Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Thanks for playing: New Linux ransomware decrypted, pwns itself
The Register ^ | 11/12/15 | Darren Pauli

Posted on 11/12/2015 3:34:59 AM PST by markomalley

Ransomware targeting Linux servers has been thwarted by hard working security boffins, with help from the software itself, mere days after its existence was made public.

The Linux.Encoder.1 ransomware seeks Linux systems to encrypt and like others of its ilk demands owners pay BitCoins to have files decrypted.

But the first iteration of the malware has, like most betas, proven fallible.

Not only can it be decrypted using scripts without the need for ransoms to be paid, but it can re-encrypt itself, corrupting files and even encrypting the ransom note that directs victims how to pay the extortion.

Bitdefender security wonks report both failures, including the flaw in Linux.Encoder's local encryption key generation that allowed it to be removed and files decrypted.

"We looked into the way the (AES) key and initialisation vector are generated by reverse-engineering the Linux.Encoder.1 sample in our lab," crypto geek Radu Caragea says.

"The tool determines the initialisation vector and the encryption key simply by analysing the file, then performs the decryption, followed by permission fixing.

"If your machine has been compromised, consider this a close shave. Most crypto-ransomware operators pay great attention to the way keys are generated in order to ensure your data stays encrypted until you pay."

The secure random keys and initialisation vectors generate information from the libc rand() function, and are seeded with the current system timestamp at the point of encryption.

"This information can be easily retrieved by looking at the file’s timestamp [and] is a huge design flaw that allows retrieval of the AES key without having to decrypt it with the" attacker's key, he says.

Caragea says BitDefender's tool (available for free on its site) may not work for those Linux admins who have been infected with multiple instances of the Linux ransomware.

This is because files are encrypted using different keys which generates a race condition that truncates some file contents to zero.

The obliteration of Linux.Encoder.1 comes days after BitDefender released a preventative tool that would prevent the reigning ransomware kings Cryptowall and CTB Locker from executing on victim systems. It does so by preventing executables running from the Windows AppData and Startup folders

Those ransomware variants including the fourth iteration of Cryptowall also released this week are well built and do not contain publicly-known encryption implementation flaws that could allow files to be decrypted without payment. ®


TOPICS: Computers/Internet
KEYWORDS: linux

1 posted on 11/12/2015 3:34:59 AM PST by markomalley
[ Post Reply | Private Reply | View Replies]

To: markomalley

The people who perpetrate these attacks are parasites.


2 posted on 11/12/2015 3:40:47 AM PST by winner3000
[ Post Reply | Private Reply | To 1 | View Replies]

To: winner3000

The scum that commit these crimes should have an automatic death penalty with no appeal process.

The death penalty should be by scourging.


3 posted on 11/12/2015 3:55:55 AM PST by Redleg Duke (The Federal Government is nothing but a welfare program with a dress code!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: markomalley

This is hilarious.


4 posted on 11/12/2015 3:56:29 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

Later


5 posted on 11/12/2015 5:34:03 AM PST by preacher
[ Post Reply | Private Reply | To 1 | View Replies]

To: markomalley

Pay the ramsom or the ramsomware gets it!

6 posted on 11/12/2015 11:59:59 AM PST by TexasRepublic (Socialism is the gospel of envy and the religion of thieves)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson