TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: I must be missing something about WannaCry etc.

3 点作者 oferzelig大约 8 年前
I understand that the massive WannaCry propagation is thanks to unpatched Windows systems such that, once the malware is inside a given computer, it spreads across the LAN that computer is part of.<p>But as for the initial &quot;infection&quot;, it&#x27;s caused by merely opening a dodgy email attachment. In which case it&#x27;s no different than any other crap one gets to their computer by recklessly opening attachments.<p>So what&#x27;s so unique about this one that makes it spread so widely?

2 条评论

cbhl大约 8 年前
1) Protocols that are designed for LANs are often exposed to the public Internet. This means that it can spread from one LAN to another by scanning the entire public IP address range for the vulnerable service. This happened in 2003 with the Blaster worm. <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Blaster_(computer_worm)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Blaster_(computer_worm)</a><p>2) LANs can be very big (thousands of computers) and span multiple buildings or cities, and many LANs only have firewalls at the &quot;border&quot; with the Internet (instead of per-machine). Windows machines in particular, tend to have shared network drives (CIFS or SMB) enabled so you can log into any computer and continue working (and to avoid viruses spread by floppies and USB keys).
tekni5大约 8 年前
If you have open ports and SMBv1 is unpatched&#x2F;enabled, I believe you can randomly get from a random scan of your ip by the worm.