Search This Blog

Showing posts with label Iran. Show all posts
Showing posts with label Iran. Show all posts

Friday, July 15, 2011

How Digital Detectives Deciphered Stuxnet, the Most Menacing Malware in History

By Findalis of Monkey in the Middle

This comes from a rather long article, but it is very insightful into the mystery that is Stuxnet.  It will take years to unravel the full story, but this is what has been discovered so far:
It was January 2010, and investigators with the International Atomic Energy Agency had just completed an inspection at the uranium enrichment plant outside Natanz in central Iran, when they realized that something was off within the cascade rooms where thousands of centrifuges were enriching uranium.

Natanz technicians in white lab coats, gloves and blue booties were scurrying in and out of the “clean” cascade rooms, hauling out unwieldy centrifuges one by one, each sheathed in shiny silver cylindrical casings.

Any time workers at the plant decommissioned damaged or otherwise unusable centrifuges, they were required to line them up for IAEA inspection to verify that no radioactive material was being smuggled out in the devices before they were removed. The technicians had been doing so now for more than a month.

Normally Iran replaced up to 10 percent of its centrifuges a year, due to material defects and other issues. With about 8,700 centrifuges installed at Natanz at the time, it would have been normal to decommission about 800 over the course of the year.

But when the IAEA later reviewed footage from surveillance cameras installed outside the cascade rooms to monitor Iran’s enrichment program, they were stunned as they counted the numbers. The workers had been replacing the units at an incredible rate — later estimates would indicate between 1,000 and 2,000 centrifuges were swapped out over a few months.

The question was, why?
It wasn't apparent to either the IAEA or the Iranians what was happening.  It took the Iranians a year to discover the culprit.
On June 17, 2010, Sergey Ulasen was in his office in Belarus sifting through e-mail when a report caught his eye. A computer belonging to a customer in Iran was caught in a reboot loop — shutting down and restarting repeatedly despite efforts by operators to take control of it. It appeared the machine was infected with a virus.

Ulasen heads an antivirus division of a small computer security firm in Minsk called VirusBlokAda. Once a specialized offshoot of computer science, computer security has grown into a multibillion-dollar industry over the last decade keeping pace with an explosion in sophisticated hack attacks and evolving viruses, Trojan horses and spyware programs.

The best security specialists, like Bruce Schneier, Dan Kaminsky and Charlie Miller are considered rock stars among their peers, and top companies like Symantec, McAfee and Kaspersky have become household names, protecting everything from grandmothers’ laptops to sensitive military networks.

VirusBlokAda, however, was no rock star nor a household name. It was an obscure company that even few in the security industry had heard of. But that would shortly change.

Ulasen’s research team got hold of the virus infecting their client’s computer and realized it was using a “zero-day” exploit to spread. Zero-days are the hacking world’s most potent weapons: They exploit vulnerabilities in software that are yet unknown to the software maker or antivirus vendors. They’re also exceedingly rare; it takes considerable skill and persistence to find such vulnerabilities and exploit them. Out of more than 12 million pieces of malware that antivirus researchers discover each year, fewer than a dozen use a zero-day exploit.

In this case, the exploit allowed the virus to cleverly spread from one computer to another via infected USB sticks. The vulnerability was in the LNK file of Windows Explorer, a fundamental component of Microsoft Windows. When an infected USB stick was inserted into a computer, as Explorer automatically scanned the contents of the stick, the exploit code awakened and surreptitiously dropped a large, partially encrypted file onto the computer, like a military transport plane dropping camouflaged soldiers into target territory.

It was an ingenious exploit that seemed obvious in retrospect, since it attacked such a ubiquitous function. It was also one, researchers would soon learn to their surprise, that had been used before.

VirusBlokAda contacted Microsoft to report the vulnerability, and on July 12, as the software giant was preparing a patch, VirusBlokAda went public with the discovery in a post to a security forum. Three days later, security blogger Brian Krebs picked up the story, and antivirus companies around the world scrambled to grab samples of the malware — dubbed Stuxnet by Microsoft from a combination of file names (.stub and MrxNet.sys) found in the code.

As the computer security industry rumbled into action, decrypting and deconstructing Stuxnet, more assessments filtered out.

It turned out the code had been launched into the wild as early as a year before, in June 2009, and its mysterious creator had updated and refined it over time, releasing three different versions. Notably, one of the virus’s driver files used a valid signed certificate stolen from RealTek Semiconductor, a hardware maker in Taiwan, in order to fool systems into thinking the malware was a trusted program from RealTek.

Finish reading here.
If they had known what they were dealing with they should have left it alone.  While not a Trojan Horse, Stuxnet acted like a Trojan Horse.  What scared the experts was that Stuxnet was so efficient at what it did and how it stayed hidden.  Its ability to remain in the system even after it was "removed" has driven the Iranians crazy.

Stuxnet was NOT written in someone's basement.  It was an effort by a government or governments to take out or at least slow down the Iranian Nuclear Program.  At best it has given the world a few years breathing room.

Hat tip to Israel Matzav

Saturday, June 11, 2011

An Israeli Fable

By Findalis of Monkey in the Middle

I received this in my inbox and thought you would love to read it.

Iran has crossed the nuclear threshold and is testing its Shihab-3 long-range missile. King Ahmadinejad has just delivered a TV address in which he celebrates Iranian invincibility and lets it be known that he has no intention of sparing the Zionist entity. The United States has issued a carefully-worded reproof while at the same time extending the hand of peace and assuring its allies that containment, sanctions and dialogue remain the best policies under the circumstances. But no one in Israel sees a silver lining in a mushroom cloud and all prepare for the inevitable. Fearing abandonment from above, the rabbis raise their voices as one, in humble prayer to the God of Israel.

And lo! their prayers are miraculously answered, for the Lord has taken pity on His suffering people at last and His heart has softened. An iridescent rainbow arches across the sky and suddenly the Heavens open and a golden stairway reaches from Jerusalem to the empyrean. A Voice is heard over all Israel commanding, “Come, My people! Hearken to My Word!” And one by one, family by family, neighborhood by neighborhood, religious and secular, scholar and laborer, leftist and rightist find themselves in Jerusalem, as if Time had contracted to an eternal instant, and all proceed to climb the golden staircase into the Lord’s beneficent embrace.

A silence covers the land. A heavenly wind arises, the earth begins to shake, and cities, villages, farms and buildings vanish as if they had never been. Not even a Starbucks remains. In the twinkling of an eye gardens, groves, orchards, greenhouses, vineyards, every cultivated field, all the work of industrious Jewish hands turn back to desert and malarial swampland, leaving only desolate hamlets and clumps of shriveled lemons and puckered olives. Bewildered Palestinians, foreign journalists, NGOs and European plenipotentiaries look about in stunned disbelief for there is nothing there any longer to slake their enmity—except locusts, mosquitoes, drought and barrenness, as it was before the great aliyah. Even the tree and the stone are perplexed at the disappearance of the Jew hiding behind them, sheltering from Abdullah who is equally nonplussed.

At the same time, the world’s infrastructure collapses. Every Israeli invention that has ever been adopted by mankind—cell phone components, computer algorithms, firewalls, voice mail, wireless LAN, search engines, SMS (texting), video platforms, desalination plants, insect control methods, agricultural drip technologies, medical applications, chemical discoveries and more, indescribably more—cease to exist. The world is bereft. The nations send up a plaintive wail. The General Assembly disbands for lack of a purpose. The United Nations Human Rights Council packs up and goes home, as does the Organization of the Islamic Conference. There is nothing left for them to do. In despair, men look about for someone to blame but find only themselves and their cankered resentments. Even Iran has begun to tremble.

The Jews in Heaven look down and are overcome with sorrow. They plead with the Lord to forgive erring humankind but His heart has now hardened. Men will reap the desert, winnow the dust and harvest destitution. Then the gates of Heaven close, although the jubilant strains of Havah Nagilah sung by the choir of angels can still be discerned, growing ever fainter.

King Ahmadinejad sits forlornly on his throne, pining for the bomb he would lovingly stroke before bedtime to inspire his dreams. It too has evaporated. Beside him, the Hidden Imam, the Mahdi, who has chosen this moment to make his long-deferred appearance, with a mixture of fury and resignation addresses the hapless monarch. His words echo in King Ahmadinejad’s ears.

“Why couldn’t you wait, you idiot?”
Be careful of what you wish for, you might get your wish.

Tuesday, June 7, 2011

Hitting The Road With "A Sense Of Adventure"

Have you ever wanted to take an epic road trip that covered thousands of miles and offered you an opportunity to truly explore the region you were traveling through? That's exactly what Rupert Grey hopes to do in September, when he and his wife will set out to drive from Bangladesh back to their home in England. But Rupert doesn't just want to just go on a road trip, he wants to do it in style. Which is why he is making the journey in his classic 1936 Rolls Royce.

Independent film company Rover Films is hoping to make a documentary of the drive, following Rupert and his wife out of Bangladesh, into the Himalaya, and westward along the Arabian Sea, through Iran and Turkey, and beyond. You can check out the trailer for the film below, and if you feel inclined, donate to the cause for getting this movie made. Rover has set up a Kickstarter page to take donations to help fund the project, which looks like it should be a good one. I mean, where exactly do you find parts for a 1936 Rolls Royce while rolling through the Himalaya?

