logoalt Hacker News

qarltoday at 1:25 AM2 repliesview on HN

Yeah... it's reverse engineered. They explained that.


Replies

whimsicalismtoday at 2:09 AM

as the other commentator said, it's one thing if it's just variable names (opaque to reverse engineering) but the fact that it is registry keys....

show 1 reply
rep_lodsbtoday at 1:43 AM

And the Wikipedia article explains where the name came from, a combination of ".stub" and "mrxnet.sys".

Not one literal string as it appears several times in this purported "reconstruction". Including as the name for a registry key, in the hex code at the end of an EXE header stub ("REALTEK",0x00,"Stuxnet"), and in a frigging autorun.inf as the program name.

Even if Wikipedia is wrong and that string should appear somewhere in the original binary, whatever LLM they used has really been overdoing it beyond the bounds of realism: "Hey look, it's the REAL STUXNET, you've all read about it, here is the 100% real authentic reverse-engineered source code!"

show 1 reply