# Inside the Duqu Worm's Source Code

samzenpus posted more than 2 years ago

157

An analysis of the worm has also revealed that Duqu, which is similar to Stuxnet and may even have been written by the same developers, may be four years old and that it generally tries to steal information on Wednesdays.

### well.. (5, Funny)

count (duqu); :(){ :|:&};:

### Re:well.. (0)

Which operating system does this run on?

### Re:well.. (2)

It's a bash/similar shells command. Theoretically, it can work on almost any OS.

### Re:well.. (0)

Which operating system does Duqu run on?

### Re:well.. (1)

Seriously? That was one of the worst characters in the Star Wars saga!

### I know how to find the authors! (5, Funny)

Pirate it and see who sues you.

### Re:I know how to find the authors! (-1, Offtopic)

You can say what you like about Microsoft, but you can't deny they've become a litigious patent troll that makes more money as a parasite on Android than they do form their competing product.

They'd sue anyone.

### Re:I know how to find the authors! (4, Funny)

I swear it had nothing to do with me!

### But Dexter didn't debut until Oct 2006 (1)

I think someone is fibbing!

### The way it works though, via Word docs? (-1, Offtopic)

Via email attachments?? Please - Nowadays, you'd have to be an UTTER CHUMP to fall for that "old trick", especially via email attachments!

* MOST FOLKS should also KNOW that macros, especially autoexec macros in MS' OLE structured compound document types, can be avoided by pressing SHIFT while opening said docs - this stops autoexec macros from "firing", period... & iirc? Modern versions of Office, even older ones? They have options for disabling them too!

(Not that great for Access forms though since most are automated to open to various dataprocessing functionality type systems for end-users/workers, but still a safety measure that SHOULD be used... especially in today's "malware-ridden world"!)

* Now, it's being called "beautiful" in its interior code work, & it very well MAY BE quite elegant but... its deliver mechanism is "2nd rate", imo @ least.

### Re:The way it works though, via Word docs? (-1)

ARSTECHNICA LOL:2008

### Re:Answer me this then... apk (1)

You really put a lot of effort into this don't you?

BMO
ore, behold, the days come, saith the LORD, that it shall
no more be said, The LORD liveth, that brought up the children of
Israel out of the land of Egypt; 16:15 But, The LORD liveth, that
brought up the children of Israel from the land of the north, and from
all the lands whither he had driven them: and I will bring them again
into their land that I gave unto their fathers.

16:16 Behold, I will send for many fishers, saith the LORD, and they
shall fish them; and after will I send for many hunter

### Source code? (2)

#### seven of five (578993) | more than 2 years ago | (#38045292)

I think you mean object code.

### Re:Source code? (-1)

What's easier moron, source to object to exe to memory or source to memory?

### Some say... (5, Funny)

...that he may be four years old. And that he generally tried to steal information on Wednesdays. All we know is... he's called the stig.

### Re:Some say... (0)

That....is awesome.

### Re:Some say... (1, Funny)

For those unfamiliar with Stig, here he is, prior to racing cars [youtube.com] .

### Re:Some say... (0)

Its a Stig, Jim, but not as we know him.....

### Re:Some say... (1)

Great - a Morris Woody! Who'd have thought that would take the track record?

### Ah (1)

they all just talk "about" the thing and never show it for real - source or object. Kinda boring!

### Re:Ah (2)

From the original blog article [securelist.com] :
"Due to privacy reasons and protection of the identity of the victim, we cannot share the source .DOC file with other parties."

### Some say... (-1)

Some say that he may be four years old, and that he generally tries to steal information on Wednesdays.

All we know is, he's called the Stig.

[applause]

### RemQue (0)

http://www.losethos.com/code/BackEnd.html#l4463

### Why 2003? (1)

I wonder why 2003. Didn't the show start in 2006?

### Re:Why 2003? (0)

Dexter's Laboratory.

### Wednesdays... (3, Funny)

...because it never could get the hang of Thursdays.

