[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Not much going on that I can find today

In Britain, they are secretly preparing for mass deaths

These Are The Best And Worst Countries For Work (US Last Place)-Life Balance

These Are The World's Most Powerful Cars

Doctor: Trump has 6 to 8 Months TO LIVE?!

Whatever Happened to Robert E. Lee's 7 Children

Is the Wailing Wall Actually a Roman Fort?

Israelis Persecute Americans

Israelis SHOCKED The World Hates Them

Ghost Dancers and Democracy: Tucker Carlson

Amalek (Enemies of Israel) 100,000 Views on Bitchute

ICE agents pull screaming illegal immigrant influencer from car after resisting arrest

Aaron Lewis on Being Blacklisted & Why Record Labels Promote Terrible Music

Connecticut Democratic Party Holds Presser To Cry About Libs of TikTok

Trump wants concealed carry in DC.

Chinese 108m Steel Bridge Collapses in 3s, 16 Workers Fall 130m into Yellow River

COVID-19 mRNA-Induced TURBO CANCERS.

Think Tank Urges Dems To Drop These 45 Terms That Turn Off Normies

Man attempts to carjack a New Yorker

Test post re: IRS

How Managers Are Using AI To Hire And Fire People

Israel's Biggest US Donor Now Owns CBS

14 Million Illegals Entered US in 2023: The Cost to Our Nation

American Taxpayers to Cover $3.5 Billion Pentagon Bill for U.S. Munitions Used Defending Israel

The Great Jonny Quest Documentary

This story About IRS Abuse Did Not Post

CDC Data Exposes Surge in Deaths Among Children of Covid-Vaxxed Mothers

This Interview in Munich in 1992 with Gudrun Himmler. (Heinrich Himmler's daughter)

25 STRANGE Wild West Home Features You’ll Never See Again

Zionists DEMAND Megyn Kelly's Head!


Science/Tech
See other Science/Tech Articles

Title: WikiLeaks' latest leak shows how CIA avoids antivirus programs
Source: [None]
URL Source: http://thehill.com/policy/cybersecu ... hows-how-cia-avoids-anti-virus
Published: Apr 1, 2017
Author: Joe Uchill
Post Date: 2017-04-01 08:09:44 by Ada
Keywords: None
Views: 66

WikiLeaks released its third package of CIA documents on Friday which highlight source code used by the CIA to avoid antivirus programs.

The source code is for a tool called "Marble," what is known as an obfuscator or packer.

Obfuscators are principally designed to jumble the execution of malware so that programs designed to spot malware have trouble determining what it is.

The Marble toolkit includes a variety of different algorithms to accomplish that task.

In its release, WikiLeaks describes the primary purpose of Marble as being to insert foreign language text into the malware to cause malware analysts to falsely attribute code to the wrong nation.

This appears to be an inaccurate description of the primary purpose of the code, however.

While the code can insert any language text or sequence of characters into the code, or English text, the point appears to be more about eliminating the original intent of coders than causing an incorrect attribution.

Analysts are more likely to lump together multiple uses of the same packer algorithm featuring text from multiple languages then they are to assume the languages accurately describe the country of origin. Though language artifacts in the code are the easiest investigatory tool to explain to a non-technical audience, the are neither the only nor the most telling piece of evidence used in an attribution.

Nicholas Weaver, a researcher with the International Computer Science Institute at the University of California at Berkeley, said in a statement that releasing the packer will allow antivirus companies to block CIA malware, but notes that is only in the public interest if "disrupting the CIA's operations for the sake of disrupting the CIA's operations is in your 'public interest.'"

While releasing information about security flaws in products being exploited by the CIA may one day be independently discovered and exploited by malicious hackers, obfuscators can only be used to help prevent attacks by the group using that specific obfuscator — in this case, the CIA.

Now, Weaver said, WikiLeaks is forcing antivirus companies to block the CIA packer because, by releasing it publicly, "[t]hey practically guarantee that a bunch of digital miscreants will start using it as well, because 'hey, a CIA packer for my malcode, cool!'" Weaver said.

Marble is the third in a series of leaks from WikiLeaks that purportedly come from a secure CIA network. The first two largely described CIA hacking techniques.

Post Comment   Private Reply   Ignore Thread  



[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]