Hacker News new | past | comments | ask | show | jobs | submit login

Wasn't NotPetya spread via SMB?



That was AFAIK WannaCry


Also Petya/NotPetya. And it used NSA's EternalBlue, too.

https://redmondmag.com/articles/2017/06/27/petya-ransomware-...


Both are correct. The NSA SMB exploit is typically ineffective for initial entry into a network because SMB is almost always blocked at the network boundary but almost never blocked internally. So both Petya and WannaCry had different means for the initial infection, then used SMB attacks to wreak havoc once inside. WannaCry was initially delivered using plain old email attachments, and Petya was delivered via a software update through a hacked update server.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: