Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is an interesting concept. Can you provide any links to the practical info re. this?

It seems to be quite easy to do something similar; especially if you're specifically targeting a single PC with a very specific configuration.

How do you ensure that the amount of entropy in the key is enough to stop a person from finding the key? Assuming the person reverse-engineering the virus already knows the key generation routine, since he has access to the binary of the virus.

Hostnames and lists of installed programs should be prone to a dictionary attack, mac addresses are not even close to having enough bytes.



Yeah! I have to run for a bit but I'll be back. There's an incredible article about Flame I detailed a bit here:

https://news.ycombinator.com/item?id=15046089

It depends entirely whether you have persistent access to the target. If your target is airgapped, your only option is to know something about the target machine (i.e. have a spy on the inside) that gives you enough info to encrypt the virus. For example, they could install a special program so that it's listed in C:\Program Files, then the virus decrypts using the string "${mac_addr}${x}" for x in [list of installed programs]. So as an analyst, you won't have any idea what the magic program name was.

That technique was likely Stuxnet, not Flame, so that article might not contain any info about it. But it's amazing in its own way. If you have any other questions too, I love chatting about this stuff.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: