The New Face of Script Kiddiez
An anonymous reader writes "Washingtonpost.com's Security Fix blog has an interesting post profiling the activities of a kid named Witlog who controls a botnet of roughly 30,000 hacked Windows PCs. Even after the authorities manage to shut down the network Witlog uses to control his bots, he pops up somewhere else. From the article: 'Witlog may in fact be the product of a new generation of script kiddiez; the chief distinguishing feature of this generation being that instead of using Web site flaws to deface as many Web sites as possible, these guys are breaking into thousands of home and work PCs and taking them for a virtual joyride, often times all the way to the bank.'"
Would seem to imply a new genre of script kiddie, such as old people doing it, rather than a mere change in behavior. And if they can track and shutdown is bot network, why hasn't someone arrested this idiot?
...these guys are breaking into thousands of home and work PCs and taking them for a virtual joyride, often times all the way to the bank.
Great! Maybe he can reconcile my account balance while he's there.
This guy's the limit!
...is just as pimply as the old face.
i find it rather funny that all these bot-net owners are getting so much publicity right now. The washington post recently had another article about another botnet owner. this is nothing new. people have been exploiting various networks and running botnets for at least a decade (that I'm aware of). these new botnets aren't any larger than the ones back in the day, either. in fact exploiting systems back then was way easier since security wasn't nearly as important to many people and firewalls were pretty rare. either way, ITS LAME
Hasn't this been going to for awhile?
"We are all geniuses when we dream"
- E.M. Cioran
These kids should be the new face of P2P research and production. Kids care more about group recognition, new toys and testing/breaking limits than they do about money. If more effort were put into giving them constructive P2P toys to play with, they would spend much less of their own effort breaking stuff.
Just stopping kids is a losing battle. The only way to win is to substitute something else into their idle hands. This has been proven over and again, most obviously with "Little League" which replaced gangs of window breakers with happy campers.
--
make install -not war
The worst part of this is that when these people are caught they are often given lucrative jobs at security and antivirus companies. Making the front page of slashdot will probably even look good on the lucky bastard's resume.
And what kind of name is witlog? It's like cunningpoop, or something.
Religion for nerds. Stuff that really matters
that should be distinctive on this "new face" is that it's either:
* Bruised and bloodied from the clue by four that's been applied; or
* mouth wide open screaming as his cell mate takes a new "wife."
I guarantee half of those bots are a result of some rogue ActiveX installation that most moms didn't know enough to click "don't install". Do everyone a favor, and just shut off ActiveX entirely. -- Jim http://www.runfatboy.net/
This morning WNBC News (Channel 4) in New York was touting an upcoming segment on identity theft. It turned out to be a jailhouse interview with a phisher who's doing hard time for grand larceny.
RichM
Data Center Knowledge
Spread a worm that:
:')
* Spreads itself to at least 2 other computers (for survival)
* Downloads and installs ad-aware
* Activates your windows firewall
* Downloads appropriate patches from Microsoft
* Prepares ad-aware to run on the next boot
* Deletes itself from the system
That'd be so beautiful *sniff*
SecurityFix: so did you just download the source from some site and set it loose?
Witlog: yes
Witlog: changed settings, and started it
Witlog: thats all
Witlog: anyone could do that
Witlog: you don't have to know many things to do a botnet like this
Why can't Microsoft push out its security fixes like this???
He who knows best knows how little he knows. - Thomas Jefferson
Witlog: so when i've read that article, i thought "why not to make my own"?
SecurityFix: so did you just download the source from some site and set it loose?
Witlog: yes
Witlog: changed settings, and started it
Witlog: thats all
Witlog: anyone could do that
Witlog: you don't have to know many things to do a botnet like this
This kid is not a "hacker" or "cracker" anymore than I'm a professional wrestler. He finds a script or two somewhere, configures it, and lets it go. He has no moral compass, he doesn't care about other people's property, and he seems to think this is a hoot. He sounds too much like those college boys who are accused of setting those Alabama church fires.
But as he says, anyone can do this. While it's nice that goups like Shadowserver.org are tracking down and shutting down these botnets, why isn't someone doing something about the supply source for these scripts? It's like leaving a loaded gun lying around -- some idiot may decide to use it, even though they don't know how. I say find the morons behind the botnet scripts and take them out. Stop wasting time on the small fry.
