Slashdot Mirror


Over a Million Zombie PCs

Doyle writes "A BBC article discusses new research revealing that over 1 million computers have been compromised and are being used in bot nets. From the article: 'The largest network spied on by the team was made up of 50,000 hijacked home computers.'"

125 of 564 comments (clear)

  1. Where have I heard this before? by maotx · · Score: 4, Funny

    Maybe I should have sent THIS in afterall...

    --
    I'm a virgo and on Slashdot. Coincidence? Yes.
  2. Anyone know... by gowen · · Score: 5, Insightful

    ... the breakdown of that million by operating system?

    You never know, it might be a nice bit of PR for some Apple/Linux/BSD organisation to casually slip into a Press Release.

    --
    Athletic Scholarships to universities make as much sense as academic scholarships to sports teams.
    1. Re:Anyone know... by winkydink · · Score: 2, Insightful

      Of course, the are Windows machines. But Linux has a long way to go before widespread desktop acceptance? Why? Joe User will expect it to work just like Windows, because Joe User views his computer as a tool, not a hobby and therefore does not want to be bothered with taking the time to learn something new.

      Yes, I'm speaking in generalities.

      --

      "I'd rather be a lightning rod than a seismometer." -Ken Kesey

    2. Re:Anyone know... by Anonymous Coward · · Score: 3, Funny
      Joe User will expect it to work just like Windows

      There are blue screen screen savers available that show fake error messages randomly for Linux. "Joe User" should feel right at home.

    3. Re:Anyone know... by dtfinch · · Score: 5, Interesting

      If Joe User started on Linux, or *BSD, then trying to use Windows would require taking time to learn.

      You can tell that Windows is meant to be used as a tool and not just for hobby because in Office and the Explorer search pane they have dozens of these little characters that'll dance and do tricks and stuff without really helping you out in the process. And a bunch of the window actions can be animated to slow them down a bit. You've got connection limits and such to ensure that you only use your desktop for desktop stuff. Network authentication restrictions ensure that your intranet design fits a standard, well supported model, and that the right edition gets used for the right job. And the whole thing is pretty awesome for running games.

      Linux must certainly be meant just for hobby because it comes with thousands of these little tools that just do their jobs without much in the way of glitter and animation to impress the user, or even a requirement that a user must be directly interacting with them.

    4. Re:Anyone know... by winkydink · · Score: 2, Interesting

      If Joe User were required to start by using Linux or BSD, it would set computing back 10 years. It would however probably have the positive side-effect of vastly improving ther desktop experience much more quickly than it is now.

      I'm not proposing Windows or Linux for that matter. The number speak for themseleves. Linux is getting adopted quickly in the server room because the people who manage are trained professionals in computer-related fields. Joe User, for the most part, is not.

      --

      "I'd rather be a lightning rod than a seismometer." -Ken Kesey

    5. Re:Anyone know... by enigmals1 · · Score: 2, Interesting

      I agree they are most likely almost all Windows OS. However, that statistic really means nothing since that is a percentage of zombie PC's--this does not mean there are proportionately more affected Windows PC's than other OSes. Now get me the percentage/number of OS's that are zombies compared to the total percentage/number of those OSes in production around the world in general! ...then you'll have something.

      GOD I am SO tired of this elitest crap on /. Personlly, I'm a Windows fan and I cannot WAIT until Linux really starts taking off so it would have just as many vulnerabilities and problems exposed. And I know they're there because of the inherent reliance on the single kernel just like Windows and the too-many-hands-in-the-pot factor.

    6. Re:Anyone know... by smittyoneeach · · Score: 2, Insightful
      does not want to be bothered with taking the time to learn something new.
      Am I alone in wondering whether this truth extends to running Windows Limited Accounts, instead of Administrator logins?
      Running XP in a safe manner is as challenging as my Gentoo boot, without the benefit of reasonable documentation, unless you want to count these <adjective> bubbles popping up over the system tray.
      Having had some Linux experience, I am guessing my way to understanding _some_ of what to do, but a nice walkthrough about how to make a legacy executable run as admin without requiring an explicit right-click and "Run As" every time would help. Anyone? Bueller?
      --
      Get thee glass eyes, and, like a scurvy politician, seem to see things thou dost not.--King Lear
    7. Re:Anyone know... by Foolhardy · · Score: 4, Informative
      Am I alone in wondering whether this truth extends to running Windows Limited Accounts, instead of Administrator logins?
      I'm sure it does extend to that. Users aren't used to dealing with computer security, on any operating system. It wasn't so important to a home user before the Internet, and it was impossible on 9x. Now they're using a different OS and are connected to a malicious network, but don't want to learn to adapt.

      As for resources, ask Google.
      noadmin.editme.com has a wiki about it, and also see Aaron Margosis' WebLog, aka the The Non-Admin blog, made by a Microsoft employee.
      Windows NT Security in Theory and Practice, a long-running set of MSDN articles about NT security is also interesting, espescially to developers.
      Also useful are FileMon and RegMon from SysInternals, to see what files/reg keys an app is hung up on trying to get unreasonable access to. (Remember that security is checked only on open/create, so set the filter to show opens only)

      Still, there is too little information about running stuff as non-admin. Part of the problem is that making a program run as non-admin when it wasn't designed for that, usually isn't easy.
    8. Re:Anyone know... by X0563511 · · Score: 2, Informative

      It's just harder to tell you are rooted because they arn't doing stupid shit with your box. Usually. (I have been rooted a couple times)

      --
      For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
    9. Re:Anyone know... by Grishnakh · · Score: 4, Insightful

      The only way to get a blue screen in them is to have a bad driver that will affect the system at the kernel level.

      Even if this is true, you're seriously downplaying this problem. With Windows, in order to use your computer at all, you're probably going to have to install vendor-written drivers for something, because there are no community-maintained drivers as there are for OSS OSes. MS does include some basic drivers for very common hardware, but almost any computer will have at least something that will require a vendor driver. History has shown us that these vendor-written drivers have a very poor record, and are known to cause a lot of problems on Windows systems.

      This alone is a good reason to avoid Windows. What good is it as an OS if you can't add various hardware (scanners, cameras, wireless ethernet, etc.) without expecting it to suddenly become unstable?

      It doesn't matter how great Ford engines are if they keep sticking tread-separating Firestone tires on their vehicles.

    10. Re:Anyone know... by AbRASiON · · Score: 2, Interesting

      Well I've recently installed ubuntu on my laptop and personally I'm scared of being rooted because I don't know shit about linux - so I actually feel safer under XP.

      It installed itself and I beleive I don't have root access but due to my lack of linux knowledge it's scary - I know a compromised linux box is a bad bad thing.

      Fortunately I'm using NAT and there's no ports forwarded to the thing.

  3. Must Be M$ Boxes Right ?? by Anonymous Coward · · Score: 5, Funny

    Aren't zombies constantly searching for "brains" ?

    1. Re:Must Be M$ Boxes Right ?? by Profane+MuthaFucka · · Score: 2, Funny

      That's a straw man argument if I ever saw one.

      --
      Fascism trolls keeping me up every night. When I starts a preachin', he HITS ME WITH HIS REICH!
    2. Re:Must Be M$ Boxes Right ?? by Sj0 · · Score: 4, Funny

      He wasn't making an arguement. He was making a joke. This is critical to understand, because an arguement is a very particular subset of conversation, usually designed to be pursuasive in nature. As a result of this, it's structure and the terminology defined with such an element is different than the terminology defined for other conversational constructe, such as jokes.

      --
      It's been a long time.
    3. Re:Must Be M$ Boxes Right ?? by Palshife · · Score: 2, Funny

      Come on man, have a heart! Or some courage maybe?

      --
      Attention deficit disorder is a complicated issue, spanning several major... HEY LET'S GO RIDE BIKES!
    4. Re:Must Be M$ Boxes Right ?? by Stormwatch · · Score: 3, Informative

      A huge difference: every major OS X update - believe it or not - IMPROVES performance on the same hardware, despite all the new features.

  4. That's still low... by BeneathTheVeil · · Score: 5, Funny

    compared to the millions of zombies in front of PCs.

    Come to think of it, the two just may be related. :P

  5. Why arent governments proacting agaisnt these nets by panxerox · · Score: 5, Interesting

    If 1,000,000 computers can be identified as being zombie machines than 1,000,000 computer owners can be contacted. This is THE major problem afflicting the internet, why dont governments form a unit to identify and at least notifiy the owners of these machines? Will it take a major internet terrorist attack like bringing down a power grid to make governments act?. As net users we should advocate government involvment in a measured controlled way rather than the reaction that will come after an attack (patriot act?)

    --
    "It's so convenient to have a system where everyone is a criminal" - A. Hitler
  6. Hope by Rosonowski · · Score: 2, Interesting

    Is it really only one million? When I think of how the average user ends up getting a machine infected, I think of a whole lot more than 1 million. 10 million, perhaps.

    --
    01101001 01100001 01101101 01101110 01101111 01110100 01100001 01101100 01100001 01110111 01111001 01100101 01110010
    1. Re:Hope by jayhawk88 · · Score: 4, Insightful

      Well this is 1 million zombie-infected PC's, which are infected with specific types of trojans and such and presumably are actively being used in bot-nets.

      I imagine there are quite a few more machines that are zombie infected that were not detected for whatever reason (turned off, firewalls, etc), plus all the millions of more machines that are "just" infected with viruses, spyware, or trojans that do not produce bot-net like activity.

  7. Not surprising by dmf415 · · Score: 5, Interesting

    At my university, we have to run snort at the head end of the network in order to control the havoc these compromised machines create. We also monitor the number of simultaneous connections each machine creates and block the ones at the very top.

    1. Re:Not surprising by gordyf · · Score: 3, Interesting

      Do you find that blocking machines with lots of simultaneous connections causes problems with bittorrent clients? (Or is that an intended side effect? :) )

    2. Re:Not surprising by dmf415 · · Score: 5, Informative

      Do you find that blocking machines with lots of simultaneous connections causes problems with bittorrent clients? (Or is that an intended side effect? :) )

      No, I think most legitimate traffic is under 5000 simultaneous connections =). When we see a machine with 10,000 , 20,000 , 30,000 (which has been detected). We know there's a problem =)

    3. Re:Not surprising by dmf415 · · Score: 2, Informative

      forgive me for asking, but i thought Snort was just an intrustion detection system, as i understand it all it does is detect and log intrusions not actually stop them like a firewall does, can i replace my servers firewall with a copy of Snort ?

      One of our student programmers wrote some code that lists the IPs snort detects based on its level of severity. He also wrote another page that uses commands on our packetshaper to determine which IPs are creating the most connections, and automatically blocks them at a 5 minute interval.

    4. Re:Not surprising by budgenator · · Score: 2, Insightful

      I'm not an expert or anything, but it seems to me that the zombies, need to report their presence to the controller, and that usualy done through an IRC channel. If you find the IRC's with the most connections, and block it or even better spoof-it to a tarpit and nobody complains about not being able to connect to their favorite IRC you'd be pretty safe. Of course a lot of people might complain that their 'puters lock-up as soon as they log in.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
  8. bah by ltwally · · Score: 3, Funny
    bah, i run unsecured windows xp and i'm saf..FJEIOJFJIJS

    *Connection Terminated Unexpectedly*

    --



    /dev/random
  9. Imagine... by RedMage · · Score: 5, Funny

    ... a Beowulf Cluster of... oh wait...

    (Hmm, can zombies be clustered? We all know from Night of the Living Dead that they DO cluster. Quite well, in fact...)

    --
    }#q NO CARRIER
  10. Back when Windows was just a hole in the wall by Kimos · · Score: 3, Insightful

    Remmeber when viruses would just "format C:"? When you were infected, you knew it cause your HD was blank. Now the average user can't tell when they have a problem or not...

    1. Re:Back when Windows was just a hole in the wall by rawg · · Score: 2

      What we need is to send commands to these networks to erase themselves. That should wake up some people. I know that these zombies can accept commands. Should be easy to send the command "format c:", shouldn't it? Please, someone do this!

      --
      The above is not worth reading.
  11. Re:Why arent governments proacting agaisnt these n by maotx · · Score: 4, Informative

    and at least notifiy the owners of these machines?

    Something like that already exists.
    Feel free to contact any of the infected and cross them out.

    --
    I'm a virgo and on Slashdot. Coincidence? Yes.
  12. well at least we're smarter than that [SPAM] by peculiarmethod · · Score: 4, Funny

    I know one thing: There's no way in hell they're ever gonna get passed my *ENLARGE YOUR PENIS* super leet windows 2003 install modded to look like xp *HELP RETRIEVE MY MILLIONS*. I even use IE7 beta, but I'm not scared cause I run McAfee *BUY SLIGHTLY USED PORN AT ROCK BOTTOM PRICES* firewall to protect my cable modem network. Let's see 'em try to get into THIS network! HA!

    --
    ** "It's not my job to stand between the people talking to me, and the ones listening to me." -- Pego the Jerk
  13. Why not ISPs by winkydink · · Score: 5, Interesting

    Better yet, why don't ISPs disconnect them until they can demonstrate they've been cleaned up?

    --

    "I'd rather be a lightning rod than a seismometer." -Ken Kesey

    1. Re:Why not ISPs by ArsonSmith · · Score: 4, Insightful

      Yea, they had the ability to disconnect me until I cleaned up some p2p software I had running. I'd say this is much more important than a few TV episodes.

      --
      Paying taxes to buy civilization is like paying a hooker to buy love.
    2. Re:Why not ISPs by SpaceLifeForm · · Score: 2, Interesting
      That would be a start. However, just because they 'cleaned up' won't prevent them from becoming a zombie again.

      The ISP needs to force the user to at minimum to install a software firewall.

      If the user has a windows box directly connected to the Internet and they don't have a software firewall, they should not be allowed to connect.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
    3. Re:Why not ISPs by eaolson · · Score: 5, Insightful
      Better yet, why don't ISPs disconnect them until they can demonstrate they've been cleaned up?

      Because it is not in the ISP's best (i.e. financial) interests to do so. Finding these machines, teaching users how to clean them up, and then reactivating their access would require a great deal of manpower and money. Since not doing it is consequence-free, there is no incentive to do it. It's like dealing with hazardous waste; it's difficult and expensive. Without some outside force compelling companies to dispose of it appropriately, they would deal with it the cheapest and easiest way possible. That is, dumping it on the rest of us, like these ISPs do.

    4. Re:Why not ISPs by FriedTurkey · · Score: 3, Interesting

      Actually they do. My parents computer got disconnected from Roadrunner for being a spam bot. Spending next weekend cleaning it up. Argh.

    5. Re:Why not ISPs by winkydink · · Score: 2, Insightful

      Unless, of course, many ISPs start doing it. Then what happens is those that don't start finding that they're not allowed to peer with those that do, etc...

      --

      "I'd rather be a lightning rod than a seismometer." -Ken Kesey

    6. Re:Why not ISPs by BitwiseX · · Score: 5, Insightful

      They won't clean up, they will go to an ISP that doesn't care. I run a small ISP, I've called customers and informed them of these issues... nothing happens... threaten to cut them off... nothing happens... cut them off... they call angry say "Fine! Don't bother!" and a customer is lost. A customer lost, is a customer lost. Police != Profit unfortunately, and it's a fine line to walk.

    7. Re:Why not ISPs by destiny71 · · Score: 3, Insightful

      Believe me, this is not the answer.

      I work for my ISP as helpdesk/tech support. I get calls all the time, 'Yeah, I got this pop-up from Norton says that Internet Explorer is trying to access the internet, what should I do?'

      If these PCs became zombies, than the users that operate them would have no clue how to operate a software firewall. Instead, they need AV software, and some computer training, and possibly a hardware firewall.

      Easiest to implement would be a DSL/Cable modem and firewall combo that the ISP setup and configures. They can leave the documentation for the end user to configure ports and such if they can figure it out on their own, otherwise, it's full on blocking all incoming ports.

      I'm all for the computer equivilent of a drivers license before they are allowed to hook up their PC to the internet.

    8. Re:Why not ISPs by budgenator · · Score: 4, Insightful

      I'd just like to know why taskmanager says CPU utilization is over 50%, the hard disk is thrashing, and the network light is on constantly, but task manger only list 3 processes using 2%? Nothing shows up on virus scans, nothing shows up on spyware scans and half the time it quits as soon as I open taskmanager.
      At least in linux TOP shows you what process is sucking up the cycles, giving you a fighting chance. I'm not completely clueless, I've used windows since 3.11, cut my teeth on basic and dos batch scripts, installed Linux on a machine before win95 was released and still I know the wife's WinXP machine that's fully patched hardware and software firewalled is owned and can't find out how; what's Joe average going to do?

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    9. Re:Why not ISPs by Politburo · · Score: 2, Insightful

      People and businesses that are irresponsible are not to be treated as equal partners in this world.

      While I agree with the sentiment, it doesn't practically work when applied to the Internet. There are a few reasons. One is the legal reason. ISPs are common carriers and if they start monitoring their traffic and nicking people for being zombies, they could be held responsible if they miss some zombies and those zombies cause damage (yes, I realize this is inane, but it's how lawyers and the law think). The other is that I believe ISP level blocking would significantly harm the internet. Just like blackholing all of China's email traps legitimate messages, blocking whole ISPs would trap legitimate connections. In some areas, a wide choice of ISPs is not available, and legitimate users would have to jump over hurdles just to get onto the internet.

      Additionally, why should I allow some ISP to adopt a business model that puts their costs onto me?

      Do you think ISP prices would go DOWN if they started going after zombie boxes? If anything, they would go up, since tracking down and dealing with the problems would require more resources, more people, more time. As I said in another post, the ISPs have decided that it's cheaper to buy more bandwidth.

      Also, you're a user of a service. The business model already puts their costs onto you. I hope you already knew this.

    10. Re:Why not ISPs by swv3752 · · Score: 2, Insightful

      The Windows XP firewall is pretty seamless. It is on and just sits there unlike NIS or ZoneAlarm.

      But for Cable/DSL the easier answer is just put in a NAT box. I mean a simple router goes for $10. If the ISPs hadn't tried to gouge everyone for hooking up two computers to one line, this probaly wouldn't be an issue now.

      --
      Just a Tuna in the Sea of Life
    11. Re:Why not ISPs by swv3752 · · Score: 4, Interesting

      So the answer is to start suing the ISPs and the customers. If it is more profitable to just sit back and do nothing, then we need to take away that profit incentive.

      --
      Just a Tuna in the Sea of Life
    12. Re:Why not ISPs by Just+Some+Guy · · Score: 4, Interesting
      Because it is not in the ISP's best (i.e. financial) interests to do so. Finding these machines, teaching users how to clean them up, and then reactivating their access would require a great deal of manpower and money. Since not doing it is consequence-free, there is no incentive to do it.

      I don't think it's that bad:

      1. Draft a standard letter / web page explaining why you're disconnecting a customer and how they can get re-connected.
      2. Port scan.
      3. Disconnect.
      4. Get kickbacks from local computer repair shop.
      5. Profit!
      which beats the heck out of
      1. Ignore the situation.
      2. Pay $BIGNUM for the bandwidth you're using to broadcast your customers' computers' spam.
      3. Lose legitimate customers who get tired of their outbound mail bouncing because your netblock is listed in every blackhole list on the planet.
      4. Loss!
      Either way, you will spend some money on the problem, either by proactively fixing it or by paying to repair the damages. Your call.
      --
      Dewey, what part of this looks like authorities should be involved?
    13. Re:Why not ISPs by Grishnakh · · Score: 5, Interesting

      I agree, especially about suing the customers. If they can sue customers for using P2P applications, they can certainly sue customers for running malicious programs on their computers, knowingly (they've been informed), and performing illegal actions with them.

      Harsh times call for harsh measures.

    14. Re:Why not ISPs by karnal · · Score: 2, Informative

      There are programs out there (freeware) that can list every process running on the box etc. Some will even show you what filename launched the process etc... much better than task mangler.

      Also, if you're privvy, before you clean the box up you should download ethereal and see what kind of traffic it is passing. Of course, you need to have a little bit of networking understanding, but it's not hard to look at and see all of the source/destinations that packets are traversing.

      In addition, I've found that MS Anti-spyware beta (google microsoft antispyware) works like a champ when it comes to getting rid of those last few things that Spybot and Adaware will not clean up....

      --
      Karnal
    15. Re:Why not ISPs by tritonic · · Score: 3, Insightful
      I'd just like to know why taskmanager says CPU utilization is over 50%, the hard disk is thrashing, and the network light is on constantly, but task manger only list 3 processes using 2%?
      I actually noticed this about half an hour ago on my windows 2000 machine. I disabled automatic update - problem solved! I don't know why the CPU usage wouldn't show up in task manager, though. Windows grr...
    16. Re:Why not ISPs by toddestan · · Score: 2, Interesting

      Once a computer becomes a zombie, just disable all traffic to that computer except port 80. 99% of the clueless types who let their computers become zombies would never notice, and then they can continue to live in their ignorant bliss. Problem solved.

      The few who would notice are more likely be the more savvy ones who might be able to keep their computer clean next time - so once they disinfect their machine you could let them back on. Problem solved.

  14. Re:Why arent governments proacting agaisnt these n by Ironsides · · Score: 2, Insightful

    No sane person should connect a critical piece of computer infrastructure, such as any computer dealing with the management of the electrical grid, to the internet.

    Better thing would be to require by law that none can be connected instead.

    --
    Fly me to the moon Let me sing among those stars Let me see what spring is like On jupiter and mars
  15. Re:Why arent governments proacting agaisnt these n by flumps · · Score: 5, Informative

    From honeypot FAQ:

    8. Do you prosecute the people that compromise systems within the Honeynet? No. The prime directive of the Honeynet Project is research and to share those lessons learn. It is not our goal to catch and prosecure blackhats. We do forward information about compromised systems to CERT so CERT can notify admins of compromised systems. We limit our contact with authorities only when the Project feels there is a critical need. If we were to become involved in a major legal case everytime a system was compromised, we would not have time for research, let alone our real jobs.

    read more about honeypot here. It seems they probably could, but are not going to.

    --
    "So there he is, risen from the dead. Like that fella, E. T." - Father Ted Crilly
  16. Re:Why arent governments proacting agaisnt these n by MatthewNewberg · · Score: 5, Insightful

    Governments?, What about ISPs? They are the ones having to pay for the added bandwitdh on both sides. I'm surprised most ISPs dont run IDS that can detect Zoombie Networks and automatically send emails to its infected customers. This will not only pay for itself by reducing bandwidth, but also make the customers more happy.

  17. Actively Scanning by forum__32 · · Score: 2, Interesting

    So if 1 million machines are actively scanning for other machines with 200 threads. With ipv4 there should be 4211604225 theoretical public ips. If they were scanning with 200 threads/sec, they could cover the entire ipv4 address space in 21secs. Granted, I know not all 1 million are scanning, and I prolly screwed up in my ip calculations, but this still an astronomical number.

    1. Re:Actively Scanning by bcmm · · Score: 2, Insightful

      But face it, that sucks so badly that everyone just increases the max with that program that's going round (no I can't be bothered to Google it, I don't even use windows any more :-).

      P2P users all do it, why can't a worm/botnet client do it?

      --
      # cat /dev/mem | strings | grep -i llama
      Damn, my RAM is full of llamas.
  18. fix them by roman_mir · · Score: 3, Interesting

    Now that the machines are known, their IPs are compiled into a list, what stops a good samaritan from setting up a script to patch them up?

    It is probably quite complicated, technically speaking, because these machines now have to be scanned for every possible trojan, logger, virus in existance, but it's not impossible. Can an antivirus company, say, get a grant from a government to run a job like that?

  19. Bullshit by LiquidCoooled · · Score: 3, Interesting

    One machine can be infected by multiple trojans.
    One machine can reconnect to the same botnet multiple times as the person reboots to try and clear the problem.
    One machine gets multiple IP addresses every time her reboots.

    --
    liqbase :: faster than paper
  20. I was wondering... by justforaday · · Score: 5, Funny

    This explains why my startup sound suddenly changed into a groaning voice saying "Braiinnnnnssss..."

    --
    I'll turn into a supernova and burn up everything. Well I'll turn into a black little hole and you'll turn into string.
  21. not entirely user behavior... by grassy_knoll · · Score: 5, Interesting
    from TFA:

    Getting the machines hijacked was worryingly easy. The longest time a Honeynet machine survived without being found by an automatic attack tool was only a few minutes. The shortest compromise time was only a few seconds.


    It's sad, but it seems the only way to mitigate this is to hold the OS vendor responisble for insecure code. Similar to cars, we hold the driver responsible if they ( say ) drive drunk, but the manufactorer responsible if while driving the wheels come off.
  22. What role for ISPs by Albanach · · Score: 3, Insightful
    There has to be a role here for ISPs. Often these machines are either spitting out spam or worms, yet abuse reports to ISPs can take days or weeks to receive any attention.

    Home PC users do not need to generate traffic on port 25 that's going anywhere other than their ISP's mailserver. ISP mailservers should use SMTP authentication. Of course these simple measures would mean support calls from users who need to reconfigure Outlook, and support calls cost money, so it'll never happen.

    Nonetheless, these companies are proffiting while user machines get hijacked. Someone needs to make a little bit of effort, 'cause for now spreading these nets wider is way too easy.

    1. Re:What role for ISPs by Troed · · Score: 2, Insightful

      Home PC users do not need to generate traffic on port 25 that's going anywhere other than their ISP's mailserver.

      Yes we do. I like my own SMTP-server a lot better than my ISPs, and one of the reasons is that I can trust the SSL SMTP encryption when I know my endpoints. That's not possible when going through my ISPs SMTP-server.

  23. Welcome to the internet age by FidelCatsro · · Score: 2, Insightful

    Now many will call me a Microsoft basher and i unashamedly am and with a dammed good reason. The insecurity of microsoft OSs does not just effect those who want to use (or dont know they have other options)windows, but it effects me and my peers.
    I know * linux ,HPUX,Solaris,OS X(maybe i should just include this in *BSD) and *BSD are not perfect and have some security issues , though nothing on this scale(my opinion ) , you can use the argument about if blah had blah monopoly then blah would be just as cracked (which i think is rubbish and doth not change the fact that it is only and if as it isnt so cant be proven) So as a user of the internet on my chosen Unix variants at home and at work I still have to suffer microsofts lackluster Network security through the set-up of botnets .
    Spam - DDOS and freinds continue to plauge our internet services.
    Fine blame the average user for not updating etc , the fact remains that a person who is skilled in other areas should not need to have the knowlidge level of a Tech or even System admin or developer just to be able to safely use a computer (Ease of use is a difrent kettle of fish)

    Sorry for the rant , but I am rather narked off at Spam nets

    --
    The only things certain in war are Propaganda and Death. You can never be sure which is which though
  24. Ethics be damned... by chill · · Score: 4, Insightful

    Time for someone to write a worm that forces an update from Windows Update; downloads a copy of SpyBot Search & Destroy, runs it and then turns on the firewall.

    -Charles

    --
    Learning HOW to think is more important than learning WHAT to think.
    1. Re:Ethics be damned... by WhitetailKitten · · Score: 2, Interesting

      I work phone support for a major ISP (hint: butterfly). I hear this a lot. "I don't want to install SP2, [OEM] told me not to."

      I want to say, look, lady, just fucking install SP2. You have Service Pack nothing. Your computer is being chewed into a pulpy mass by viruses that received patches two years ago.

      Instead I push them to their OEM and let their OEM deal with it, since it's their fault they don't have SP2.

  25. Next Step: Take them over. by bigtallmofo · · Score: 4, Interesting

    I think the only plausible defense against a botnet of such a size is to use the botnet against itself. Allow one of your systems to be infected with the botnet - effectively join their network. Then sniff the network traffic to find out what IRC server and channel to join and any security codes that are necessary to control the botnet. Then upload a "virus" into the botnet that will patch the infected system and remove the botnet binaries. No more botnet.

    The only thing that makes me think it might not work is that it's similar to the stereotypical way of ridding the world of aliens in almost every sci-fi movie. Come to think of it, I might have gotten this idea from Independence Day.

    --
    I'm a big tall mofo.
  26. In the end people just won't bother by Anonymous Coward · · Score: 2, Interesting


    in the UK now the earlier hacker key logging story has broken, newscasters are doing their very best to convince people the internet is safe but ultimatly that wont last forever and it will simply be "safer" not to use the internet at all, with rampant ID theft, viruses, extortion by botnets, spam, worms, viruses, spyware,malware,tracking, phishing, 419's,fraud sites, its just not worth the risk of doing anything serious on the net at all! and if the hostilities continues its trend of growth it will be very soon for security professionals to argue against disconnecting as this is will eliminate a substantial risk/cost factor for buisness/private users

    people just cant be bothered anymore (or thats the feedback i get), its just too complex for the average joe who is currently overwhelmed with threats to his financial and personal wellbeing (look at list i just mentioned) its hard enough to protect your assets in the "real world" as it is from conmen,burglars etc, without worrying that a glass screened box in the corner is gonna ruin you and your families life forever if you click on the wrong thing

    i know im getting fed up of it and im an IT professional !

  27. ... and they affect Linux too by poopie · · Score: 3, Interesting

    My home machine's webserver gets regularly punished by bots that are sending buffer overflow URLs. I only have port 80 open, too. I use my home machine for mythtv, and I certainly notice when the bots start attacking me.

    It's really annoying. I've thought about what I can do to shut down bots that are annoying me with excess traffic...

    Does anyone have some good suggestions for keeping zombie PC traffic off of linux webservers either via firewall rules, apache config files, or ?

    Perhaps a more interesting question is... if your machines is being attacked by a zombie PC, is it okay to attack it back (and try to take it offline?) - Isn't this sort of like 'self defense'?

    1. Re:... and they affect Linux too by alyandon · · Score: 4, Interesting

      I have a cron entry that runs a script to examine /var/log/http/access_log for any obviously abusive requests (requests that contain 0x90x90x90x90x90x90, system32, cmd.exe, etc) and adds the offending ip address to the firewall list. I do something similar for my ftpd and sshd services as well.

      So basically my machine becomes invisible to the attacker and their ip address stays shitcanned forever.

    2. Re:... and they affect Linux too by alyandon · · Score: 2, Interesting
  28. I sometimes wonder by cyberworm · · Score: 2, Insightful

    I'm not the greatest security expert, but I follow the proper guidelines (running AV, firewall, patches etc) and I still find that my xp machine is constantly coming up with some sorts of odd processes or quirks. I am giving up on windows as a personal machine, simply because it's ridiculous to constantly be fighting off things like this. I'm not going to blame anyone but the virus/spam/malware writers. I do what I can to practice "safe computing" (sic) and don't download stuff willy nilly.
    I think it's a shame that it has to be like this. Unfortunately the only real solution would be genetically modifying everyone to get rid of the gene that makes people think it's ok to spam/hack/whatever people's machines. Impossible as it is, the best solution would be to shut down the internet for about 2 months, then all the spammers would have to give back their money to the people that paid them (as if they would). Not likely to happen though.

  29. Will it take a Terrorist Act? by arjay-tea · · Score: 2, Insightful

    "Will it take a major internet terrorist attack like bringing down a power grid to make governments act?."

    Yes.
    Of course it will.

  30. Part of the team by dfj225 · · Score: 5, Funny

    I'm glad to be just part of the team!

    <-[XP]-86840>: This message brought to you by Backdoor.Win32.Rbot.gen

    --
    SIGFAULT
  31. Any better metrics on this? by Weaselmancer · · Score: 2, Interesting

    The article says:

    Many well-known vulnerabilities in the Windows operating system were exploited by 'bot net controllers to find and take over target machines.

    That's the only mention of an OS. Any metrics on exactly which OS and version/patchlevel is the most responsible?

    --
    Weaselmancer
    rediculous.
    1. Re:Any better metrics on this? by KarmaMB84 · · Score: 2, Insightful

      Doesn't matter now because even if they've been upgraded, the infections are probably still present and running. They could all be Windows XP SP2 now for all we know, but the trojans are already in.

  32. I wonder.. by MoceanWorker · · Score: 2, Insightful

    How many, out of that estimate, pertain to those who still didn't patch up that stupid RPC/DCOM vulnerability for 2000/XP?

    --


    "The ones who dont do anything are always the ones who try to pull you down" -- Henry Rollins
  33. Does anyone know if... by bluprint · · Score: 3, Interesting

    bots that infect computers ever conflict with each other. Like Bot1 takes over a PC, then Bot2 comes along, and maybe they fight over that PC or its resources?

    --
    A modern day witchhunt.
  34. Comment removed by account_deleted · · Score: 2, Insightful

    Comment removed based on user account deletion

  35. Re:Before Everybody Blames Microsoft by bob670 · · Score: 3, Insightful
    "If Linux had the the type of marketshare like Microsoft, there would still be plenty of zombie PCs to go around with unpatched systems."

    Thank you, I could not have said it better myself. I use Linux everyday, and in all honesty I patch my Linux box more than I patch my Windows XP box. Sure, the Linux box is frequently getting simple app upgrades/patches, but there are a good number of security fixes in those patches as well. An admin I work with left his Red Hat box unpatched and for a year and it got nailed twice, just do the math. Linux might be more secure, but it is only as secure as the person who administrates the box.

  36. Re:Why arent governments proacting agaisnt these n by Brad1138 · · Score: 5, Funny

    I get nice little pop ups telling me my computer may be already infected all the time, don't you?

    --
    If you could reason with religious people, there would be no religious people
  37. Re:Why arent governments proacting agaisnt these n by Florian+Weimer · · Score: 2, Interesting

    This is THE major problem afflicting the internet, why dont governments form a unit to identify and at least notifiy the owners of these machines?

    Why should they? It's the ISPs who make money by providing Internet access. They should be responsible for alerting their customers about compromised machines. Most of them don't because it costs too much money, and there's little liability even if you do absolutely nothing.

    On the other hand, customers aren't willing to pay for a notification service, or accept the privacy implications (notifying customers requires a mapping from dynamically assigned IP addresses to customer accounts). What's worse, a large percentage of them will just switch to another ISP once you restrict their network access because of a compromise.

  38. I find it interesting... by suitepotato · · Score: 5, Insightful

    ...that all these botnets themselves seem to compromised that journalists and researchers can so easily get into them. If you're going to compromise other people's computers for whatever nefarious use, do you want your system itself wide open for someone to steal away from you or document your doings for law enforcement? The best back doors and holes are ones that no one sees until you're using them and it is too late.

    --
    If my grammar and spelling are off, I am [distracted/tired/careless] (take your pick)
    1. Re:I find it interesting... by Jtheletter · · Score: 2, Insightful
      The best back doors and holes are ones that no one sees until you're using them and it is too late.

      I think that's what worries me the most about the sizes of the current botnets we're seeing - how big are the ones we can't see yet? There are definitely some crafty hacker orgs out there who are smart enough to realize that a covert and/or latent botnet would be the most devastating kind, especially if it could return to latency after use. Imagine it, one day a quarter million previously 'safe' windows boxes execute their delayed instructions, form a zombie net, perform a devastating DDOS or the like, then quickly go back to sleep. Parts of it could turn on for short periods solely to infect new machines quickly and quietly. Essentially it's the cyber equivalent of terrorist cells, dormant and unseen until exercised, and impossible to estimate or completely stamp out because of their low-lying nature. One of these days something like this is going to rear its ugly head and it will be for some greater and much more devastating purpose than just sending a few million spam about penis pills.

      --
      -- I'm not a pessimist, I'm a realist. It's not my fault that life sucks so much. --
  39. Re:Why arent governments proacting agaisnt these n by Kaa · · Score: 4, Funny

    No sane person should connect a critical piece of computer infrastructure ... to the internet.

    ROTFL...

    Quickly! Disconnect the backbone from the internet! Unplug the DNS root servers! Take the routers offline! Cut the cables leading into Mae East! The internet is too dangerous!!!

    --

    Kaa
    Kaa's Law: In any sufficiently large group of people most are idiots.
  40. Re:Before Everybody Blames Microsoft by brxndxn · · Score: 4, Funny

    But it IS Microsoft's fucking fault! Microsoft has ultimate control over almost every users' system... and almost ever users' system eventually gets compromised.

    Microsoft's browser that gives developers every last inch of control over a user's PC is what inevitably led to developers just completely taking over users' PCs. Microsoft insists on certain features in Internet Explorer that make it a pain for even the smartest PC users to control what they see.

    Here's some problems with IE:
    - no real ability to disable popups (Completely disallowing all forms of popups is more secure and convenient for the USER. Fuck developers.)
    - Install on demand (What a fucking trainwreck feature this is. Developer puts the 'yes' button behind the 'close' button nested 8 popups under the first one. User gets frustrated and clicks 7 close buttons and 1 button marked 'fuck me in the ass please')
    - Patch-and-fix attitude.. It's somehow not Microsoft's fault if they allow 'get into my PC free' for two months if they eventually release a patch for it?

    Here's how you fix Internet Explorer:

    - get rid of 'install on demand' (Make it so users have to actively download and install what they want installed. This whole 'make things easier for flash to install itself and bombard you with ads' is stupid.
    - SUE MICROSOFT. That's right. Consumer class-action large-scale - the type of lawsuit that puts them in the red for a quarter. How many billions has this cost Joe Consumer?

    "Just remember that it is also the responsibility of the computer users to patch their systems in a timely manner as soon as they are available."

    What if my computer is already fucked up, assface?

    Ya, I'm pissed. I'm not an idiot computer user - I spend 8 hours a day on a computer. Yet, while typing this, I got a goddamn a.tribalfusion.bullshit popunder sitting there on my taskbar... and this is while I'm running a proxy filter, run Spybot, run Ad Aware.. And, if I'm having problems like this, Joe Consumer is getting raped.

    Ya, you can call me stupid and say I browse the Internet wrong or whatever shit like that. But, this shit never happened back when Netscape was the dominant browser and it did not allow the developer to ad 'features' that work much like a virus.

    These zombie PCs ARE by and large Microsoft's fault. Microsoft needs to implement features with the idea that developers will EXPLOIT at every turn possible for money and they need to focus on the consumer, for once. You can't tell me that Microsot doesn't know that Joe Consumer does not want 8 popups while browsing Slashdot.org.

    BTW, if anyone has an easy, one-click fix for all the problems I have browsing (that is made by Microsoft, built-in to Internet Explorer), I will print out this post and EAT IT.

    --
    --- We need more Ron Paul!
  41. Zombie.SETI@home by mykroft42 · · Score: 3, Funny

    Perhaps all these Zombie comps should be put to good use. Who cares if people don't want to participate in grid computing ... they can be forced!

  42. windows 2000 box: a zombie in ~ 5 minutes by hurricaen · · Score: 4, Interesting

    My coworker is doing some of his own investigations into this stuff. He hooked up a freshly installed, but unpatched, windows2000 box to the net with a freebsd box in between to monitor traffic. Within minutes it was infected, and we could see IRC traffic: connecting to a hidden channel to await instructions. Not that I'm that outraged that an old unpatched windows 2000 box is vulnerable; it's just amazing how quickly a worm will get you if you are vulnerable! -K

  43. Rent zombies online! by Animats · · Score: 5, Informative
    They're down today, but SpamForum.biz carries ads for zombies, open proxies, botnets, etc. Numbers available range from 1000 to 50,000.

    When they're up, they're very entertaining.

    An older spammer forum, SpecialHam.com is back up. With banner ads, even. "DarkMailer - not for newbies". "Blackbox Hosting - bulletproof hosting options" "SendSafe - bulk mail has never been this easy". "Bulkhost.com - the leader in bulk-friendly e-mail hosting".

    Sites like these are where the hackers and spammers meet, find deals, and scream about being ripped off by each other. The actual deals tend to take place on ICQ.

    1. Re:Rent zombies online! by Don'tTreadOnMe · · Score: 2, Funny
      With banner ads, even. "DarkMailer - not for newbies"...

      So I clicked on the Dark Mailer ad, thinking it'd be good for charging them some ad money, and was amused instead:

      If you have installed a cracked version on your computer by mistake, we suggest you format your hard drive and reinstall Windows. Delete the cracked version and download Dark Mailer from this site.

      Beware teh cracked SPAM software!

  44. Comment removed by account_deleted · · Score: 2, Insightful

    Comment removed based on user account deletion

  45. Bill Gates is using a robot net to by BrentRJones · · Score: 2, Funny

    Bill Gates is using a robot net in building a spacecraft to return to his solar system.

    --
    Help end the use of Sigs. Tomorrow
  46. Re:Before Everybody Blames Microsoft by Dashing+Leech · · Score: 2, Interesting
    "Just remember that it is also the responsibility of the computer users to patch their systems in a timely manner..."

    This is true, but I'd like to go one step even further. Is there software out there to check if your PC has been co-opted, like what honeynet has but for regular users (just an integrity check)? I have a server with a firewall, then a router with a firewall, then ZoneAlarm software firewall on my main home PC. I expect this should be safe, but I know I've gotten spyware and adware on it (from downloaded programs), so even removing that how is one to know if there's an exploit through one of the legitimate I/O routes (web browser, P2P, IM, etc.).

  47. Comment removed by account_deleted · · Score: 2, Insightful

    Comment removed based on user account deletion

  48. Distributed processing by mr_z_beeblebrox · · Score: 2, Insightful

    How long til they start using distributed hijacked PC networks to crack complex codes etc....

  49. Cluster by EduardoFonseca · · Score: 3, Funny

    And people say that the largest computer cluster in the world runs Linux. Bah!

    Of course it runs Windows! Go Microsoft!

    *ugh*

  50. Obligatory Buckaroo Banzai: by SmokeHalo · · Score: 4, Funny

    "Where are we going?"
    "Planet Ten!"
    "When?"
    "Real soon!"

    --
    I'm not good in groups. It's difficult to work in a group when you're omnipotent. - Q
  51. "Zombies" by Audigy · · Score: 2, Interesting

    Ah, thank you Steve Gibson from grc.com for that lovely nickname.

    --
    [an error occured while processing this directive]
  52. Appliance by Straker+Skunk · · Score: 2, Interesting

    The ISP needs to force the user to at minimum to install a software firewall.

    Simpler than that. Just give customers a firewall appliance with their modem, and warnings of the doom that will befall them if they don't hook it up between their modem and PC....

    --
    iSKUNK!
    1. Re:Appliance by j1m+5n0w · · Score: 3, Informative

      Simpler than that, put the firewall at the ISP end of the connection so they can't get around it. (But I think users should still have the option of enabling incoming ports if they so choose.)

  53. Re:Why arent governments proacting agaisnt these n by DavidTC · · Score: 2, Funny

    The Internet is much too important to be connected to the Internet.

    --
    If corporations are people, aren't stockholders guilty of slavery?
  54. A fresh install solaris is just as vulnerable by merreborn · · Score: 4, Interesting

    My father recieved his first couple of Sparc-based unix boxes about 4 years ago in the wake of the dot-com collapse. For one reason or another, he decided to reinstall (a somewhat old version of) solaris from a disc he got with the system.

    A couple of days later, his cable-modem based lan was nigh unusable; lo and behold, the unpatched solaris box was sending out data as fast as it could. Neither of us had the technical expertise to figure out what exactly had happened, but the process that was causing all the trouble was sitting in a dir full of various tools that seemed to be doing some sort of IP range scaning and self propegation.

    If there are enough systems out there with a given hole, someone will exploit it, reguardless of OS.

  55. Re:What can I use to detect a hijacked computer? by Foolomon · · Score: 4, Informative

    "netstat -a -o" will display all active connections and the processes that own them.

    Task Manager will show you the currently running processes. This is of limited usefulness since it doesn't show the path of the executable nor the arguments used to launch it. So SVCHOST.EXE will show up multiple times because it is used to by 2000/XP to run several different services.

    "Control Panel > Administration Tools > Computer Management" will run an applet that, among other things, will allow you to see the number of open shares and connections to your computer. There are some other useful things in there.

  56. Re:Not their responsibility by magarity · · Score: 2, Informative

    but I don't pay my ISP to protect me and my privacy. I pay my ISP to provide a pipe, and nothing more

    And your ISP pays *its* ISP by the MB. It is therefore in their interest to halt traffic generated by spam-bots and ddos-bots.

  57. What is the control group? by gelfling · · Score: 4, Interesting

    I have a bunch of Win XPhome, Pro and W2K boxes @ home, fully patched, personal firewalled, my router screens what it can, in fact it blocks most every port and tosses pings from both sides. There's antispyware and AV scanners running on all desktops. And brute force scans for virus and all other malware kick off weekly. The uplink is cable (shared). Am I contaminated? You betcha. I can run any spyware tool @ random and find something and once a month I trap a virus either in the browser cache or the jpi cache on one or all of these machines.

    Shit I forgot why I wrote this - oh yeah. What is the definition of "GOOD"? So while there 1.2 globzigillion zombies out there, what is the likelihood you're actually clean? I'd say damn near zero.

    1. Re:What is the control group? by WalterGR · · Score: 3, Insightful

      I can run any spyware tool @ random and find something and once a month I trap a virus either in the browser cache or the jpi cache on one or all of these machines.

      I wasn't looking over your shoulder when you performed this scan, so I don't know precisely what you saw, but finding things in the browser cache is not cause for alarm. For example, if I were to rename some virus-laden executable to have the JPEG extension, reference it in an img tag in an HTML file, and pop it on a website, all browsers would download the file - they don't know any better. It's not like they're then going to say, "Oh look, it's an executable! I better run it now." (At least, one would hope... :)

      Just because you find something in your browser cache doesn't mean you're infected.

  58. You've just described ... by tomhudson · · Score: 4, Insightful
    I think the whole idea is extremely intriguing. Once you have a system set up like that, capable of accepting commands.. you can do whatever you want without ever having a trail come back to you. Having a machine tell another machine tell another machine what to do.
    ... the next version of p2p software that the **AA will have one hell of a time trying to combat.

    Have your machine intentionally be part of the "zombies", and you get all the goodies, and look like a victim at the same time.

    1. Re:You've just described ... by LilMikey · · Score: 2, Funny

      Have your machine intentionally be part of the "zombies", and you get all the goodies, and look like a victim at the same time.

      Damn... you've just uncovered the one thing that could possibly draw Linux and MacOS users back to Windows.

      --
      LilMikey.com... I'll stop doing it when you sto
  59. Re:You Must Be Linsux User Right ?? by Guido+von+Guido · · Score: 2, Funny

    Don't tell my wife or my girlfriend.

  60. Why don't ISPs use Firewalls? by guru42101 · · Score: 4, Interesting

    I work for a minor dialup in BFE, KY. We used to have large problems with our users getting hacked and zombiefied. But we decided since they weren't going to have a local firewall then we'd run one for them. Generally speaking Joe User doesn't need an internal SMTP server, http server, and so on. So we've got it set up now where they can connect to http, ftp, send their emails, send their IMs, play their games, and even use BT. But, alot of things that they'll never noticed are disabled for their own good. We'll occasionally have someone call about something not working and we'll then add in a rule to punch a hole for them. But I think that has been one person in the past year so far.

    I'm surprised more ISPs don't do this as we used to be overloading our pipe due to the bots but now we're using half of our pipe durring peak times.

    I could see this as a potential issue for some broadband ISPs but the saved money in bandwidth is much higher than the cost of manpower

    1. Re:Why don't ISPs use Firewalls? by SuiteSisterMary · · Score: 2, Insightful

      It's not the ISP's job to firewall. The clients are paying for an Internet connection, not a web-browsing service, so they get a damn Internet connection.

      Besides, by doing some filtering, you take responsibility. You remember, common-carrier status and all that.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
  61. Will never stop unless.... by Electric+Eye · · Score: 4, Interesting

    ....a group of super smart nersd somehow figures out how to do the same thing to these millions of PCs, but in reverse. Somehow create a worm that turns on the XP firewall, installs MS Anti-Spy and SpyBot and whatever else is needed. Isn't this easy to do (for the geek crowd)? Every new client I get (I'm a home computer tech) is infected with massive amounts of spyware. They have NO idea. My last two clients had more than 10,000 files and programs that were deemed spyware (not including cookies). It took forever to clean these machines, esp with those damn trojans not wanting to leave. I've got years of experience so I know what to do. But 99.999% of Windoze users doesn't have the damndest clue. My clients can't even set up their own DSL connections. how are they going to prevent their computers from being turned into zombies? Hell, they don't even know what that means.

    It's up to the benevolent hackers or MS. My $$ is on the geeks outside of Redmond.

    1. Re:Will never stop unless.... by Electric+Eye · · Score: 2, Insightful

      Like that act is stopping the malicious attacks? Dosn't look like it. You have a better idea?

  62. Do NOT clean up Winboxen for free. by Werrismys · · Score: 4, Interesting
    Do not clean up these boxes. Disconnect them from net and tell the relative in question to either PAY for the cleanup, get someone else to clean it, or get a Mac.

    Bad PR but who the fuck cares.

    tihihi I said boxen.

    --
    'Once scientists, even the dim-witted social scientists, get muzzled, the Western Civilization is finished.' - oldhack
    1. Re:Do NOT clean up Winboxen for free. by FriedTurkey · · Score: 2, Funny

      Do not clean up these boxes. Disconnect them from net and tell the relative in question to either PAY for the cleanup, get someone else to clean it, or get a Mac.

      Dude you want me to charge my Mom? Should I tell my 60 year old mom "PAY UP WITH THAT SOCIAL SECURITY CHECK MONEY BITCH"? Sorry I am not a heartless bastard.

    2. Re:Do NOT clean up Winboxen for free. by Arslan+ibn+Da'ud · · Score: 2, Insightful

      Dude you want me to charge my Mom? Should I tell my 60 year old mom "PAY UP WITH THAT SOCIAL SECURITY CHECK MONEY BITCH"? Sorry I am not a heartless bastard


      Who said anything about charging $ to clean up Mom's PC? Better yet to barter with her...clean it up for a batch of cookies...or a 6-pack. People are generally a lot more willing to trade goods/services than pay $.