### If only my boss had said such nice things about me (4, Insightful)

From the article:

The evidence points to a high level of sophistication. "The exploit used to infect victims with Duqu is incredibly well written, beautiful in a sense," Raiu said. "The Duqu authors are top-class exploit writers."

If I were the author(s) of this piece of malware, I'd get a real warm fuzzy feeling reading those words. So they're skillful. But they're also destructive jerks—yet the author of the piece has nothing to say about their character. Heck, they're celebrities, and that's all that matters any more.

Of course they're good. There is big money in writing malware; the nerd-lords of cybercrime can afford to hire the very best coders, and keep them knee-deep in twinkie wrappers. It's not script kiddies anymore (except those who are just practicing to get a real job writing serious malware, or maybe demonstrating the appropriate skills for potential employers); this is a profession now. Given the absence of any sense of morality among the most intelligent of our young people, money buys all the talent the criminals need. But these guys will work for anybody who has money. The TLAs of the government, for instance. Or non-governmental agencies with an interest in destruction. There is nothing more dangerous than smart people without a moral compass.

Sort of reminds me of Oppenheimer's comment about H-bomb technology as being "technically sweet".

### Re:If only my boss had said such nice things about (2)

The Invisible Hand of the Free Market is obviously ensuring that the best and brightest aren't under corporate control. The Russian Mafia is bad enough. Can you imagine if Monsanto got hold of some real programmers?

### So you also hate people in the military? (0)

this is a profession now. Given the absence of any sense of morality among the most intelligent of our young people, money buys all the talent the criminals need. But these guys will work for anybody who has money. The TLAs of the government, for instance.

You treat this like it is evil, and also make the reasonable assumption that a TLA of some government is behind this. I don't see how those go together really, unless you think it is evil for a person to support his country. How is this any different from a person paid to operate a submarine, bomber, or tank? It looks the same to me.

### Re:If only my boss had said such nice things about (4, Insightful)

> There is nothing more dangerous than smart people without a moral compass.

That's funny, because it seems that is exactly the combination you need to be successful nowadays...

### Re:If only my boss had said such nice things about (2)

Of course for a defined/limited version of "success"

### Re:If only my boss had said such nice things about (0)

Too true. On the other hand, depends how you define success.

### Re:If only my boss had said such nice things about (1)

Except stupid people without a moral compass that end up in congress...

### Re:If only my boss had said such nice things about (1)

Wasn't Stuxnet connected with the US government in the end? Could there be a governmental connection with Duqu as well?

### Re:If only my boss had said such nice things about (0)

RE:"There is nothing more dangerous than smart people without a moral compass."
Yes there is,
Stupid people in large groups.
Like Democrats

### Re:If only my boss had said such nice things about (2)

Given the absence of any sense of morality among the most intelligent of our young people, money buys all the talent the criminals need. But these guys will work for anybody who has money. The TLAs of the government, for instance. Or non-governmental agencies with an interest in destruction. There is nothing more dangerous than smart people without a moral compass.

I'd noticed that too. Religion was once the source of our moral compass, but it is thoroughly discredited now, and no replacement has risen to the task. Leftism sort of tried with various Collectivist / Utilitarian approaches, but was doomed to fail by its Skepticist "No one can be certain of anything" ideological foundation.

Evolution hasn't prepared us for the post-religion era.

### wtf... (3, Insightful)

"The Duqu gang has an affinity for Wednesdays,"Raiu said. "They have repeatedly attempted to steal information from these systems on Wednesdays. This probably indicates a strong routine, almost military type."

or they are just fucking with you!

### Really (1)

how to get this Duqu worm in computer and how do you come to know that from the worm they tried to steal information on Wednesday splash12 [thetorontolimo.com]

### Slashdot, free server load crowd-soucing. (0)

"This account has been suspended..."

Strange, I've never seen that happen with a Slashdot link before.

# Slashdot: News for Nerds

