Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The reason is that there's a big difference between an exploit and a fully weaponized utility that gives you a root shell for a given IP address.

You almost never see these lying around the Internet. There is a lot of work involved in creating a tool that'll successfully identify and exploit every single build of an executable, with 99.9% reliability. There is lots of testing to be done, lots of tweaks required. Things that random individuals just don't do by themselves.



but his point is that we're not talking about individuals. The article breathlessly goes on about foreign states, you know the bad ones, who have used this to attack all over the world. Except as tptacek points out, these states can do this kind of work on a slow day, in office. I actually disagree with tptacek, I don't think its partially, or even at all because of the name. I strikes me as more fear mongering, part of a narrative thats meant to drive more defense spending. "Look at all these breaches, can't have this stuff happening, be afraid lowly citizen, and support your security state".


>According to three former N.S.A. operators who spoke on the condition of anonymity, analysts spent almost a year finding a flaw in Microsoft’s software and writing the code to target it. Initially, they referred to it as EternalBluescreen because it often crashed computers — a risk that could tip off their targets. But it went on to become a reliable tool used in countless intelligence-gathering and counterterrorism missions.

If it took the NSA a year to develop, then it can't be done "on a slow day".


I didn't say it could be done "on a slow day". I said it could be done "out of petty cash", in the context of a SIGINT agency. Google employs dozens of people who do this stuff as a hobby.

We don't have to wonder whether this is some space alien technology that only the NSA can develop; it's a reliable Windows remote in pre-Win8 SMB servers. Read a writeup on it; it's less complicated than most type confusion browser RCEs.


fair enough, my language, not yours. I was driving at a similar point however inept my language was.


I don't object to your language as a rhetorical flourish, because I think it's true that this level of exploit development is not all that rarified. I'm just saying, what I actually said is harder to knock down with a message board rebuttal. :)


"you know the bad ones" - Yes, we know. The top of the list would be: North Korea, Russia, USA, UK, China ...


Isn’t Metasploit pretty close?


It is more than pretty close; Metasploit has more offensive capabilities than simply popping a shell, which is what every exploit does by itself already.


> You almost never see these lying around the Internet.

This may have been true 15 years ago when GitHub didn't exist and people hoarded their code, but I would say it's the exact opposite now. You'd be hard-pressed now to find a viable public exploit that doesn't have fully functioning PoC code available in multiple languages through a simple search of the CVE on GitHub.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: