Light

Episode #827 Quiz

REvil's Clever Crypto
Date: 2021-07-13 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Microsoft’s PrintNightmare patches left Point and Print vulnerable by design unless registry keys NoWarningNoElevationOnInstall and UpdatePromptSettings are removed or zeroed, because authenticated users can invoke RpcAddPrinterDriverEx and related APIs to load remote DLL printer drivers with SYSTEM privileges. REvil/Sodinokibi ransomware encrypts files with unique Salsa20 keys derived via Curve25519 ECDH.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific registry condition did Microsoft later describe as making Point and Print "vulnerable by design"?
Question 2: What did the CERT note say an attacker could do by abusing RpcAddPrinterDriverEx?
Question 3: What capability was missing from the Kaseya VSA intrusion path that made the resulting ransomware campaign less damaging than it could have been?
Question 4: In Sodinokibi’s cryptographic design, what is the purpose of the per-file public key stored in each encrypted file header?
Question 5: What was the key purpose of the operator key pair in Sodinokibi’s design?
Cancel