      And if she's family, she should understand where you're coming from. You may not be a heartless bastard, but the spammers sure are. And keeping that machine clean costs $. Or cookies :)

      --

      Practice Kind Randomness and Beautiful Acts of Nonsense.

    3. Re:Do NOT clean up Winboxen for free. by DaveJay · · Score: 2, Insightful

      Consider telling your mom "Hey mom, I just bought you a new PC. Here's the deal, though: since you don't have the time or money to keep your computer from getting infected, I had to get you a different kind of computer. It's very easy to use, and does lots of great stuff, but looks a little different. The good part is, you won't get disconnected again. Oh, and I'm putting this little box (router) between you and the internet for your protection. Don't worry, you don't have to actually touch it or do anything, it'll just work."

      Then drop a Mini Mac on them.

  63. Re:Why arent governments proacting agaisnt these n by BVis · · Score: 3, Insightful

    why dont governments form a unit to identify and at least notifiy the owners of these machines?

    To paraphrase the late great Jerry Orbach playing Lenny Briscoe, "Sure, let's get the government involved. That'll solve everything."

    And as far as the ISPs go, I've worked for ISPs that wouldn't even cut someone off for non-payment for fear of their subscriber numbers going down. Do you really think they have the manpower, resources, or interest in doing anything about this until they're forced to by business pressures? (eg, never.)

    The only way to fix this problem is user education. And because most users refuse to be educated, or accept any form of responsibility for their own machines, I don't see this problem getting fixed. Ever.

    --
    Never underestimate the power of stupid people in large groups.
  64. Those aren't Microsoft Zombies by consumer_whore · · Score: 2, Funny

    Remember, Linux is is the Insecure OS, not WIndows! http://linux.slashdot.org/article.pl?sid=05/03/16/ 1517207&tid=163&tid=1&tid=218

  65. 10 Year Setback Sounds Great! by MooseByte · · Score: 4, Insightful

    "If Joe User were required to start by using Linux or BSD, it would set computing back 10 years."

    To a time before rampant SpambotNets and the DMCA. Sign me up! :-)

  66. Re:Why arent governments proacting agaisnt these n by 615 · · Score: 2

    What? What?! NOW it's the ISP's responsibility?? Consistenty, Slashdot. Please. ISPs provide a connection to the Internet. It's the USER's responsibility to decide what they do with that connection. And it's the GOVERNMENT's (read: society's) responsibility to find and prosecute the sons of bitches who willfully and with malice inject our machines full of their garbage--be it bots, spyware, or spam. Casting [any] blame on the ISPs is akin to blaming P2P companies for copyright infringement or blaming Smith and Wesson for drive-by shootings. I could go on for hours, but I feel like I've made my point.

  67. P2P Nets by nurb432 · · Score: 2, Interesting

    So how many of these are being used for P2P serving?

    "But Judge, I wasn't me that was sharing those files "

    Before you laugh, I had a Linux 'router' broken into about 8 years ago. I of course caught it in nightly auditing, but it happened.

    Turned my machine into a porn ftp server and a bridge to break into the next person.. If I hadn't been auditing, might have been months before discovery..

    --
    ---- Booth was a patriot ----
  68. My local one does sometimes by dlZ · · Score: 3, Informative

    I've had machines show up in my shop along with notes from Road Runner stating that they can't regain their service until they show proof the machine was repaired properly. These machines have always been so bad off, they were unusable, yet they were kept online constantly, to display popups and act as zombies.

    One case it was actaully not the customers machines, but his neighbor who was taking a free ride on their wide open wireless network. Turning on WEP immediatly fixed the problem. The customer couldn't figure it out, because they were a household of Macs, and were sure they couldn't get hijacked like that. They never even thought of the wide open network.

    --
    rm -rf ./evidence @ punkcomp
  69. Honeynet by smoker2 · · Score: 3, Interesting
    From the Honeynet homepage:
    More than 90% of these connection attempts were caused by a machine running Windows, whereas only about 3% could be identified as originating from Linux machines.
    The first attempt to attack one of the honeypots was noticed about ten minutes after the whole honeynet was attached to the Internet. The system was systematically searched for weaknesses (port scan) and the attacker tried to exploit a known vulnerability in the Internet Information Server (IIS). After this short period of time, an unpatched version of this server would have been compromised.
    The ports 445, 135, 137 and 139 - all belonging to Netbios, the protocol favored by the Microsoft Operating System family - see by far the most traffic.

    Apparently they were using SUSE 8 Pro and Solaris 8 as the Honypots. My issue with the BBC article is that although (as can be seen from the Honeypot site) 90% of the attacks were aimed at, or originated from a Windows machine, the offending OS is mentioned only once.
    They (the BBC) should spell it out, so that the general public actually gets notified officially, and thus make it a well known issue amongs non-IT literate people.
  70. Re:What can I use to detect a hijacked computer? by Suidae · · Score: 2, Informative

    That is a connection between your system and the box on the rogers network, but I can't tell you which side opened the connection.

    The last number is the process ID on your computer that holds the socket. Go to the task manager (right click on task bar or ctrl+alt+del) and select the Processes tab. If the PID column is not visible, select View|Columns and turn on the PID column.

    If you don't recognize what you find in the 'Image Name' column, you can usually do a google search and find it.

  71. Re:Why arent governments proacting agaisnt these n by needacoolnickname · · Score: 2, Insightful

    why dont governments form a unit to identify and at least notifiy the owners of these machines?

    I think I would prefer my tax dollars go to the fixing of schools and highways or medical research or even the military before someone gets a government job notifying people that their comptuters are bothering people.

  72. Recommend: Process Explorer by x2A · · Score: 4, Informative

    Google for "Process Explorer" - free download, shows all processes and CPU usage (there is also an option to show % fractions of CPU usage or context switches for being really precise). Shows processes in a tree also, so you can see what's started what. Also gives ability to pause (a la -SIGSTOP/CONT) processes, very handy lil download. Well done the creators.

    -2A

    --
    The revolution will not be televised... but it will have a page on Wikipedia
  73. Win95 box: Never bothered :-) RH6 - killed. by billstewart · · Score: 2, Interesting
    A couple of years ago I got DSL in my lab, and left a couple of machines on it unprotected partly to experiment with and partly to see what would happen to them. One Linux box was running tcpdump continuously to sniff the network. The Win95 box was never bothered - it had anti-virus software, and I used Netscape rather than IE (and of course there was nothing useful on it to exploit because it was a Win95 box :-) The RedHat 6.x box typically lasted a week between crackings - I eventually named the machine "Kenny" because it kept getting brutally and senselessly killed every week. One of the crackers really didn't like it when I got rid of his Staecheldraht installation and reformatted the disk. So I installed a newer RedHat version, in a mode with no servers running, and people mostly left it alone other than basic doorknocking.

    This *was* a few years ago, and crackers have gotten more sophisticated, and DSL and cable modem proliferation means there are lots more fast net connections for them to work with. At the time, Win95 was obsolete, RedHat was doing 7.x versions, and Staecheldraht attacks seemed to mostly come from universities (including Washington University, whose wu-ftpd was one of the main holes exploited by crackers, and a machine that looked like it was from MIT but was actually from somebody in Japan with a byte-order problem.)

    --

    Bill Stewart
    New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks