Day in the Life of the Internet Storm Center
An anonymous reader writes "Network World Fusion has an
article about the Internet Storm Center's inner workings.
The writer follows the ISC during the day of the MyDoom-O outbreak (the one that hit Google et al.).
The article talks about running W2K in
vmware on top of SuSe Linux. A practice very common in malware analysis to isolate yourself from various ill effects of the malware. Other open
source software receiving a mention in the article is everybodies favorite packet analyzer Ethereal."
Nice caterpillar...
Linux you say?
I don't need no instructions to know how to rock!!!!
Firsties! completely irrelevant AC first post!
An invaluable tool for PCs that are "public access" or even boot-partitions of computers at work:
DeepFreeze
Just one reboot, and any malware infection is obliterated. (There are alternatives, too, but I like DeepFreeze the best)
Ethereal's website is ethereal.com, not ethereal.org.
A practice very common in malware analysis to isolate yourself from various ill effects of the malware
;-)
Best description of Windows I've heard in ages...
Tedious Bloggy Stuff - hooray?
Has some "Goddamn Hippy" taken over the packet analyser site?
Is running them in WINE. Especially since it's not a virtual machine, and the virus might detect WINE then trash your lunix ;)
Windows 98 has largely been ignored by the virus writers for the past two years... The worms this year that took down my school districts entire network of w2k machines didnt harm the windows 98 machines at all!
Speaking of it: I can't get VMware Workstation 4.5.2-8848 to work on SuSE 9.1 with the latest kernel.
Anybody got a good tip ?
Rainer
Windows 2000 - from the guys who brought us edlin
Ethereal is for the weak - real admins use snort.
Real storm chasing leads to really cool pictures.
Internet storm chasing leads to porn.
I can't decide which one is better.
From TFA :
He is the only full-time staffer among the 30 ISC handlers who span the globe and are on duty 24-7. The rest are volunteers who take turns watching over the Internet. Most have other jobs and aren't expected to be awake for their entire 24-hour shift.
Who the hell is this Ulrich guy? R2D2?
This is my sig. There are thousands more, but this one is mine.
Does anyone really remember the difference between MyDoom-O and MyDoom-N? Perhaps they should start using first names like real storm centers do for tropical storms/hurricanes. They could issue warnings about incoming class 5 virus MyBad-Kevin.
One line blog. I hear that they're called Twitters now.
SANS Internet Storm Center
Provides current Internet port graph history and advisories
CERT's Vulnerabilities page
Provides current Internet virus history and news.
Keynote Internet Health Report
Provides a table of ping times between various Internet backbones and providers. Great for checking if it's your ISP, or the backbone they are attached to that's having a slow day.
I advise everyone to check these out, as they provide a great wealth of information in a nice organized format.
up 12 days, 22:30, 2 users, load averages: 993.20, 994.21, 994.56
*makes note to limit user processes...
Real storm chasing leads to really cool pictures.
Internet storm chasing leads to porn.
You mean to say porn isn't really cool pictures?
my pet machine
What about the rest of you? What links do you check out, and what am I missing?
Carousel is a lie!
If slashdot lives up to its reputation, I can imagine that today will not quite follow the usual pattern for the ISC.
EMail: 0110001101100010010000000110001101110010 0110000101111010011011100110000101110010 0010111001100011011011110110
Hopefully they're really hot pictures.
Sorry.
Mark
Liked this comment? Why not buy me something nice
From the article:
"It's amazing how these virus writers get such small code," Ullrich says. "They should be working for some of the commercial code vendors."
Why not: s/should/could
And for the conspiracy-minded: s/working for/commanded by
Really twisted addon to the latter: s/code vendors/anti-virus vendors
Another episode in "preaching to the converted".
Slashdot: stuff for news, nerds that matter, matter for news, stuff that nerd
Tech News Live covered this a few weeks ago. Pretty nifty stuff in here. Check it out!
... is Packetyzer, available from Network Chemistry http://www.networkchemistry.com/products/packetyze r/.
Has some neat additional features, such as conversation tracking and I believe it has a few more decodes. Only for Windoze, however, thus encouraging the VMWare machines.
From the article...
Like previous versions of MyDoom, this one too seems to be listening on certain ports for commands. Ullrich pings each port, but the virus does not react.
That's a neat trick.
I guess they mean "ping" as in "connected to a TCP or UDP port in some manner", and not the usual "send ICMP ECHO_REQUEST", which I don't believe has anything to do with "ports".
Ah, journalism.
What were the skies like when you were young?
learn the meaning of company and product names first, before posting slashdot stories.
--
ignorants
Those are great and all, but where do I go when Slashdot goes down?
-Adam
http://www.google.co.uk/search?q=cache:jo3aRe29uH
i know, i know...
liqbase
...are the "commercial code vendors" interested in small code size?
"Oh, a lesson in not changing history from Mr I'm-my-own-Grandpa." - Dr Hubert Farnsworth
Microsoft's "Virtual PC" for Windows. It gives you a complete virtualized PC that you can run on top of Windows. We use it a lot to test installs, to give ourselves a "clean machine" to make sure there are no dependencies that we didn't think of, and to test unknown software.
Best Buy can have you arrested
from the Internet Storm center. Tonight, expect a high pressure system of script kiddies from the northeast to make the morning telecommute messy. Tomorrow, scattered DDOS showers, high of 10000 bots. Now, here's Glenn with sports.
Where does the school board find them and why do they keep sending them to ME?
It should actually be called the Microsoft Windows Storm Center. Most of the problems are with Windows.
For Linux users, I highly recommend Linux Security to keep up on current advisories.
#include "sig.h"
The first word that caught my attention was the word "handler".
To paraphrase Dave Aitel, "handler = someone without a CS degree".
$ans is all about cash. That is why their classes are packed to the brim, so people can watch powerpoint presentations...
(yes I have attended one)
Half of the SANS hardening guides were ripped straight from the US government (NSA/DISA STIGs). No credit given either btw.
up 12 days, 22:30, 2 users, load averages: 993.20, 994.21, 994.56
.sigs I've ever read on /.
[*makes note to disable fork()]
That is one of the funniest
Still chuckling.
A host is a host from coast to coast...
Unless it's down, or slow, or fails to POST!
umm, is the sans site not firefox compatible? thats pretty funny
would you like 7o everyday...We
It aatempts to from the sidelines, cuntwipes JordaN was at the same
..is a caterpillar, not a worm.
Filth, pure filth. Don't say nobody warned you.
Sign the petition to get rid of these nasty websites from the internet over at Tech News Live!
you insensitive clod!
is at this URL.
Why use products like DeepFreeze after the malware has run and (irreperable?) damage is done when you can stop the malware from running in the first place.
Since malware by email is extremely popular, my approach simply treats all file attachments as 'text files'. 'Running' a text file on an uncompromised machine will cause the file to be loaded into another (trusted?) program.
These 'text files' can be safely handled, scanned for malware by trusted antivirus software, then deleted if infected or renamed back to their original extention.
As the old saying says:
An ounce of prevention is worth a pound of cure.
Why not focus on malware that doesn't use email to spread itself around and solve that problem instead?