This looks like a fantastic travel experience, and as I've mentioned before, I'd love to do a long distance, overland road trip like this with friends. My road trip of choice would be Cairo to Cape Town, but his looks like a great route as well. I hope the gang over at Rover get the opportunity to make their film!



A Sense Of Adventure OFFICIAL TEASER from Rover Films on Vimeo.

Monday, November 29, 2010

Iranian Nuclear Scientists Targeted By Explosions

Video below from LA Times



Two separate explosions killed a nuclear scientist and injured another in the Iranian capital Monday morning, official news outlets reported.

Both scholars' wives and a driver were also injured in the attacks, according to the news agencies. The slain scientist, Majid Shahriari, was a member of the nuclear engineering team at the Shahid Behesti university in Tehran, according to the official Islamic Republic News Agency, or IRNA.


Although no arrests have been made, Iran is , of course, blaming "The Zionists" (Israel) and Western Powers, according to a statement statement by the office of President Mahmoud Ahmadinejad.

On the heels of the Stuxnet computer worm that crippled portions of Iran's nuclear capabilities, one might be inclined to assume that someone, or many someones according to the Wikileaks cables just released, might just not want Iran to have a nuclear bomb.

Just a guess.

.

Tuesday, November 23, 2010

Afghanistan: U.S. Conducted Peace Talks With An Impostor

Protecting America is the first and most urgent duty of the president. When there's a crisis and that phone rings at 3:00 a.m. in the White House, there's no time for speeches or on-the-job training. You have to be ready to make a decision.--- Hillary Clinton, March, 2008

Like a badly written movie plot, the New York Times breaks the story that Aghan leaders have supposedly been in talks with the Taliban to negotiate peace and end the war, only after several meetings and handing the supposed Taliban leader a "sizable sum" of money, it was discovered that the Taliban leader in question, Mullah Akhtar Muhammad Mansour, was an impostor.

But now, it turns out, Mr. Mansour was apparently not Mr. Mansour at all. In an episode that could have been lifted from a spy novel, United States and Afghan officials now say the Afghan man was an impostor, and high-level discussions conducted with the assistance of NATO appear to have achieved little.

“It’s not him,” said a Western diplomat in Kabul intimately involved in the discussions. “And we gave him a lot of money.”

American officials confirmed Monday that they had given up hope that the Afghan was Mr. Mansour, or even a member of the Taliban leadership.


Of course U.S. officials now claim they were "skeptical" form the start but that didn't stop them from handing the impostor money, nor continuing to negotiate with the fake Mansour.

Read the whole two page report yourself.

We should also not be basing our war strategy on talks with terrorists, whether it is U.S. officials at the negotiating table or Afghan officials.

There is a reason that U.S. policy has always been "we do not negotiate with terrorists" and news today, this news as well as the news that North Korea opened fire on South Korea, are perfect examples of why cuddling up with terrorist states is a bad idea.

As Jim Geraghty points out, snark included, "I can’t believe the president’s personal letter to Kim Jong Il didn’t work."

How did Obama's letter to Iran's Mahmoud Ahmadinejad work out for him?

Did Obama's letter to Iran's Supreme Leader Ayatollah Ali Khamenei work out any better than the other two?

FLASHBACK, via Video below



The questions that need to be asked in relation to the fake Taliban leader are many and varied, but number one should be, who the hell authorized negotiations with Mansour to begin with, especially if they are telling the truth and were "skeptical" about his claims the whole time?

Where has the Obama's policy of open communication with terrorist countries gotten America?


IRAN:


"Iran to produce nuclear fuel for Tehran reactor in September 2011"

"Iran reaps benefits of US-led sanctions"

"Iran strategy in nuclear talks: Stand its ground"



NORTH KOREA:

"North Korea close to new nuclear test explosion"

"Scientist: North Korea Secretly Built New Nuclear Facility"

"Negotiating with North Korea a serious diplomatic challenge"



AFGHANISTAN:

"Taliban Leader in Secret Talks Was an Impostor"

"Negotiator for Taliban was an impostor, Afghan officials say"

"Taliban Leader in Peace Talks Was Impostor"

Is it any wonder 69 percent of Americans think our country is on the wrong track and that Barack Obama's approval numbers continue to plummet, according to Zogby, he has yet again, hit new lows.

President Barack Obama's job approval rating has dropped to the lowest point of his Presidency at 39%, and in potential match-ups with Republicans in 2012, he trails Mitt Romney, Jeb Bush and Newt Gingrich and is just one point ahead of Sarah Palin.


The level of incompetence the Obama administration has shown is simply astounding and the whole world is watching him flail.

.
Related Posts Plugin for WordPress, Blogger...