Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Anyone that bothers to download this should expect that there is some form of malware included in the file.


And this is why the good Lord has given us virtual machines.


Escaping a virtual machine isn't unheard of. If I were a betting man then I would place good money that this, being a data dump of a state, could contain state-sponsored 0-days designed to escape such things.


Last escape from hardware virtualization on Qubes OS that I'm aware of was in 2006, by the Qubes founder: https://en.wikipedia.org/wiki/Blue_Pill_%28software%29.


I’d only touch this stuff with an airgapped machine which is imaged before and after.


And even then there are ways to put malware into BIOS and disk firmware. Seriously: only a throwaway machine.


On a Pinephone or Librem 5, there is no such semi-writable firmware. You can wipe them fully AFAIK.


Put it on a stone tablet to be on the safe side


Sorry I actually meant virtual virtual machines - they don’t even exist. Truly the only secure option.


And viruses have adapted to that for well over a decade.

And add to that, I would most certainly not trust a normal virtual machine to be a big enough boundary.


And why Baphomet gave us hypervisor escapes.


time to have a HN-swarm of static analysis


This is mentioned on the release page (https://ddosecrets.com/wiki/Roskomnadzor) as well:

> Users are advised to be extra careful as some directories, like ПОЧТА Приемная, appear to contain large numbers of email attachments. Email attachments are often a vector of malware and phishing attempts, so use caution and tools like Dangerzone (https://dangerzone.rocks/) and others.

> This dataset was released in the buildup to, in the midst of, or in the aftermath of a cyberwar or hybrid war. Therefore, there is an increased chance of malware, ulterior motives and altered or implanted data, or false flags/fake personas. As a result, we encourage readers, researchers and journalists to take additional care with the data.


Seriously - dump this on a machine of which you could care less if it caught on fire.


I mean who would look at it outside of a well controlled sandbox?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: