Stuxnet! Here reproduced by me. Only researchs educations purposes.
Discussion Highlights (12 comments)
monster_truck
Directory filtering needs to be fixed, one weird filename or symlink will make it BSOD. SSDT should probably have a lock. The chance of a race is ~low (higher under heavy sustained workloads) but it's too important to leave to chance. I'd probably do a rebuild of the directory lists in a separate buffer instead of working in place to avoid alignment fuckups. Yes I used LLMs, just like I did for all of the other vulns I've found or refined. As you can see from the source, this shit is tedious as hell. Doesn't change the value of knowing what to look/ask for. Give one of those open models a fresh windows box (not a VM) and tell it to fuck something up, it's fun.
kibitzor
Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant (the same target of the cyber-weapon) as I listened to the audio book[2] based on this ~12 years ago, entirely changed how I viewed critical industrial infrastructure. One quote from the book that stuck with me was how you can only use a cyber weapon once at full potential, as it’ll either get patched and/or everyone can reverse engineer it to use. For those not familiar with Stuxnet, it’s a discovered cyber-weapon from 2010 which “reportedly destroyed almost one-fifth of Iran's nuclear centrifuges. ” and “ neither the United States nor Israel has openly admitted responsibility” but likely were the developers [1] [1-Wikipedia Entry]( https://en.wikipedia.org/wiki/Stuxnet ) [2-“Countdown To Zero Day” book if you liked the Wikipedia entry]( https://www.audible.com/pd/Countdown-to-Zero-Day-Audiobook/B... ) [3-“Zero Days” movie]( https://www.imdb.com/title/tt5446858/ )
aussieguy1234
Somehow, I don't think the original authors of this proprietary code are going to be filing a copyright claim...
andai
g_dwCentrifugeDestroyed++;
beavis000
I very much recommend reading "Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon". Fascinating stuff.
mzs
I always wondered about how feasible the usb drive propagation bit always noted was. Was there ever any evidence that the hardware was already infected at a less scrupulous reseller? I’ve heard of another site in EU that had misbehaving s7. It could have been a reseller that played loose with licensing.
tonyhart7
waiting for Pegasus source code
rep_lodsb
This looks like slop, it's all concatenated into a single file and most probably not based on the actual malware. I'm fairly sure that for example the real one does not include the literal string "Stuxnet" anywhere, like it does here: RegDeleteKeyW(HKEY_LOCAL_MACHINE, L"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Stuxnet"); Wikipedia about the origin of the name: The original name given by VirusBlokAda was "Rootkit.Tmphider;"[41] Symantec, however, called it "W32.Temphid", later changing it to "W32.Stuxnet".[42] Its current name is derived from a combination of keywords found in the software (".stub" and "mrxnet.sys").[43][44]
broodbucket
If you're going to spend tokens on the RE for this, it would've been nice to spend some tokens documenting it or making it easier to navigate
wiml
What binary did you start from?
sneak
AIUI, the successors used a hash of certain system configurations or directory listings to serve as the decryption key for the malicious payload, so that if you found the binary but didn’t have a target system also, it was meaningless.
outfitcolormatc
Thanks for posting that
Related Discussions
Found 5 related stories in 67.0ms across 5,804 title embeddings via pgvector HNSW
Discussion Highlights (12 comments)
monster_truck
Directory filtering needs to be fixed, one weird filename or symlink will make it BSOD. SSDT should probably have a lock. The chance of a race is ~low (higher under heavy sustained workloads) but it's too important to leave to chance. I'd probably do a rebuild of the directory lists in a separate buffer instead of working in place to avoid alignment fuckups. Yes I used LLMs, just like I did for all of the other vulns I've found or refined. As you can see from the source, this shit is tedious as hell. Doesn't change the value of knowing what to look/ask for. Give one of those open models a fresh windows box (not a VM) and tell it to fuck something up, it's fun.
kibitzor
Thanks for posting! ~15k lines of code, a lot to poke around in. I was working on a Siemens S7 PLC project with a WINCC HMI for a power plant (the same target of the cyber-weapon) as I listened to the audio book[2] based on this ~12 years ago, entirely changed how I viewed critical industrial infrastructure. One quote from the book that stuck with me was how you can only use a cyber weapon once at full potential, as it’ll either get patched and/or everyone can reverse engineer it to use. For those not familiar with Stuxnet, it’s a discovered cyber-weapon from 2010 which “reportedly destroyed almost one-fifth of Iran's nuclear centrifuges. ” and “ neither the United States nor Israel has openly admitted responsibility” but likely were the developers [1] [1-Wikipedia Entry]( https://en.wikipedia.org/wiki/Stuxnet ) [2-“Countdown To Zero Day” book if you liked the Wikipedia entry]( https://www.audible.com/pd/Countdown-to-Zero-Day-Audiobook/B... ) [3-“Zero Days” movie]( https://www.imdb.com/title/tt5446858/ )
aussieguy1234
Somehow, I don't think the original authors of this proprietary code are going to be filing a copyright claim...
andai
g_dwCentrifugeDestroyed++;
beavis000
I very much recommend reading "Countdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon". Fascinating stuff.
mzs
I always wondered about how feasible the usb drive propagation bit always noted was. Was there ever any evidence that the hardware was already infected at a less scrupulous reseller? I’ve heard of another site in EU that had misbehaving s7. It could have been a reseller that played loose with licensing.
tonyhart7
waiting for Pegasus source code
rep_lodsb
This looks like slop, it's all concatenated into a single file and most probably not based on the actual malware. I'm fairly sure that for example the real one does not include the literal string "Stuxnet" anywhere, like it does here: RegDeleteKeyW(HKEY_LOCAL_MACHINE, L"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Stuxnet"); Wikipedia about the origin of the name: The original name given by VirusBlokAda was "Rootkit.Tmphider;"[41] Symantec, however, called it "W32.Temphid", later changing it to "W32.Stuxnet".[42] Its current name is derived from a combination of keywords found in the software (".stub" and "mrxnet.sys").[43][44]
broodbucket
If you're going to spend tokens on the RE for this, it would've been nice to spend some tokens documenting it or making it easier to navigate
wiml
What binary did you start from?
sneak
AIUI, the successors used a hash of certain system configurations or directory listings to serve as the decryption key for the malicious payload, so that if you found the binary but didn’t have a target system also, it was meaningless.
outfitcolormatc
Thanks for posting that