It looks like you're new here. If you want to get involved, click one of these buttons!
http://www.flyingpenguin.com/?p=8091&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+flyingpenguin+%28flyingpenguin%29
The source of this was leaked also recently ;), time to be taking over some power stations
I would like to share some of the information i knew about the stuxnet worm
"according to me the most interesting part was the worm is based on utilizing 4 exploits"
And the most amazing thing is they managed to exploit one of the security patch for one of the old exploit,I never heared or seen any thing like this...
this tells how dumb is the microsoft OS,it seems they are patching security holes poorly...
Also see here..
http://www.flyingpenguin.com/?p=8091&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+flyingpenguin+%28flyingpenguin%29
@Xinapse--->
The source of this was leaked also recently ;), time to be taking over some power stations
if possible can you share them please?
i have not read alot about the stuxxnet worm. i am curious, why do they go through port 445? is the malware initiated through RPC and needs to bind to UUIDs from the portmapper? is it using named pipes?
Attacker --> [Malicious WritePrinter Requests through port 445] --> [Deletes files that are processed automatically in Wbem\Mof] --> [Wbem\Mof automatically \"executes\" malicious WritePrinter requests]
Target --> [Shell] --> Attacker
http://www.metasploit.com/modules/exploit/windows/smb/ms10_061_spoolss