necessary to prevent an intruder from hijacking the process.
The company simultaneously reiterated the narrow scope of ShadowHammer, noting that the malware targeted a "very small and specific user group." It's believed to be an Advanced Persistent Threat -- that is, a state-backed assault against organizations rather than everyday users. Other ASUS devices weren't affected, according to a notice. While the fix is reassuring, it also raises questions as to why the systems weren't locked down earlier. Update tools are prime targets for hackers precisely because they're both trusted and have deep access to the operating system -- tight security is necessary to prevent an intruder from hijacking the process.
I believe that there's a tool with the same name for motherboard users. Are they included in the fix?
Hi guys, I have ASUS and I noticed something odd about this program:
C:\Windows\System32\DriverStore\FileRepository\asussci.inf_amd64_3b4ecfb9c2e13327\ASUSSystemAnalysis\AsusSystemAnalysis.exe
It is upload and steal my files to here:
http://40.83.126.61/Help
Which is also known by this name:
http://mazhkasuspl4.eastasia.cloudapp.azure.com/Help
Does it happen to anyone else?
Has of course had updates disabled, so that is great!
Comment removed based on user account deletion
Pretty sure the fix is not serving malware to your customers in the first place.
0.0.0.0 asushotfix.com
0.0.0.0 liveupdate01.asus.com
0.0.0.0 liveupdate01s.asus.com
* To cripple "shadowhammer's" communique, etc. - et al...
SOURCE https://securelist.com/operati...
APK
P.S.=> For the best hosts file multiplatform:
APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between chars & download)
APK Hosts File Engine 10++ SR-1 32/64-bit for Windows https://hosts-file.net/?s=Down... (DL link @ bottom)
Soon for MacOS too (I just got a NEW Mac-Mini to port it there)... apk
See subject & the threat's STILL LIVE + info. I put out is for those that haven't been made aware of fixes. Answer my question.
* Of course, I KNOW you'll "Run, Forrest: RUN!!!" from my question!
APK
P.S.=> Why will you RUN? It's ALL "your kind" does, chatterbox (do-NOTHING "ne'er-do-well" JEALOUS "Lil' Jowies" EVER do, lol - zero (the SUM of your WASTED LIVES is that, zero))... apk
See subject: It's ALL "Jealous 'Lil' Jowie'" is good for & doing ZERO (the sum of his WASTED life) lol!
APK
P.S.=> We ALL know it - he PROVES it... apk
They just now started using cryptographic security for their system software updater.
And don't worry, the malware only "targeted" a small group of users. Never mind that malware ran with full admin privs on your computer undetected for months. You're totally safe because it didn't "target" you specifically.
<facepalm>
See subject: I will again - I was SAFE vs. this thing crippling it BEFORE FIXES ISSUED - were you (assuming ASUS use on your part)?
* You've done BETTER & earlier? No. YOU personally haven't done SHIT (& you KNOW it, lol) but that's what you FAKENAMES do - zero/nothing.
APK
P.S.=> Care to debate that? Prepare for your OWN self-destruction IF you do (doubt it)... apk
Why didn't they fix this earlier, TFS asks?
Isn't it obvious? They were not going to spend money to fix some theoretical problem, especially when there are no real consequences if it actually does get exploited. Release a patch, wait for the 24 hour news cycle to move on, day after that everyone has forgotten and most people never even heard that your software is insecure. Sales unaffected.
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
They won't answer (they're USELESS is why): Useless chatterbox DO-NOTHING incapable incompetent MENIAL level ZEROS, period.
* & they KNOW it... lol!
APK
P.S.=> Based on their LACK of valid factual response? Now, SO DO YOU... apk
If you let the ASUS Live Update utility update itself, it fails.
If you try to download it manually from their website, they only have the old version.
You have to run the updater, copy the downloaded archive out of the temporary directory before it's automatically deleted, and then install that...
Hence my pre-emptive protection here https://hardware.slashdot.org/...
* :)
APK
P.S.=> Enjoy... apk
The company simultaneously reiterated the narrow scope of ShadowHammer, noting that the malware targeted a "very small and specific user group." It's believed to be an Advanced Persistent Threat -- that is, a state-backed assault against organizations rather than everyday users.
Well are they going to notify the victims of the attack or just pretend the problem is solved?!
Anons need not reply. Questions end with a question mark.
Additionally subie DUMBO it's for those infected: As I said in my initial post? It can't "talk back to C&C mama" STUPID - that's blocked.
APK
P.S.=> Lastly - HOLY SHIT (sorry Lord, but it fits here): You are 1 STUPID motherfucker... apk
[ASUS notes] that the malware targeted a "very small and specific user group." It's believed to be an Advanced Persistent Threat
What a good news for the infected users! Now their GPU and hard disk firmware are probably compromised as well, making sure that ASUS' update will not wipe attacker presence out of the machine.
See subject: It's PARTIALLY what hosts do - stop it "getting orders/sending data" back to "mama" https://hardware.slashdot.org/...
* WORKS both ways EVEN IF YOU ARE infested - it's CRIPPLED in that capacity via hosts...
APK
P.S.=> Enjoy - it REALLY works (been doing it vs. BS like this, for decades)... apk
I own an Asus gaming laptop and LiveUpdate won't even update. That's a conundrum. No patch for me.
Looks like shit for brains APK is talking to himself again. He has to pretend that someone supports him when he gets destroyed because he can't backup anything he says. At best all he can do is spam some shit over and over again that he has gotten torn apart on many time before.
Looks like useless APK just can't stop talking to himself. That multiple personality disorder must be difficult to live with.
See subject MENIAL: Minus guys like myself (programmers/software engineers), menials like YOU can't DO their menial by rote jobs & you BLEW IT vs. https://hardware.slashdot.org/...
* WE CREATE YOUR TOOLS FOR YOU TO MERELY USE & because of my program I created I WAS ALSO again ALREADY "PROOFED" vs. THIS THREAT you LIMITED stupid MENIAL...
APK
P.S.=> FACT along w/ the FACT I'm also your SENIOR in age AND SKILLSET/KNOW-HOW by far... apk
See subject: Because of a program I created I WAS "PROOFED" vs. THIS THREAT you LIMITED MENIAL https://hardware.slashdot.org/... - were you "subie" FAKENAME?
No (assuming you use ASUS because you never said you did not when I noted this before earlier).
I WAS & STILL AM vs. this threat due to MY SKILLS/EFFORT (which you lack, lol, on BOTH accounts).
APK
P.S.=> MENIAL/subie, Minus guys like myself (programmers/software engineers), menials like YOU can't DO their menial by rote jobs
So says some nameless person that neither you(apk) or apk knows anything about. I'm so impressed by a keyboard warrior tough guy.
I'm 54++ & YOU BLEW IT MENIAL (fact) vs. https://hardware.slashdot.org/... & I was PROOFED TO THIS THREAT BEFORE PATCHES ISSUED because of MY EFFORTS with those of others - YOU were NOT, period.
ALSO - FOLKS CAN'T GET TO THIS ALLEGED PATCH per https://hardware.slashdot.org/... STUPID
HOWEVER: They CAN my fix for this shit https://hardware.slashdot.org/... & my fix WORKS crippling this malware machination.
Additionally: As to MY claims you don't KNOW or DO squat vs. me?
I actually have evidence of a program I did in my posts that works vs. THIS THREAT & TONS of others - do you? Hell no.
* You = MENIAL... lol!
(The MORE you "try" effetely & VAINLY to "get in the last word" the MORE YOU END UP WITH EGG ON YOUR FACE, lol!)
APK
P.S.=> I retired 12++ yrs. ago (running my OWN successful business since) & I also STILL put out great work!
Want DOZENS of testimonials from our /. peers liking/using/praising MY work - not yours?
Ask & "ye shall receive" to YOUR further humiliation & dismay, lmao... apk
Avoid APK's work for security. It is close source shitware that has been proven to not provide any actual security but used over 14,000 lines of Pascal code to write a string sorter. Also why should one trust a prolific spammer with the security of their system.
APK is just a little monkey here to entertain us. It's fun to poke him and watch him react -- he can't resist. But never, ever trust him or his software.
YOU BLEW IT MENIAL (fact) vs. https://hardware.slashdot.org/... & I was PROOFED TO THIS THREAT BEFORE PATCHES ISSUED because of MY EFFORTS with those of others - YOU were NOT, period.
ALSO - FOLKS CAN'T GET TO THIS ALLEGED PATCH per https://hardware.slashdot.org/... STUPID
HOWEVER: They CAN my fix for this shit https://hardware.slashdot.org/... & my fix WORKS crippling this malware machination.
Additionally: As to MY claims you don't KNOW or DO squat vs. me?
I actually have evidence of a program I did in my posts that works vs. THIS THREAT & TONS of others (want EVIDENCE OF THAT? ASK & you'll get it by the DOZENS if not 100's) - do you? Hell no.
* You = MENIAL... lol!
(The MORE you "try" effetely & VAINLY to "get in the last word" the MORE YOU END UP WITH EGG ON YOUR FACE, lol!)
APK
P.S.=> Want DOZENS of testimonials from our /. peers liking/using/praising MY work - not yours?
Ask & "ye shall receive" to YOUR further humiliation & dismay, lmao... apk
See subject & results in https://tech.slashdot.org/comm... https://yro.slashdot.org/comme... https://it.slashdot.org/commen... https://linux.slashdot.org/com... https://news.slashdot.org/comm... https://apple.slashdot.org/com... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://search.slashdot.org/co... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://apple.slashdot.org/com... https://tech.slashdot.org/comm... https://it.slashdot.org/commen... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://science.slashdot.org/c... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://tech.slashdot.org/comm... https://it.slashdot.org/commen... https://it.slashdot.org/commen... https://yro.slashdot.org/comme... https://hardware.slashdot.org/... https://yro.slashdot.org/comme...
* That's only recently while I've been on Linux (July 2018) & 100's of times vs. MANY other botnets/malwares etc. in the past circa 2006-early 2018 while I was on Windows: CONCRETE VERIFIABLE UNDENIABLE REALITY (see those links as proof). ... & that's ONLY what /. reported on (there were FAR more /. OMITTED reporting on)
APK
P.S.=> "It's working: Neville... it's working!" - "I A
Who did it 1st: China or me? I did - dates are my proof https://theregister.co.uk/2017... w/ the FACT China rampantly STEALS U.S. Intellectual properties & military secrets https://www.theregister.co.uk/...
* IMITATION truly IS the SINCEREST FORM of FLATTERY!!!
(... & proves hosts work vs. DNS faults in tracking you via dns request logs (since you avoid it & resolve FASTER locally using hosts) + DNS being downed OR Kaminsky REDIRECT security flaw misdirected poisoned (or vs. DNSChanger))
US DHS issues DNS redirect is HUGE danger (not w/ hosts vs.) https://threatpost.com/gov-war... & ICANN ISSUES SAME WARNING https://tech.slashdot.org/stor...
APK
P.S.=> Folks, It's NOT EASY being "World-Class" like me (lol - 200,000++ users prove it for me) - enjoy the fruits of my labors for FREE + going FASTER/SAFER/MORE RELIABLY online (w/ a bit more anonymity too via my program)... apk
"classic Windows hosts trick to block the Coinhive or Crypto-Loot domains" - https://www.bleepingcomputer.com/news/security/a-new-player-joins-coinhive-on-the-browser-cryptojacking-scene/ - BLEEPING COMPUTER
ZD NET http://www.zdnet.com/article/how-to-use-a-hosts-file-to-improve-your-internet-experience/ "Hosts files really shine by letting you block ads, spyware sites, malware sites, & tracking sites"
SANS ("A related approach to the DNS issue is to create a hosts file on each system that sends requests for spyware to some place else" hosts by myself & RAMU right @ START of "malware explosion" mid 2005 on) https://isc.sans.edu/forums/di...
Aryeh Goretsky/ESET/NOD32: hosts = good security https://it.slashdot.org/comments.pl?sid=7442373&.cid=49747129/
Oliver Day (SYMANTEC/SECURITYFOCUS) http://www.securityfocus.com/columnists/491/
Spybot S&D uses hosts!
APK
P.S.=> Malwarebytes' hpHosts hosts & RECOMMENDS my program forum.hosts-file.net/viewtopic.php?f=5&t=4290
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* SEE SUBJECT & TELL US: How does EATING YOUR WORDS taste?
APK
P.S.=> You're already VASTLY OUTNUMBERED but many more are coming (you haven't done better)
Apk has the answer for that - really... kill automatic updates by adding a hosts file entry setting updates.steam.com or whatever to 127.0.0.1. You have to find the right hostname for each software you want to block updates on by raymorris (2726007) on Friday July 06, 2018
APK your posts on this and the hosts file posts, and more, have never been in error and/or bad advice by BlueStrat (756137) on Wednesday June 21, 2017
I support APK's stand on the hosts file and can't see why it's not used more than it is. My hosts file is 144247 lines long (4,332 Kb) it & a firewall serves me very well - by Trax3001BBS (2368736)
ABP is insufficient as a solid hosts file does everything APK reminds us about fast turtle September 17 2013
You need APK's hosts file - by Teun (17872) on Wednesday August 06, 2014
APK
P.S.=> You EATING YOUR WORDS != GOOD NUTRITION... apk
APK is totally right on this count. Adblock Plus on Firefox mobile is a dog on older, or lower end, phones. A hostfile based adblocker makes for a much better experience in this context. Of course, your phone has to be rooted, which isn't the case with Firefox + adblock." - by chihowa on Saturday May 16, 2015
APK solution STILL relevant Thud457 June 11 2015
In a footnote, I would like to note that I find your hosts file admirable - by vel-ex-tech (4337079) on Tuesday November 24, 2015
APK's monolithic hosts file is looking pretty good at the moment - by Culture20 on Thursday November 17
you're right about hosts files - by drinkypoo (153816) on Thursday May 26
APK, I know people give you a lot of shit regarding hosts, but please don't ever stop - by nasredin (958927) on Friday June 12, 2015 @03:34PM
APK
P.S.=> Are you ENJOYING the taste of EATING YOUR WORDS yet?... apk
APK is kinda right... I've given up on JS based adblocking and gone to blackholing in /etc/hosts, just like it was back in the 90s. The computational load has gotten intolerable for any ad-blocking using JS. I've tried his hosts file generating software. It works. - by bmo (77928) on Thursday October 15, 2015
get around to 'installing' a hosts file list, not sure which one, likely the one from someonewhocares.org. If it works as well as what I used for a while about ten years ago, I'll be happy. And grateful to APK for the lesson and the reminder. - by kermidge (2221646) on Wednesday March 27
I actually went and downloaded a 16k line hosts file and started using that after seeing that post, you know just for trying it out. some sites load up faster. - by gl4ss (559668) on Thursday November 17
dammit MS, you proved APK right about something by lgw
APK
P.S.=> Your words YOU'RE EATING: You choking on them yet?... apk
(APK) is still right a hosts file really does work. It even blocked a some of the video ads that were inserted into a stream OrangeTide February 10 2016
the Host File Engine performs exactly as promised - by mmell (832646) on Thursday February 16, 2017
I do use APK's host file on all my systems at home by OrangeTide December 01 2017
I've never tried to belittle (APK's work), I've flat out said it's good - by BronsCon (927697) on Thursday February 11, 2016 @06:48PM (#51491263)
* Toss on 200,000++ users worldwide too!
APK
P.S.=> You still haven't said how EATING YOUR WORDS tastes? apk
Apk made a monkey of you https://hardware.slashdot.org/... . You made a monkey of yourself in your ignorant chimpout.
See subject: When they're reported on they are LIVE & threats dumbo - I block them to help myself & others gratis - do you? No.
* WHY? You've TOO F'ing STUPID to create something as nice as I have is why, lol - & you KNOW it.
APK
P.S.=> People can judge for themselves & a sick in the head LOON like YOU that TRULY IS Jealous "Lil' Jowie" in yourself can't STAND the fact I do well (my kind always does by myself + my fellow man but SCUMBAG do-NOTHING zero "ne'er-do-well" uneducated UNSKILLED losers like you? Never will - & you KNOW it - you hate people like me? No - in truth/fact you HATE yourself - I pity you, I really do - why?? You are WASTING YOUR LIFE away accomplishing ZERO)... apk
He even states that it has failed more times than those above and there were even more in the past. - by Anonymous Coward KING LOSER (lmao) on Wednesday March 27, 2019 @07:06PM (#58344510)
I stated SLASHDOT omitted reporting on MANY infestors/infectors I caught, & oddly, from sites they use like bleeping computer (they only report SOME of what those guys catch).
* See subject DOLT - learn to read, please (for your own sake).
APK
P.S.=> You really make me laugh you know - it's KILLING YOU that nearly EVERY THREAT THERE IS I can stall or stop using hosts while a CHATTERING TWAT troll like you is just ENVIOUS as hell, lol... loser! apk
You really can't stop lying can you. You've stated that you just had a birthday recently, but before that you stated that you were 54. You've also recently stated that you "retired" 12 years ago, and that you "retired" at age 46. Your continual stream of lies must be really fucking hard to keep track of as you just keep getting caught. Why should anyone believe a pathological liar like you on anything? You take people's statements out of context, you say articles say things different than they actually do, you make shit up when you bullshit gets exposed, you post fake support for yourself, etc. No one should take your advise on anything as you are a liar and have been shown to be wrong on everything you say but can't accept reality.
You've stated that you just had a birthday recently, but before that you stated that you were 54. - by UNNIDENTIFIABLE Anonymous Coward STALKER of me IDIOT on Thursday March 28, 2019 @04:30AM (#58346416)
See what I quote from you? You said I had a B-day recently (I did) & I'm 54 - that IS what I said dumbo (54++ = just past my recent b-day dumbo) - see subject. It's you.
You really can't stop lying can you. - by UNNIDENTIFIABLE Anonymous Coward STALKER of me IDIOT on Thursday March 28, 2019 @04:30AM (#58346416)
See subject again - that's you & so is your projecting you are a liar & STUPID as hell too now, lol!
APK
P.S.=> YOU're a liar you project you are & you've proven yourself JUST PLAIN STUPID &/or ILLITERATE as well, lol... apk