Eavesdropping on a Botnet
wild3rbeast writes "Joe Stewart, a senior security researcher with LURHQ's Threat Intelligence Group has figured out a way to silently spy on a botnet's command-and-control infrastructure, and finds that for-profit crackers are clearly winning the cat-and-mouse game against entrenched anti-virus providers. From the article: 'The lesson here is once you get infected, you are completely under the control of the botmaster. He can put whatever he wants on your machine, and there's no way to be 100 percent sure that the machine is clean. The only way to be [completely] sure the system is malware-free is to completely wipe the hard drive and reinstall the operating system.'"
"The only way to be [completely] sure the system is malware-free is to completely wipe the hard drive and reinstall the operating system.'""
Trusted Computing to the rescue!
My house was robbed once... even with fully locked doors, up to date alarm company subscription, and a dog. For peace of mind, I decided blowing up the house was the best option. I've since moved to the woods and have been civilization free.
I can see it now: In the future there will only be one botnet, then the entire hacking community will just be a big game of RootThisBox (http://rootthisbox.org/) (hmm...RTBs website seems to be redirecting to HackThisSite for some reason).
Anyone else think the comments just weren't rendering right before they turned off ABP and saw ads?
"Until someone creates something that can infect the various *nixes that is."
That's impossible. How do I know. Just "Ask Slashdot".
Until someone creates something that can infect the various *nixes that is. Or an asteroid destroys Earth.
"The only way to be [completely] sure the system is malware-free is to completely wipe the hard drive and reinstall the operating system."
I say we take off and nuke 'em all from orbit. It's the only way to be sure.
Any sect, cult, or religion will legislate its creed into law if it acquires the political power to do so.
I do not believe in karma. "Funny"=-6. Do good and forbid evil. Yours, Oft-Offtopic Flamebaiting Troll.
My house was robbed once...
It was one of those cheap houses, you know using old materials and not the best contractors (the doors and windows would not always close properly.)
even with fully locked doors, up to date alarm company subscription, and a dog.
Though that brand of locks use one of five common keys, and the alarm company sometimes works with other companies to let marketers in, and the dog, as vigient as he is is just a dog and frankly pretty stupid.
For peace of mind, I decided blowing up the house was the best option. I've since moved to the woods and have been civilization free.
Actually it was more like a posh wooded suburb gated-community thing, where all the prices are higher and the selection is more limited, but the cars are to die for. I don't even assoiate with my old neighbors much anymore. My kids ands wife are much more happier and I have a lot less stress about stuff like that.
Now if it were Linux, you would probably be in the woods, in some commune, inside an abandoned high security military bunker, whith a lot of really smart people that don't socialize all that well.
"Enjoy what you're doing! If it becomes drudgery, you're doing it wrong!" - Jim Butterfield
My house was robbed once... even with fully locked doors, up to date alarm company subscription, and a dog.
You probably had Windows...
Fixed that for you.
"I've got more toys than Teruhisa Kitahara."
You are a pseudo-geek with a handful of windoze skills who has no idea how much he doesn't know. Congratulations on writing some crappy .bat script, you are officially eligible to work in the tech support department at Best Buy.
Sacrilege! Sacrilege, you Windows fanboi!!!! How dare you criticize the Holy Penguin!!!!!!!!!!
"I don't know, therefore Aliens" Wafflebox1
Of course, since he effectively broke a digital access control (reverse-engineering "trivial" encryption) and then ran the program in ways that the author did not explicitly permit (in a sandnet) then he's a criminal as bad as DMCA Jon.
AC