Duqu in the press

Kaspersky Security
http://www.securelist.com/en/blog/208193197/The_Mystery_of_Duqu_Part_Two

Symantec Security
http://www.symantec.com/connect/blogs/duqu-status-update-1
http://www.symantec.com/connect/w32-duqu_status-updates_installer-zero-day-exploit

Forbes
http://www.forbes.com/sites/kenrapoza/2011/10/21/duqu-virus-likely-handiwork-of-sophisticated-government-kasperky-lab-says/
http://www.forbes.com/sites/robertvamosi/2011/10/18/son-of-stuxnet/

BBC
http://www.bbc.co.uk/news/technology-15554361

ZDNET
http://www.zdnet.com/blog/security/hungarian-lab-found-stuxnet-like-duqu-malware/9683
http://www.zdnet.com/blog/security/open-source-duqu-detector-toolkit-released/9790

Ars Technica
http://arstechnica.com/business/news/2011/11/researchers-discover-zero-day-windows-exploit-in-duqu-virus.ars

The Register
http://www.theregister.co.uk/2011/11/01/duqu_exploits_windows_zero_day/

Le Monde
http://www.lemondeinformatique.fr/actualites/lire-duqu-utilise-une-faille-zero-day-dans-le-kernel-de-windows-42458.html
http://www.lemondeinformatique.fr/actualites/lire-le-malware-duqu-repere-en-iran-et-au-soudan-42415.html

FOCUS Online
http://www.focus.de/digital/internet/trojaner-stuxnet-bruder-kommt-aus-ungarn_aid_677018.html

Heise
http://www.heise.de/security/meldung/Duqu-nutzt-bislang-unbekannte-Luecke-im-Windows-Kernel-1370005.html

Computerwoche
http://www.computerwoche.de/security/2498601/

Computerworld
http://www.computerworld.com/s/article/9221105/Hard_to_fully_assess_Duqu_threat_yet_researchers_say?taxonomyId=82

Infoworld
http://www.infoworld.com/d/security/duqu-exploits-zero-day-windows-kernel-vulnerability-infect-computers-177731

Eweek
http://www.eweek.com/c/a/Security/Duqu-Exploited-ZeroDay-Vulnerability-in-Microsoft-Windows-Kernel-757626/

Origo
http://www.origo.hu/techbazis/szamitogep/20111020-duqu-ipari-kemkedo-kartevot-talalta-egy-magyar-kutato.html
http://www.origo.hu/techbazis/hightech/20111102-magyar-kutatok-lepleztek-le-a-duqu-kartevo-telepitojet.html

HVG
http://hvg.hu/Tudomany/20111020_stuxnet_szeru_duqu

HSWN
http://www.hwsw.hu/hirek/47582/duqu-crysys-biztonsag-stuxnet-bme-muszaki-egyetem-symantec.html

CERT Hungary
http://tech.cert-hungary.hu/tech-blog/111102/egy-kritikus-0-day-hibat-hasznal-a-duqu

New York Times
http://www.nytimes.com/2011/10/19/technology/stuxnet-computer-worms-creators-may-be-active-again.html?_r=2

Washington Post
http://www.washingtonpost.com/blogs/checkpoint-washington/post/new-stuxnet-like-code-is-discovered/2011/10/19/gIQA8TTHxL_blog.html

Reuters
http://www.reuters.com/article/2011/11/01/us-microsoft-cyberattack-idUSTRE7A06ZX20111101

Suddeutsche Zeitung
 http://www.sueddeutsche.de/digital/neues-virus-duqu-nachfolger-von-stuxnet-spaeht-unternehmen-aus-1.1168266

 

CrySyS Duqu Detector Toolkit released

We released a new open-source toolkit to detect Duqu traces and running Duqu instances. Details and the tool are available using the URL below.

http://www.crysys.hu/duqudetector

=========================================

STATEMENT

Our lab, the Laboratory of Cryptography and System Security (CrySyS) pursued the analysis of the Duqu malware and as a result of our investigation, we identified a dropper file with an MS 0-day kernel exploit inside. We immediately provided competent organizations with the necessary information such that they can take appropriate steps for the protection of the users.

NYILATKOZAT

Laborunk, a CrySyS Adat- és Rendszerbiztonság Laboratórium tovább folytatta a Duqu trójai elemzését, és a kutatás eredményeként azonosítottunk egy dropper fájlt, mely egy MS 0-day kernel hibát használ fel. A szükséges információkat azonnal továbbítottuk az illetékes szakmai szervezeteknek, akik gondoskodni tudnak a felhasználók megfelelő védelméről.

Symantec status updates, Nov 2

=========================================

STATEMENT

Our lab, the Laboratory of Cryptography and System Security (CrySyS) participated in the discovery of Duqu malware within an international collaboration. While gathering deeper knowledge about its functionality, we have confirmed Duqu is a threat nearly identical to Stuxnet. After the thorough analysis of samples we prepared a detailed report about Duqu, named by us. We immediately provided competent organizations with the initial report in order to jointly step up in a professionally prepared way. Our research lab will provide the professional community and the public with all relevant details in the future as well. But we can not reveal further information about the ongoing case. Instead of speculating we encourage all professional organizations to enhance the joint process of finding a solution, since strong international collaboration will remain to play a key role.

NYILATKOZAT

Laborunk, a CrySyS Adat- és Rendszerbiztonság Laboratórium egy nemzetközi összefogás keretében részt vett a Duqu trójai program felfedezésében. Mûködésének részletesebb megismerése során bizonyosodtunk meg arról, hogy a Duqu közel azonos a korábbról ismert Stuxnettel. A minták alapos elemzését követõen, részletes riportot készítettünk az általunk elnevezett Duqu trójai programról. Az elõzetes riportot azonnal eljuttattuk az illetékes szervezetekhez annak érdekében, hogy együttes erõvel, megalapozottan tudjunk fellépni. Kutatólaborunk, a jövõben is minden releváns részletet eljuttat a szakmai közösséghez és segítségükkel a közvéleményhez. A folyamatban lévõ ügyrõl azonban további információt nem hozhatunk nyilvánosságra. A spekulációk helyett a megoldást elõsegítõ közös munkára bíztatunk minden szakmai szervezetet, hiszen a szoros nemzetközi szakmai összefogásra továbbra is nagy szükség van.

Symantec report, Oct 18
Symantec status update, Oct 21

 

Click Trajectories

We collaborated with our colleagues at UCSD and ICSI, Berkeley to do an analysis that quantifies the full set of resources employed to monetize spam email — including naming, hosting, payment and fulfillment — using extensive measurements of three months of diverse spam data, broad crawling of naming and hosting infrastructures, and over 100 purchases from spam-advertised sites. We relate these resources to the organizations who administer them and then use this data to characterize the relative prospects for defensive interventions at each link in the spam value chain.

STUDY

K. Levchenko, N. Chachra, B. Enright, M. Félegyházi, C. Grier, T. Halvorson, C. Kanich, C. Kreibich, H. Liu, D. McCoy, A. Pitsillidis, N. Weaver, V. Paxson, G. M. Voelker, and S. Savage,
Click Trajectories: End-to-End Analysis of the Spam Value Chain,
in Proceedings of IEEE Symposium on Security & Privacy 2011, Oakland, CA, USA, May 22-25, 2011.

PRESS

 

Dan Kaminsky DNS vulnerability study

The implementation of the defense against Kaminsky DNS attack in Hungary concerns a high number of organizations. The bug is known since July 08, 2008, and since the same date the updated software version are also available. In our analysis we checked whether the authors of the Hungarian DNS servers installed the new software versions, which are indispensable for the protection today.

The results show that about two thirds of the servers are vulnerable. Most of the large service providers have already implemented the suggested defense, but it is not enough for the protection of the users.

STUDY

Boldizsar Bencsath, Levente Buttyan
Kaminsky DNS Vulnerability - The big companies made a step already, the small ones are slower
(in Hungarian)

PRESS

 



Budapest University of Technology and Economics
Department of Telecommunications
CrySyS - Laboratory of Cryptography and Systems Security