GetOuttaMySpace - The Anti-Social Network
Why isn't this little turd in prison? Are our authorities that FUCKING lazy that they can't track down and arrest some little punk like this who's engaging in thousands of counts of criminal tresspass? What the FUCK?
The only reason this guy is having any success at this is because of the default security settings on Windows.
No, this isn't an anti-Microsoft rant. But the fact is that without those open ports, his worm wouldn't be spreading. You cannot depend upon the end-users to correctly patch or firewall their systems.
All it would take to stop this guy is for the next version of Windows to ship without any open ports by default. Ubuntu already does this, Apple already does this.
Having a software firewall on the machine is a distant 2nd place option. If there is a flaw in the firewall software, he'll have the same opportunity he has now.
I know they do'n't spelcheck articlez, but this is rediculus!
If only I could come up with a script to clean a machine reliably I'd save plenty of time. Just today I tried and failed to de-crapify a horribly compromised Win ME/kazaa-induced nightmare.
I spent nearly an hour with ad-aware, hijackthis, and spybot s&d before realizing best case I'd end up with a limping Win ME system.
Now it's happily running 2k, fully patched, and the ignorant user warned.
Man, you really need that seminar!
What he does is wrong. Don't get me wrong.
At the same time, I couldn't give a rat's ass. Leave your car unlocked, get your radio stolen, see me cry 0 tears.
Leave your house unlocked, and the fine china will walk out the front door.
Leave your computer unprotected, and your data/bandwidth will be taken.
We run OS X/Linux. Automatic security updates, 0 ports exposed, everything behind a NAT, no automatic execution of downloaded files, and nobody types in administrator password without calling me first, either because they don't know them, or they know to verify EVERYTHING with me. Did I mention that user desktops run few (no) services? CUPS, SMB, SSH. No remote or local root logins.
Everyone here understands that ANY thing they download could potentially result in all their data being messed up. Period.
The last piece of the puzzle for me would be to prevent people from "spoofing" OS X users using incorrect icons for executable mime-types. Then I'll be happy.
Why should I care?
WhiteWolf666 an exBush supporter. All you new-school,compassionate,save the children Republicans can rot in hell
This kid is not a "hacker" or "cracker" anymore than I'm a professional wrestler.
D'OH, that's why the article title says "script kiddiez", not "hackers".
"At least one machine that he showed me from his botnet was located inside of a major U.S. defense contractor."
Ah, the irony...
Many people don't care how they make their money. Only how much.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Hardly. I simply warned the user that if they ever brought me a spammed-out zombie again I'd charge double.
And be crabbier.
Sure, your cousin did it. Nobody installs bad software on their own machine.
Man, you really need that seminar!
The writers write code against systems that are easily broken into. The SKs that would create botnets, simply grab code that is on the net and use it. It was never about size. It is about the ease of getting systems.
I prefer the "u" in honour as it seems to be missing these days.
Adam Vitale aka Batch1 arrested by Secret Service
M.
Saw your other post too.. U r right, whoever isn't mailing compliant these days and is promoting illegal shit like pharm or stocks on top of it, is just asking for the feds to bust through their door...
Hamster
I am not saying this guy didnt scam tons of people which is not right however if swank does not like you for whatever reason he will post you info on his anti friends websites so be very very carefull when dealing with swank and make sure your personal info is kept to you.. Personal revenge is the key to try and recover money that was scammed not whoring shit out to the anti's....
P.S. swank you know I dont like fake people.. You guys get a kick of this one http://www.spamhaus.org/rokso/evidence.lasso?roks
Look half way down the message and you will see this
"Swank"(Chris Brown) and "Batch1"(Adam Vitale) are in a tiff over a spam deal gone bad, and are in a flame-war on spamforum.biz.
Swank has repeatedly posted "Batch1's contact info that was used in their spam dealings with each other.
I think this is what I have been explaining all along about how swank has ties to the antis and posts peoples info if he doesnt like them and if you notice reading these articals the anti's really never say anything bad about swank HMMMM I wonder if he is friends with them.. Enjoy guys.....
1200000 / recipients_per_Email = 47,000 emails sent.
hard to understand isnt it hamster
also if you've paid any attention to the forum, the informant (sean dunaway) is already notified and you've started a double thread because of your ignorance
This is starting to sound like those Mafia wiretap transcripts that came out as the New York Mafia was coming unglued. Law enforcement was doing well enough that the crooks were more afraid than the good guys, and were desperately trying to figure out who was selling out.
Spamming is starting to yield to straightforward police work.
I should point out that ISP blocking makes these folks essentially useless, not to mention limiting upstream.
However, I hate that my ISP is packet filtering for things like torrents (Rogers), one has to wonder why they fail to filter for the things that uselessly waste their network rather than the people who actually use it.
-M
when you see the word 'Linux', drink!
When he sends that 'net for a DDoS ride to your address.
I have zero sympathy for idiots who can't secure their system. If they could only harm themselves, they could just as well go down in flames. Maybe it would work as a LART on them.
But it doesn't. Those bots are supposed to be no damage to the infected machine, but instead use said machine to cause harm somewhere else. If it DID cause some damage on the infected machine, the infected person would probably care.
So his attitude is just like yours: Why should I care?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
The claim only needs to be as credible as Jr's claim about Al Qaeda and Saddam. Then just sit back and watch...
Like which System Admin of a large government contractor is not aware of network security in this day and age, which would allow compromised computers and connections to the outside world?
In the future, when computers are recognized as citizens with rights, botnet operators will be viewed as slavers, and any punishments they will have received be viewed as a mark of moral growth in society. (Personally, I don't agree that computers should be citizens. But given how so many people are stupid enough to see a soul in a zygote, there's little hope that in 20 years or so they won't see souls in their household devices, too.)
Why shouldn't kids who damage thousands of computers be subject to the same penalties as the kids who burned down those churches recently? The economic damage is about the same. The excuse, "This started as a joke!," about the same. The amount of effort required to start a fire or set loose a virus, about the same. It's destruction of property, with great economic loss, and serious inconvenience to thousands of people's lives - in both cases.
If we'd do the sensible thing and repeal the drug laws, we'd have plenty of room in our jails for these thugs.
"with their freedom lost all virtue lose" - Milton
It seems that you've been living two lives. One life, you're Thomas A. Anderson, program writer for a respectable software company. You have a social security number, pay your taxes, and you... help your landlady carry out her garbage. The other life is lived in computers, where you go by the hacker alias "Neo" and are guilty of virtually every computer crime we have a law for. One of these lives has a future, and one of them does not.
I'm sorry, I just watched matrix today again, so all my comments today might reflect it..i will go back to my cave till i'm off it.....
Like Script Daddiez.
Imagine if these bot nets did something more subtle... like.. turning a single random pixel black or slightly fudging the movement of the mouse. Warranty Havoc!! Gawd that would suck.
K. Thx. Bye.
Botnets ain't new. They're even past their prime, past the time of the huge 'net that grew, unhindered by user awareness or antivirus tools.
Today's botnets are no longer standalone tools. They are used to spread secondary attacks. That's where the new threat comes in. That's how secondary threats like trojans and viri can spread via email. Or you can use the botnet to download and distribute updates for trojans.
The possibilities are pretty much limitless. Just imagine you have a few 100 to a many 1000 computers at your hands that could be used however you like, and let your imagination run wild.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
So we can all examine the EXIF fields, of course...
Some people trust the system on their computers because they don't know any better. That doesn't make the bad or wrong. Just "ignorant".
The only difference is that you have a physical limit to the houses you can break into. There is no such limit on computers.
People have a much easier time understanding physical security because they can see it. They know when they've been robbed. They know when the neighbors are robbed.
With a computer, they probably won't know, or even really care. Unless they lose money from their accounts.
And fighting against ignorance is a long and difficult task. There are millions of individuals out there and each one has to be correctly educated.
Personally, I'd recommend focusing on an easier target ("easier" being relative here). Get Microsoft to ship the next version of Windows without any open ports by default. Yeah, I know what you're going to say. But it's more likely to happen than educating the millions of individual users out there.
..only old people run botnets.
my password really is 'stinkypants'
some of the sources used can be found at the private section of http://sinred.com/
- - - - - .
All it takes to put this kid out of business is to send a real badass hacker/cracker after him.
Per Aspera Ad Astra.
However, they too can bring down networks in a DDoS style; even while cleansing the system.
That's because the white worms are more or less engineered off of the previous one. I don't want to make the comparison to the topic of this post (since I respect their endeavor), but they're basically behaving like script kiddies.
If it was properly done, the worm would automatically delete itself after x days or after receiving a ping from another white worm (with the newer worm taking over security of that network from the old). That would prevent DDoS and eliminate all problems... Until revision B of the original worm, which mimics the ping, but by then most of the computers that are prone to infection will have been immunized.
the activities of a kid named Witlog
Man, what were his parents thinking?!
The kid probebly was told by his 'expert' compy486 teacher that he can be a god with sub7. I dont think the error is the kids, I think its the users that got infected by a worm from the kid. PROPER ANTIVIRUS PEOPLE! *starts to mumble AVG, Antivir...*
We all here know what a hacker is. We all know what a cracker is. We all know what a script kiddie is. That's what we know.
The audience of the media don't know what a hacker is, or what a cracker is. They don't know that these botnets are not hackers or even crackers. They don't know what script kiddies are. The BBC calls these dudes hackers.
We know why script kiddies do their worthless crap. They do it for the attention. They do it for their own ego. The money makes them extortionists and thus, criminals. The media is making script kiddies out of ordinary losers by making them famous and calling them hackers.
Why doesn't some group of white hats get together to search for machines that are open and then close those machines via turning their firewall on, or if the machine is too old/limited/compromised already then disable it sufficiently such that the OS must be reinstalled?
I come here for the love
Man, what were his parents thinking?!
Yeah, why couldn't they of given him a real name like "Sunbeam Wind Child", or "Tiffonia".
What could be better than a jet powered motorcycle? http://www.youtube.com/watch?v=u8l6GTHLSWE
Behind bsd firewall / nat All machines behind it are either linux (tightened up, no ports open) or a flavour of bsd (Openbsd). Did forget to mention that i monitor firewall traffic regularly, and run Cron-apt to get security updates? Come at me holmes!
these guys are breaking into thousands of home and work PCs and taking them for a virtual joyride
:-)
You don't usually call it a break-in when you let the person in through an open front door.
Then again, these guys are going in through open windows, which is usually frowned upon.
Direct away from face when opening.
It's really sad that people are just NOW figuring this out. =/
the only permanence in existence, is the impermanence of existence.
...for bringing this "Estonia" to our attention.
We will now be bringing American Democracy(TM) and Freedom(TM) to the Estonians who live in this lawless and vile place.
Join the Army today, and fight for the Freedom(TM) of the Estonians! (Or are you one of them? Are YOU Unpatriotic(TM)?)
There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
With hundreds of open Wireless access points residential and business. Add to that PC's sharing out their C:\ drives with no password courtesy of the person who installed it. You don't even have to be l33t script kiddie. You just might be on your neighbors access point strictly by accident.
We salute you Mr. linksys admin:admin wireless residential internet service providerrrr.
The Microsoft "get the facts" ad that accompanies it...
>Speaking of which, that lock you have on your front door can be picked in a few seconds. /me puts on "physical security" hat
Kicking, not picking, is the threat to protect against first. Get a reinforced strike plate, make sure the screws reach into structural framing.
Locks with sidebars and tight tolerances make it harder for a would-be picker to use a torsion wrench. Add angle-cut keys, such that the pins have to be lifted *and* rotated to the right amount, and you've create a tough problem for anyone who wants to pick the lock.
Medeco is famous for attack-resistant locks, and a priori there should be other companies equally good that I haven't heard of because they do less marketing.
Somewhere during that process, take a break from obsessing about the door and give some serious thought to the windows.
Someone could deliberately change their writing style, hoping that would make the reader think that the author is from .
But that requires good language skills and knowledge of several foreign languages; I believe people who have these skills are too smart to be playing around with nasty things on the Internet.
The saddest poem
Kinda like that girl from Alabama that went to Aruba to somke pot and/or drink and/or other stuff that would have been illegal for her to do at home, got killed or has otherwise gone missing and sparks a large conflaguration of peoples to trying to enforce US law on foriegn soil.
The problem with all those foreigners is that they're so foreign
I have been using NTL as my (UK) ISP, and suddenly found I was banned from /.
On inspection, it's the (very well advertised) proxy which is banned..
The proxy IP is well advertised as it's the only one that works correctly with eBay on NTL's network. Unfortunately, I don't rate NTL's chances of finding or dealing with the kiddie responsible, based on their current performance: and they are a cable co.!
[ insert meme here ]