Day in the Life of the Internet Storm Center
An anonymous reader writes "Network World Fusion has an
article about the Internet Storm Center's inner workings.
The writer follows the ISC during the day of the MyDoom-O outbreak (the one that hit Google et al.).
The article talks about running W2K in
vmware on top of SuSe Linux. A practice very common in malware analysis to isolate yourself from various ill effects of the malware. Other open
source software receiving a mention in the article is everybodies favorite packet analyzer Ethereal."
An invaluable tool for PCs that are "public access" or even boot-partitions of computers at work:
DeepFreeze
Just one reboot, and any malware infection is obliterated. (There are alternatives, too, but I like DeepFreeze the best)
Ethereal's website is ethereal.com, not ethereal.org.
A practice very common in malware analysis to isolate yourself from various ill effects of the malware
;-)
Best description of Windows I've heard in ages...
Tedious Bloggy Stuff - hooray?
Has some "Goddamn Hippy" taken over the packet analyser site?
Is running them in WINE. Especially since it's not a virtual machine, and the virus might detect WINE then trash your lunix ;)
Windows 98 has largely been ignored by the virus writers for the past two years... The worms this year that took down my school districts entire network of w2k machines didnt harm the windows 98 machines at all!
From TFA :
He is the only full-time staffer among the 30 ISC handlers who span the globe and are on duty 24-7. The rest are volunteers who take turns watching over the Internet. Most have other jobs and aren't expected to be awake for their entire 24-hour shift.
Who the hell is this Ulrich guy? R2D2?
This is my sig. There are thousands more, but this one is mine.
Does anyone really remember the difference between MyDoom-O and MyDoom-N? Perhaps they should start using first names like real storm centers do for tropical storms/hurricanes. They could issue warnings about incoming class 5 virus MyBad-Kevin.
One line blog. I hear that they're called Twitters now.
SANS Internet Storm Center
Provides current Internet port graph history and advisories
CERT's Vulnerabilities page
Provides current Internet virus history and news.
Keynote Internet Health Report
Provides a table of ping times between various Internet backbones and providers. Great for checking if it's your ISP, or the backbone they are attached to that's having a slow day.
I advise everyone to check these out, as they provide a great wealth of information in a nice organized format.
up 12 days, 22:30, 2 users, load averages: 993.20, 994.21, 994.56
*makes note to limit user processes...
snort is for big girls blouses.
Real admins plug the network cable directly into their brains to perform packet analysis
Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
What truth?
There is no dupe
Real storm chasing leads to really cool pictures.
Internet storm chasing leads to porn.
You mean to say porn isn't really cool pictures?
my pet machine
What about the rest of you? What links do you check out, and what am I missing?
Carousel is a lie!
Get the latest VMware build, and check the vmware community forums. But the latest build I downloaded installed without a hitch on Suse 9.1 running on an AMD64 system.
---- join dshield.org Distributed Intrusion Detec
Real admins plug the network cable directly into their brains
You mis-spelled brains. Its spelled 'ass'
If slashdot lives up to its reputation, I can imagine that today will not quite follow the usual pattern for the ISC.
EMail: 0110001101100010010000000110001101110010 0110000101111010011011100110000101110010 0010111001100011011011110110
and its one of the BOFH's "special" cables
Zaaaaaaaap!
Hopefully they're really hot pictures.
Sorry.
Mark
Liked this comment? Why not buy me something nice
From the article:
"It's amazing how these virus writers get such small code," Ullrich says. "They should be working for some of the commercial code vendors."
Why not: s/should/could
And for the conspiracy-minded: s/working for/commanded by
Really twisted addon to the latter: s/code vendors/anti-virus vendors
Another episode in "preaching to the converted".
Slashdot: stuff for news, nerds that matter, matter for news, stuff that nerd
Real admins plug the network cable directly into their brains to perform packet analysis.
Real admins don't need the cable. They are already one with the network.
... is Packetyzer, available from Network Chemistry http://www.networkchemistry.com/products/packetyze r/.
Has some neat additional features, such as conversation tracking and I believe it has a few more decodes. Only for Windoze, however, thus encouraging the VMWare machines.
From the article...
Like previous versions of MyDoom, this one too seems to be listening on certain ports for commands. Ullrich pings each port, but the virus does not react.
That's a neat trick.
I guess they mean "ping" as in "connected to a TCP or UDP port in some manner", and not the usual "send ICMP ECHO_REQUEST", which I don't believe has anything to do with "ports".
Ah, journalism.
What were the skies like when you were young?
learn the meaning of company and product names first, before posting slashdot stories.
--
ignorants
don't click on the link unless you want your cube mates stare at you ;-)
---- join dshield.org Distributed Intrusion Detec
Real admins plug the network cable directly into their brains to perform packet analysis
I really don't want to know what type of viruses you have!
yeah, ditto. what gob shite modded that informative? or is that some kind of switchable proxy miror?
Those are great and all, but where do I go when Slashdot goes down?
-Adam
Real admins plug the network cable directly into their brains to perform packet analysis
You mean like this?
http://www.google.co.uk/search?q=cache:jo3aRe29uH
i know, i know...
liqbase
...are the "commercial code vendors" interested in small code size?
"Oh, a lesson in not changing history from Mr I'm-my-own-Grandpa." - Dr Hubert Farnsworth
Microsoft's "Virtual PC" for Windows. It gives you a complete virtualized PC that you can run on top of Windows. We use it a lot to test installs, to give ourselves a "clean machine" to make sure there are no dependencies that we didn't think of, and to test unknown software.
Best Buy can have you arrested
from the Internet Storm center. Tonight, expect a high pressure system of script kiddies from the northeast to make the morning telecommute messy. Tomorrow, scattered DDOS showers, high of 10000 bots. Now, here's Glenn with sports.
Where does the school board find them and why do they keep sending them to ME?
For Linux users, I highly recommend Linux Security to keep up on current advisories.
#include "sig.h"
"big girls blouses"???
( . Y . )
That conjures up mental images of pr0n.
No wonder you scored high for off topic!
This is something like the third article where someone has posted that link, then it has been modded up as informative.
Maybe a lot of Slashdotters don't pay attention when they Mod, but it smells to me of some organised trolling.
I'd guess organised trolling - responses pointing out the NSFW link have been modded down too.
The first word that caught my attention was the word "handler".
To paraphrase Dave Aitel, "handler = someone without a CS degree".
$ans is all about cash. That is why their classes are packed to the brim, so people can watch powerpoint presentations...
(yes I have attended one)
Half of the SANS hardening guides were ripped straight from the US government (NSA/DISA STIGs). No credit given either btw.
That's not "Offtopic" at all. It's the very symbol for the topic.
Why is a larva the symbol for "Worms"?
up 12 days, 22:30, 2 users, load averages: 993.20, 994.21, 994.56
.sigs I've ever read on /.
[*makes note to disable fork()]
That is one of the funniest
Still chuckling.
A host is a host from coast to coast...
Unless it's down, or slow, or fails to POST!
umm, is the sans site not firefox compatible? thats pretty funny
This is actually a very good security measure. No-one is going to attempt to sniff the network after *that*
Moderation Total: -1 Troll, +3 Goat
Maybe a lot of Slashdotters don't pay attention when they Mod, but it smells to me of some organised trolling
I would like to nominate Mant for the No Shit Sherlock Award of the year! Taking obvious clues and producing even more obvious conclusions merit this high award.
You shall now be known as Captain Obvious!
Nah. We just need a better trust system.
May we never see th
Why? The NSFW reminders are just as offtopic as the disgusting link posts themselves.
..is a caterpillar, not a worm.
Filth, pure filth. Don't say nobody warned you.
Sign the petition to get rid of these nasty websites from the internet over at Tech News Live!
you insensitive clod!
is at this URL.
Why use products like DeepFreeze after the malware has run and (irreperable?) damage is done when you can stop the malware from running in the first place.
Since malware by email is extremely popular, my approach simply treats all file attachments as 'text files'. 'Running' a text file on an uncompromised machine will cause the file to be loaded into another (trusted?) program.
These 'text files' can be safely handled, scanned for malware by trusted antivirus software, then deleted if infected or renamed back to their original extention.
As the old saying says:
An ounce of prevention is worth a pound of cure.
Why not focus on malware that doesn't use email to spread itself around and solve that problem instead?
In case anyone is interested, that site appears to retrieve a copy of your clipboard, so be careful when visiting.