Looks Like WannaCry Has Been Halted

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
Hutchins said he stumbled across the solution when he was analyzing a sample of the malicious code and noticed it was linked to an unregistered web address. He promptly registered the domain, something he regularly does to discover ways to track or stop cyber threats, and found that stopped the worm from spreading.
http://www.nbcnews.com/storyline/ha...-wannacry-cyberattack-bedroom-compter-n759931

Some great work here. Let's hope it has been truly halted. If so, his work may be able to assist in the discovery of ways to stop future attacks more quickly.
 

HutchinsonJC

Senior member
Apr 15, 2007
465
202
126
It's a temporary stop gap at best.

Odds are fairly good that an entirely new version of the malware without this particular kill switch has already been attempted to be sent out through the night.

The real fix is the windows update.
 

HutchinsonJC

Senior member
Apr 15, 2007
465
202
126
Yeah, I can't help but throw blame at the NSA's feet. #1) They should have reported the flaw to Microsoft and #2) They couldn't contain their knowledge or tools of the flaw and it ended up in public domain.
 

Elixer

Lifer
May 7, 2002
10,376
762
126
http://www.nbcnews.com/storyline/ha...-wannacry-cyberattack-bedroom-compter-n759931

Some great work here. Let's hope it has been truly halted. If so, his work may be able to assist in the discovery of ways to stop future attacks more quickly.
Erm, no, that was just the "feel good story" of the day, there have already been new versions that don't have a "kill-switch".

Then there are the other guys, that installed crypto mining software, and THEY patched SMB, so, they wouldn't be nailed by wannacry.

Yeah, I can't help but throw blame at the NSA's feet. #1) They should have reported the flaw to Microsoft and #2) They couldn't contain their knowledge or tools of the flaw and it ended up in public domain.
How do you know they didn't once the exploits went out? Remember, this was patched back in March.
*edit, yeah, pretty much confirmed it was the NSA that notified MS to patch ASAP.
"The agency eventually warned Microsoft after learning about EternalBlue's theft, allowing the company to prepare a software patch issued in March."
https://arstechnica.com/security/20...leak-nsa-reported-critical-flaw-to-microsoft/
 
Last edited:

Red Squirrel

No Lifer
May 24, 2003
68,020
12,412
126
www.anyf.ca
It's interesting the coder would have used something like this as a kill switch. Seems to me it would make it possible to trace who wrote and distributed it. I would have been hesitant to register that domain myself in case authorities think I'm the one that made the virus. But it's also a genius kill switch since it would work almost right away. An alternative that would be harder to track would be to release another virus into the wild the same way that one was released but it would have to spread again and it would take a while before it starts to kill the first one.

It almost sounds like fun to write viruses tbh. Like not because of the destruction, but just seeing how fast it can spread and stuff.
 
Reactions: XSoldier77X

XSoldier77X

Member
May 23, 2017
113
9
81
Check out that link Elixir shared from Github over some other post here.

It almost sounds like fun to write viruses tbh. Like not because of the destruction, but just seeing how fast it can spread and stuff.

I wish coke's campaigns were as viral.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |