Slashdot Mirror


Exposing Bots In Big Companies

CalicoPenny let us know about yet another "30 days" effort, this one to name the names of major companies infected with spam-spewing bots. Support Intelligence began the effort on March 28, out of frustration at not being able to attract the attention of anyone who could fix the problems at these companies. While they haven't named 30 companies over the ensuing month, they did name some prominent ones, such as Thompson Financial, Bank of America, and AIG. The scary part is that if a bot can spam it can capture keystrokes or troll for interesting documents.

113 comments

  1. Really? by baldass_newbie · · Score: 5, Funny

    The scary part is that if a bot can spam it can capture keystrokes or troll for interesting documents.


    Or troll slashdot.

    --
    The opposite of progress is congress
    1. Re:Really? by Meadowhog · · Score: 1

      I'm impressed by the effort that went into this troll.
      --
      CashCrate: Earn money for filling out surveys/forms, real info not required

    2. Re:Really? by no1nose · · Score: 1

      Where the hell are my mod points?!

  2. Aflac by Anonymous Coward · · Score: 0

    AFLAC!

    1. Re:Aflac by Archangel+Michael · · Score: 1

      Ben or Casey?

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
  3. Gives a whole new meaning by overshoot · · Score: 4, Funny

    to "kicking bot and posting names."

    --
    Lacking <sarcasm> tags, /. substitutes moderation as "Troll."
    1. Re:Gives a whole new meaning by heinousjay · · Score: 5, Funny

      Why attack conjunctions, man?

      --
      Slashdot - where whining about luck is the new way to make the world you want.
    2. Re:Gives a whole new meaning by svallarian · · Score: 1

      obviously a school-house rock hater.

      --
      I patented screwing your mom. But it got revoked for "prior art."
    3. Re:Gives a whole new meaning by dblanchard · · Score: 1

      Blakey Rat, you must be thinking of "kicking butt and taking names." Since you're keeping score.

      D

  4. Not surprising... by Penguinisto · · Score: 4, Interesting
    Big company == shedloads of workstations with shedloads of not-too-intelligent computer users.

    Aside from IT efforts to clean up (or at least keep their heads above water), the percentages would likely compare favorably with the home user population at large, methinks. Sometimes (like ferinstance the company I work for) can be outright anal about security (custom images, email that's filtered nine ways from Sunday, etc), and yet about once a month scans will pop up someone who has been bit with the latest variant of (insert malware here). To their credit, the guys here remove it often within minutes of detection- never seen one last more than a couple of hours. (not just saying that because I happen to be a sysadmin there, seriously... the user-end guys are anal about that sort of thing, and if they weren't the network guys would happily shut off the offending port @ the switch to get the user's attention).

    /P

    --
    Quo usque tandem abutere, Nimbus, patientia nostra?
    1. Re:Not surprising... by pe1chl · · Score: 2, Interesting

      In a properly administered network, the office users do not have administrator access to their workstation, and the PC cannot connect to random addresses on the Internet on port 25.
      So, the systems do not get easily infected and when they do, they cannot spam the outside world.

      But of course, there are too many users that think they need admin access (and worse: need it all the time). And the worst of those are the programmers. They think they need admin access and fail to test their products under a lesser-privileged account.

    2. Re:Not surprising... by Anonymous Coward · · Score: 1, Informative

      Admin access on a PC and getting out to the internet on port 25 are two completely different things.
      It comes down to a model of seperation and trust and applying policies at the proper place, not trust as in trust the users but trust the workstations and what is plugged into your network. Spyware, bots, viruses etc are the reason you should never trust a computer on the network, it does not matter whether you trust the user of that computer or not. The network engineer or a developer does not need port 25 outgoing either, if there is a time when it is needed for testing or troubleshooting, provide a specific machine to that user or unblock port 25 for an hour or so. If you are creating an application that interfaces with mail and you need outgoing port 25 all the time, provide one workstation that ability. Basically, at the network level, you give various computers the bare minimum access they need to the outside and this should be the standard practive across the board. If it is not, your company will need to seek outside consultants to help pull your head out of your ass. If the companies IT management is weak and can not get through to the decision makers, make sure your concerns about security are noted and sit back and wait for the shit to hit the fan. If the IT management is weak and does not bring up a security plan to the decision makers, enjoy the ride while it lasts and sit back and wait to be fired.

  5. Re:I hate overlord posters.... by Anonymous Coward · · Score: 0

    I for one welcome our overlord poster hating overlords

  6. I know what you're thinking. by Anonymous Coward · · Score: 0

    But I know this guy. An without being graphic or verbose let me see if I can paint a picture. In a word, "Blowback" It's something to see. They play his videos on public access tv in berlin.

  7. Send in the lawyers by secolactico · · Score: 5, Interesting

    How long before some company tries to cover up the embarrassment by suing the people who disclose the fact that they have machines infected with bots? They might not succeed, but they might make life unpleasant for a short while for those who post the info.

    --
    No sig
    1. Re:Send in the lawyers by abb3w · · Score: 1

      How long before some company tries to cover up the embarrassment by suing the people who disclose the fact that they have machines infected with bots? They might not succeed, but they might make life unpleasant for a short while for those who post the info.

      Probably a little while, since it would be monumentally stupid. The obvious first step for the sued is talk to a lawyer (IAmNotALawyer). Then, have their lawyer to get a judge to order preservation of the current system state on each of the suspected machines for third party forensic analysis, and incidentally subpoena all of their logs — a serious counter-hassle for the users at fault. Depositions from anyone who used the computer or was responsible for its maintenance would probably be obvious early requests in the disclosure part of the case.

      Sarbanes-Oxley makes for some nasty requirements on IT security reporting. By threatening to sue the person disclosing, they give a third party reasonable grounds for subpoena of evidence (such as I mention) that may later be admissible for future criminial and civil charges against the company and its officers... and providing the third party motive to pass the evidence along to Federal regulators. Any company lawyer starting such a lawsuit should be fired for stupidity and disbarred for vexatious litigation, although the latter is likely to take longer.
      --
      //Information does not want to be free; it wants to breed.
  8. Who works for IT divisions in big companies? by AB3A · · Score: 3, Insightful

    Answer: they're usually the height of mediocrity. The best and brightest, if they're there, are often ignored.

    The notion that lots of big companies have spam bots all over the place is not all that hard for me to believe. Their IT divisions are often poorly staffed with folks who were selected with more input from HR than from the actual manager. They look at the certificates and then decide if a person is OK for the job. Honestly, the certificates are not a good gatekeepers to ensure that people without a clue don't find themselves on the front line. They can't be.

    We all have known people who were extremely good at passing tests, but for reasons unknown to the rest of us, are unable to use those very skills in a real application. Those are the people who all too frequently end up in big organizations, pretending to know what real IT is. There is no substitute for learning from experience.

    And these corporations are about to have one of those learning experiences. It won't be pleasant.

    --
    Nearly fifty percent of all graduates come from the bottom half of the class!
    1. Re:Who works for IT divisions in big companies? by Penguinisto · · Score: 2, Interesting
      Depends on how its structured and where exactly you're at within the company.

      The folks I work for has roughly 100,000+ employees, but as the sysadmin for one of the R&D labs, I'm given some very wide latitude. In exchange, I have to be a lot more flexible on lots of aspects than the guys who keep the production servers/network/etc going. IT's a trade-off, but one that I truly enjoy.

      I can't hide behind policy to keep my schedule sane as a downside, in spite of working for a company whose production IT policies practically straddle the phrase "anal retentive". Then again, if I want to switch from one tech/protocol/etc to something else, as long as it doesn't disturb the developers and engineers, I'm free to do it (within reason, naturally - e.g. if it plugs into the corp network, it adheres to corp standards as seen from those interfaces, etc).

      Even in the biggest, most soulless corporations, you can sometimes find yourself a place in it that not only lets you thrive, but a place where you are encouraged to.

      /P

      --
      Quo usque tandem abutere, Nimbus, patientia nostra?
    2. Re:Who works for IT divisions in big companies? by Anonymous Coward · · Score: 1, Interesting

      I think parent keeps getting knocked back when s/he applies to big companies because s/he has no formal training.

    3. Re:Who works for IT divisions in big companies? by bberens · · Score: 1

      No offense, but simply because you're allowed to thrive doesn't mean you have the foggiest idea what you're doing with respect to keeping your machines clean.

      --
      Check out my lame java blog at www.javachopshop.com
    4. Re:Who works for IT divisions in big companies? by Penguinisto · · Score: 1

      No offense, but simply because you're allowed to thrive doesn't mean you have the foggiest idea what you're doing with respect to keeping your machines clean.

      None taken - my own evaluation of proficiency is judged by the results of my work as audited on a periodic semi-random basis. Because of the nature of my specific duties, I cannot simply hand off localized email filtering duties to "the email guys", hand off local IOS patching and vigilance to "the network guys", the Oracle and MySQL patches to "the DB guys", and etc. In fact, if anything goes splat in the lab security-wise and spreads to the corp network? I daresay that I'm more responsible for the results than the average schlep who could simply (and credibly so) shift the blame to "the network guy", or the "desktop support guy", or "...". If/when it falls on my head, I had better be prepared to prove that I showed due diligence before, during, and after.

      Maybe that's what gives your theory of 'incompetence == corporate position material' an anchor... that with such specialization and little direct responsibility (aside from the most bleeding obvious of blunders), it is drop-easy for someone in a big company to credibly shift blame when in truth it should rightly fall in his lap. Couple this with the subtle and often chain-reaction-like nature of malware and other types of compromise, and *poof* - there you go.

      It then gets boiled down to a pass-the-blame game consisting of: "the email filters should've been updated", "No, the firewall should've stopped it outbound", "No - the workstations should've been patched!"... Typical corporate culture prevents anyone from daring to say "I fucked up..."

      /P

      --
      Quo usque tandem abutere, Nimbus, patientia nostra?
    5. Re:Who works for IT divisions in big companies? by DynaSoar · · Score: 2, Insightful

      > Answer: they're usually the height of mediocrity. The best and brightest,
      > if they're there, are often ignored.

      IT at big companies are kept busy just trying to keep the base OS and necessary apps puttering along, and resurrecting users' workstations that have melted down or upchucked. Their mediocrity is enforced by the needs and whims of the big suits and PHBs. Corporate budgeting for IT is on a need-to-go basis. If IT has any money left at the end of a fiscal year, rather than letting them put it to security and be good neighbors on the net, corporate bosses tend to do the corporate thing: take the money and put it towards TV commercials saying what good neighbors they are. The job is mostly never-ending thanklessness punctuated by blame. The best and the brightest are usually not given the time or resources to be that. If they try, they end up pointing out flaws for which their cohorts are either responsible for creating or at least for fixing. In corporate IT, as in Japan, "the nail that sticks out gets pounded down". I've watched several freinds and acquaintances go from being very good at IT to being either disillusioned and bitter medicore IT drones, or giving the appearance to be that at work and saving their expertise for their own projects. Those are often unpaying, but at least they get due thanks and/or a sense of accomplishment.

      --
      "I may be synthetic, but I'm not stupid." -- Bishop 341-B
    6. Re:Who works for IT divisions in big companies? by AB3A · · Score: 2, Insightful

      Actually, I have lots of certificates. I have formal training. The thing is, I was technically proficient BEFORE I got those certificates. The certificates were simply a means to prove to my PHBB and the HR weenies that I really am worthy of the salary I have. Being relatively honest about such things, I don't usually bother to get certified for something unless I'm serious about using that certification. I'm not a certificate collector. My career is not some merit badge collection from the Boy Scouts. However, the way they write job descriptions these days, one is often reduced to collecting a mess of badges for this, for that, and for other stuff...

      The reason I have this attitude is because I know many others who also have these certificates. Their capabilities range from extraordinarily adept, to blithering idiot. The certificate may indicate exposure to knowledge, but the application of that knowlege is an entirely different thing. That's what separates the pretenders from those who really do know and care. In large organizations, the only thing they can show is evidence of training. Sadly, there is a very wide gulf between that and someone who really performs well on the job. And that gap is not easily measured in any way. That's why large organizations have such strong tendencies toward mediocrity.

      --
      Nearly fifty percent of all graduates come from the bottom half of the class!
    7. Re:Who works for IT divisions in big companies? by azrider · · Score: 1

      Because of the nature of my specific duties, I cannot simply hand off localized email filtering duties to "the email guys", hand off local IOS patching and vigilance to "the network guys", the Oracle and MySQL patches to "the DB guys", and etc
      Hear, Hear!! When I worked as a sysadm in classified labs, it was my job to keep the network and its attached systems secure. While the company I worked for had a network group, they were only allowed to make changes that my team approved. This meant that we (I) had to keep up with what was going on. You slip up in these situations and, worse case, you jeopardize your security clearance.

      It then gets boiled down to a pass-the-blame game consisting of: "the email filters should've been updated", "No, the firewall should've stopped it outbound", "No - the workstations should've been patched!"... Typical corporate culture prevents anyone from daring to say "I fucked up..."
      Wouldn't it be nice to see that statement (or PC variants) come out on a more or less regular basis? The current "In retrospect, we may have made a mistake..." kind of leaves a strange taste in one's mouth :)
      --
      And ye shall know the truth, and the truth shall make you free.
      John 8:32(King James Version)
    8. Re:Who works for IT divisions in big companies? by drew · · Score: 1

      Even without any of the best and brightest, it should take about ten brain cells and a half hour's work to disable outbound port 25 traffic from your corporate network (minus the mail server, if you're not bright enough to put it on a seoarate network), and no legitimate use would ever know the difference.

      --
      If I don't put anything here, will anyone recognize me anymore?
  9. Ya know... by FlyByPC · · Score: 4, Insightful

    ...along with the deinfestation, a little education might go a long way. If employees could be paid to attend a (mandatory) presentation on just how a botnet gets set up, I bet this would reduce the instances of infections by an appreciable amount. (Yeah, not 100%, I know.)

    Make it interesting. Start out asking for people's opinions on spam. Get 'em good and worked up. Then set up some network monitor with a nice, easy-to-see graphic interface (maybe write one) and demonstrate how a workstation gets infected by the user running a compromised app. Once it takes hold (pick a good one), pull out the stopwatch, tick off 5-10 seconds, then show how many mails it sent. Then do the math; multiply those ten seconds by 6 to get minutes, then 60, to get hours, then 24. I bet even the math-challenged will get the point quickly, looking at those really large numbers.

    --
    Paleotechnologist and connoisseur of pretty shiny things.
    1. Re:Ya know... by StikyPad · · Score: 5, Funny

      Then do the math.

      Then, to ensure you reach 100% of your target audience, convert the presentation to an animated .gif and e-mail it to everyone on your contact list, instructing them to do the same.

    2. Re:Ya know... by dunezone · · Score: 2

      I think you really need to add some consequences to the situation for them to really understand. Unfortunately, the IT department and upper management has to be competent enough to understand when the employee was in at fault or they were at fault or it will just be finger pointing game to the easiest target.

    3. Re:Ya know... by bl8n8r · · Score: 1

      That's a noble idea, but unfortunately I think most people don't really care. Ever see that glassed-over look just explaining how pop3 works (even when they ask)? "What I do is click this and then that window pops up with the blahblahblah but it's not working. And my internet is slow." Not saying people are stupid, most are just not interested and don't feel they have to be. I'd say the malware is succesful due in a large part to widespread apathy. Technical issues are second.

      --
      boycott slashdot February 10th - 17th check out: altSlashdot.org
  10. Class Action risk for using Microsoft's Products by NZheretic · · Score: 1, Interesting
    In comparison to MacOSX or Linux based desktop, Microsoft's desktop operating systems and Microsoft's desktop applications face a disproportionally higher risk of being "infected" with hostile malware. Just relying on third party Antivirus software to prop up a Microsoft flagging security record in no way puts you any closer to the level of security that a switch to another vendors desktop platform can provide. ( Just updating to Vista is no guarantee of better security in comparison to another vendors platform )

    Maybe it is time some people who have been spammed or have had personal sensitive data exposed from infected Windows desktops in these organizations to enter into a series of class action lawsuits against those same organizations for using Microsoft's products. If switching to Linux or MacOSX based desktops would greatly reduce the risk of further intrusion why should not organizations be "encouraged" to make the move.

  11. Shouldn't be too hard? by hklingon · · Score: 4, Interesting

    It scares me just how prevalent this type of software is.. not just the spam bots but the malware and other stuff meant to steal data. Locating+shutting down spambots is the easiest task. I'm pretty small time but I found something interesting once while working with a new client to get them fixed up with antivirus and internet monitoring software (squid+sarg). I'd locked down some things and I kept noticing one PC trying to connect to yahoo every week at about 2:00 am. Long story short it was apparently attempting to email a 500kb attachment... that was apparently a log of everything typed in the week before and some other stuff. That *almost* went unnoticed. That type of infection is downright scary.... who is going to notice a 500kb email going out through an https connection at yahoo? It didn't even seem to be part of a command+control network... just gathering info??


    The spambot infections is just the most visible symptom of a larger problem... they're talking about some "big name" companies apparently, but it is the smaller and medium sized businesses that really make the world tick... it is simply too complex, challenging and costly to really secure windows boxes without severely compromising functionality. It is also apparently not something that lends itself well to automation... I see big companies using enterprise software to "lock down" workstations and "reset" workstation images as their solution but there isn't really a small business answer here that I know of. If the tools were better/easier to use it might be easier to keep an eye on one's "flock" but it is a horrible pain both in setup and upkeep to really anticipate what might be happening. The entire stack one could use in windows to manage this stuff, from Event Logging to vb scripting automation, and all the way up to group policy is half-assed at best. This is the type of result you can expect.


    this type of story is why I think that learning and/or heuristic scanners (both at the machine and router/firewall/proxy level) are pretty much the only way we can win. I'm not imagining something sentient, mind you, just something that will sift through all the event logs and point me toward things actually worth my attention instead of "every little thing".



    1. Re:Shouldn't be too hard? by Turn-X+Alphonse · · Score: 1

      But then wouldn't the spammers aim under the bar of "important"? I mean sure 3 million e-mails a second is annoying but what if they cut it down to 1 a minute? Lets say you have 500 zombies, that is still a lot of spam and we know 500 is a drop in the ocean compared to what these guys have.

      --
      I like muppets.
  12. No difference between the bot and Windows by SpaceLifeForm · · Score: 0, Troll

    Seriously, there is no difference.

    Instead of suing those who disclose the fact
    that machines on their lan are infected,
    they should sue Microsoft for allowing it.

    You don't know that Windows is not doing the
    same nasty spyware tricks that people accuse
    the bots of doing.

    Oh, that's right, there is a difference.

    The Microsoft EULA covers their ass, whereas
    the bot does not ask you for permission to spy.

    --
    You are being MICROattacked, from various angles, in a SOFT manner.
    1. Re:No difference between the bot and Windows by thogard · · Score: 1

      The only ones who can sue Microsoft are the ones who don't agree to their terms anymore. There are plenty of consumer product protection laws that are clear that Microsoft's failure to recall their buggy software is illegal. Its just going to take someone who wants to be the next the next Ralph Nader to take the case.

      A worm attacked my server through an exploit and M$ took care of my bandwidth bills.

  13. Re:Send in the boomstick by skoaldipper · · Score: 1, Funny

    Since March 28, the list identified more than a dozen corporations, including [...] Bank of America.
    "Army of Botness", to be aired May 2, 2007

    Bill - "Hey, what's going on here?"
    Larry - "Stop giving free checks for life Bill."
    Winston - "And free ATM cash withdrawals!"
    Charles - "Or we let these spam zombies eat our brains!"
    Bankers Pen - "Yeah!"
    Bill - "Whoah! Whoah! Guys. People love all the features of WAMU's spam free online checking."
    Larry - "Horse Pockey! V1a6rA l0ng D0ng che4p$$! Mmm. Braaaaaains..."

    [ Larry, wearing a BOA pin on his collar, begins nibbling on Charles' hairpiece as others join in on the feeding frenzy... ]

    [ Bill repeatedly cocks his Remington as the penguin suits start dropping behind the velvet ropes... ]

    Bill - "Key log this EFT, baby! Groooovy..."
    --
    I hope, when they die, cartoon characters have to answer for their sins.
  14. Why don't they block outgoing smtp traffic? by whoever57 · · Score: 5, Insightful

    Surely, these large companies could block outgoing port 25 traffic, except for their own email servers. Then the traffic can easily be monitored and spam zombies detected.

    Why is this not "best practice"?

    --
    The real "Libtards" are the Libertarians!
    1. Re:Why don't they block outgoing smtp traffic? by Anonymous Coward · · Score: 0

      Seriously, all 99% of workstation users need http(s) & ftp. Giving them more than that is like asking for a soldering iron in the face.

    2. Re:Why don't they block outgoing smtp traffic? by techno-vampire · · Score: 0

      All the bot needs to do is find out what the user's SMTP server is and use that. That way it doesn't care which outbound ports are open and which are blocked.

      --
      Good, inexpensive web hosting
    3. Re:Why don't they block outgoing smtp traffic? by grasshoppa · · Score: 1

      All the bot needs to do is find out what the user's SMTP server is and use that. That way it doesn't care which outbound ports are open and which are blocked.

      But by then we are dealing with a known quantity at a central location. These companies should be blocking everything their users don't need first and foremost, then they can look at the traffic from their mail server and use standard off the shelf pattern analysis to find the spammer bots.

      It's simple security.

      --
      Mod me down with all of your hatred and your journey towards the dark side will be complete!
    4. Re:Why don't they block outgoing smtp traffic? by Mr.+Roadkill · · Score: 2, Insightful

      All the bot needs to do is find out what the user's SMTP server is and use that. That way it doesn't care which outbound ports are open and which are blocked.
      Indeed. But it's still a good idea to block port 25 on business or educational networks unless it's absolutely needed - as it prevents one class of abusers, i.e. direct-to-mx sending malware, making use of that particular method on your network. There still seems to be a lot of direct-to-mx stuff in circulation, if the evidence in our logfiles is anything to go by. I can't think of many normal desktop users who would need unrestricted port 25 access, and anyone trying to tighten up their network in areas where it won't affect legitimate use ought to be applauded.
    5. Re:Why don't they block outgoing smtp traffic? by TheSkyIsPurple · · Score: 1

      I'd love to do this in my org... a large company.

      But our department doesn't have the clout to override the other VPs desire to keep that functionality.

      In fact, I think part of the argument is that we can't respond to their needs quickly enough, partly because we're running around dealing with stuff we wouldn't have to if we were allowed to do things right =-/

    6. Re:Why don't they block outgoing smtp traffic? by techno-vampire · · Score: 1

      I'm not disagreeing with you. What I'm saying is that blocking outbound port 25 isn't going to stop cleverly-written spambots.

      --
      Good, inexpensive web hosting
    7. Re:Why don't they block outgoing smtp traffic? by MsGeek · · Score: 1

      ftp? No way! sftp/ssh2/scp. Sure, it doesn't come installed with Windows. But there are free solutions for that. Port 22, port 80, port 443. That's it. End of story.

      --
      Knowledge is power. Knowledge shared is power multiplied.
    8. Re:Why don't they block outgoing smtp traffic? by init100 · · Score: 2, Interesting

      All the bot needs to do is find out what the user's SMTP server is and use that. That way it doesn't care which outbound ports are open and which are blocked.

      There are ways to block that behaviour. You could use SMTP AUTH to authenticate connections to the SMTP server and SSL/TLS to encrypt the connection. That way the bots won't be able to use the SMTP server to send their spam.

    9. Re:Why don't they block outgoing smtp traffic? by flyingfsck · · Score: 1

      FTP sends user names and passwords in plain text, so this is not recommended. You should look at ssh and sftp instead. On Windoze, about your only option is to use https, since Windoze doesn't have any other security software, unless you install Cygwin and OpenSSH.

      --
      Excuse me, but please get off my Pennisetum Clandestinum, eh!
    10. Re:Why don't they block outgoing smtp traffic? by drew · · Score: 1

      What possible reason could he have for wanting to keep that functionality. It seems to me to be one of the very few security practices that one could implement with a "no exceptions" policy without catching innocent users.

      --
      If I don't put anything here, will anyone recognize me anymore?
    11. Re:Why don't they block outgoing smtp traffic? by TheSkyIsPurple · · Score: 1

      Developers who just want things to work... and they know a server "x" that does what they want.

      When you get an organization large enough to have hundreds of VPs, you also have the other flotsam that comes with them.

  15. Everyone thinks they are better. by Anonymous Coward · · Score: 1, Interesting

    I've been apart of small companies, AT&T and a large utility (heavily regulated).

    Every admin thinks they are better. Every IT guy thinks they KNOW how to run a network. Consider a company, a large one, with BRAZILLIONS of dollars like RIM. They screwed the pooch in a big way. Google did it too w/ their email/homepage disappearings.

    The reality is computers break. I still contract for a large company on a part time basis. The "best and brightest" have jobs that reflect their skills. They design the network, implement processes and "fix" systems that fail. The rest of the company simply resets passwords and updates user info. Not the brightest bunch but they don't need them, there anyway.

  16. This wins the DUH award by toby · · Score: 3, Insightful

    The scary part is that if a bot can spam it can capture keystrokes or troll for interesting documents.

    Uh, yeah, that's why, like, some of us actually run a secure operating system instead of freaking Windows.

    I look forward to the day when proposing a Windows SOE is a firing offence. As for the state of American IT... Aren't you guys supposed to have landed on the moon, way back before Microshit was founded? WHAT HAPPENED TO Y'ALL?

    --
    you had me at #!
    1. Re:This wins the DUH award by Stormie · · Score: 1

      Always a delight to see a 3-digit user ID maintaining the True Spirit of Slashdot.

    2. Re:This wins the DUH award by madsheep · · Score: 1

      I look forward to the day when proposing a Windows SOE is a firing offence. As for the state of American IT... Aren't you guys supposed to have landed on the moon, way back before Microshit was founded? WHAT HAPPENED TO Y'ALL? Well first Microsoft Windows is the most widely used OS in the world. So if "Y'ALL" is referring to the people of the U.S., it looks like we made the most popular OS in the world, which you are probably running. On top of that a large number of the developers of open sources systems are from the U.S. as well. Then of all these "major companies" that are infected (think Fortune 500 or Fortune 100), a large portion [majority?] are U.S. companies. So it doesn't look like a whole lot happened besides a lot of success.
    3. Re:This wins the DUH award by kir · · Score: 3, Insightful

      Yeah... you'd think he'd have grown up by now.

      --
      3cx.org - A truly bad website.
    4. Re:This wins the DUH award by Anonymous Coward · · Score: 0

      Given the comments made by the person you responded to, do you really think that it's probable he's using Windows?

    5. Re:This wins the DUH award by Anonymous Coward · · Score: 0

      ...And given the 3-digit ID of the person you responded to, do you *really* think they have no idea what they're talking about?

  17. Exposing Bots in Big Companies by errxn · · Score: 4, Funny

    Exposing bots in big companies? That's easy. I see 'em every day. We even have a nickname for them here..."Middle Management."

    --
    In Soviet Russia, Chuck Norris will still kick your ass.
    1. Re:Exposing Bots in Big Companies by weighn · · Score: 1
      We even have a nickname for them here..."Middle Management."

      Nah, they're the "dolts".

      Another term people often confuse with "bots" is "bods" who tend to work in HR and Marketing. Unfortunately they also tend to have Middle-Management-like qualities.

      --
      Mongrel News all the news that fits and froths
  18. No way by madsheep · · Score: 2, Insightful

    Major companies infected with spam spewing bots?? No way. This is just to ground breaking to be true. Next thing they are going to tell us is that government machines are also infected. Since we all know that major companies and government machines are impenetrable because their users are so smart, savvy, and technologically secure. Oh wait, the users at these places are the same people that use AOL dial up at home. OK.. so maybe it is true *and* unsurprising. :P

    1. Re:No way by Inverted+Intellect · · Score: 1

      Indeed you are right that this should not be news. Sadly, however, it is to some of these corporations. That's the entire point of the operation.

  19. Re:Class Action risk for using Microsoft's Product by dbIII · · Score: 1
    The real point is malware is currently only MS Windows compatible. Other platforms have other problems but there's no way to compare things and no point pretending it's a contest about what is better. For a variety of reasons it can be a good idea to run MS software, but so long as you avoid the hobby versions intended to be used at home and keep the things isolated and monitored they can work well. Fdisk it from orbit and restore from a known good backup - it's the only way to be sure.

    A lot of the MS Windows advocates I know are in the situation where they have never purchased the software and do not have the ability to make good backups (has anyone ever got a flawless restore back from NTbackup? Ok so I exagerrate, but it has problems and that is all a lot of people use). These people tend to stuff about with flawed spyware removers and registry editors and are sometimes confident that their machine is no longer compromised (um, how do you know - they rooted your machine and could have changed any file?).

  20. Sarbanes-Oxley by thatjavaguy · · Score: 3, Interesting

    This is actually pretty big news.

    My understanding is that Sarbanes-Oxley imposes strict IT standards for public companies.
    If the companies involved are indeed Fortune 500 companies then they are exposing themselves to massive lawsuits.

    In the big company that I work in this couldn't happen: we have good firewalls, machines are locked down in terms of downloads, machines are regularly tested/audited and we have a great IT department.

    If I were a CEO of one of these companies I'd be looking to fire the CIO...

    1. Re:Sarbanes-Oxley by advocate_one · · Score: 1

      If I were a CEO of one of these companies I'd be looking to fire the CIO...

      If I were a shareholder, I'd be asking for the resignation of the CEO... the buck stops with him...

      --
      Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
    2. Re:Sarbanes-Oxley by TooMuchToDo · · Score: 1, Insightful

      In the big company that I work in this couldn't happen: we have good firewalls, machines are locked down in terms of downloads, machines are regularly tested/audited and we have a great IT department.

      Bullshit. If a box is on a network, the possibility of an exploit exists. The only secure desktop/server is the one buried in concrete 6 feet underground.

    3. Re:Sarbanes-Oxley by mattoo · · Score: 2, Funny

      In the big company that I work in this couldn't happen Let's file this under 'famous last words' :)
    4. Re:Sarbanes-Oxley by thatjavaguy · · Score: 1

      OK. Let me rephrase that.

      It is very unlikely to happen on a large scale...

  21. Good to see the word getting out. by twitter · · Score: 2, Insightful

    The Register reported this about a month ago and I'm glad the issue is getting the attention it deserves. Having done some "upgrades" for a major bank and worked at a fortune 500 company, I can say that many supposedly secure corporate networks are owned by spammers. It's a big deal because it's hard to filter out.

    the percentages would likely compare favorably with the home user population at large, methinks.

    You would think that, seeing how much money these companies have to throw into manpower and software, but it's not always so. I'd really like to know what kind of Voodoo the few successful companies are employing.

    Sometimes (like ferinstance the company I work for) can be outright anal about security (custom images, email that's filtered nine ways from Sunday, etc

    At some companies, this is no more than an inconvenience to the user. Just think about companies that ban cell phones with cameras while allowing actual cameras. The dumber the company, the less effective and more annoying their "security" measures will be.

    The problem with a bot net infection at a major company is filtering the email downstream. What ISP is going to blacklist Bank of America IP address? ISP's have to take and filter each and every mail from major companies or risk shafting mail from a real mail server they don't know about in the same IP range. By contrast, mail from home PCs gets little to no respect. ISPs feel free to reject, block and limit it all at the same time, so the home user can only send some piddling number of mails each day and only through the ISP's smtp. The botnet people can and do compensate for this by owning more machines but corporate networks are much better for them.

    The root cause, of course, is M$'s easy to abuse desktop.

    --

    Friends don't help friends install M$ junk.

    1. Re:Good to see the word getting out. by ewieling · · Score: 1

      I'd work on getting the bots shutdown, but I can't seem to find any information in actually FINDING the damn things. We don't have the budget hire a full time person to handle infected machines. If we could find the machines then we might be able to do something about them. As it is we filter out all outgoing SMTP.

      --
      I really shouldn't have used someone else's email address for this account.
    2. Re:Good to see the word getting out. by Deagol · · Score: 2, Informative

      Just log all internal IPs trying to hit external IPs on port 25 (except your mail servers, of course). That's pretty much it. If it's an NT domain, you can search the authentication logs for the IP to get a pretty good idea of who sits at the machine. Proceed accordingly. Don't fart around with disinfecting -- wipe, reinstall, and lock down.

    3. Re:Good to see the word getting out. by Anonymous Coward · · Score: 0

      Speaking for my Fortune 50, we have a very simple solution. Default route goes through an authenticated proxy firewall. Only allowed services are 80/443, and authentication is required. It's a true proxy, so you can't just telnet on port 80 to your home computer.

      The beautiful thing about it, is it's trivial to find misconfigured machines, and spyware. If something tries to connect straight out to the internet, it means it's not setup to use the proxy, and is either a workstation the user installed/configured themselves (users are NOT admins on corporate boxes), or spyware.

      We'll probably get owned eventually by someone writing a bot that looks for proxy configuration, and then sniffs the user's credentials to reuse themselves, but so far everything we've seen is the same shitty bots, which get trapped internally.

  22. Bank of America by omeomi · · Score: 2, Interesting

    Thompson Financial, Bank of America, and AIG.

    So you mean that some of those Bank of America SPAMs are actually coming from Bank of America computers? Woh...

  23. What, like the broadband ISP's do? by twitter · · Score: 0, Troll

    Surely, these large companies could block outgoing port 25 traffic, except for their own email servers. Then the traffic can easily be monitored and spam zombies detected.

    Surely, the bot net operators have already gotten around that on cable networks and those companies that do this. All they have to do is make the bot mail through the company smtp.

    Your idea is a variation on the "blame the user" theme. The problem is M$ on the desktop. Big dumb companies fork over all sorts of money, do what they are told and get slammed anyway. What will be funny is when M$ themselves end up on this list. Who will they blame then?

    --

    Friends don't help friends install M$ junk.

    1. Re:What, like the broadband ISP's do? by Anonymous Coward · · Score: 0

      I'd imagine many of these large companies actually use IMAP servers or even Notes mail servers and not standard Pop and smtp servers. Even if they do it shouldn't be too hard to have some basic spam throttling applies to 90+% of the users to limit external emails to some reasonable rate that the spambots are likely to pass. It also shouldn't be too hard to spot a steady stream of emails going out at unlikely times. Once again probably 90+% of most companies is home by 8:00 or 9:00 at the latest.

      I'm not suprised that large companies with large numbers of pcs had some pcs that got infected with crap. I am surprised that either their networks were open enough that the machines could spam or that some of the limited machines that were not locked down got infected, eg servers.

    2. Re:What, like the broadband ISP's do? by grasshoppa · · Score: 1

      The problem is M$ on the desktop. Big dumb companies fork over all sorts of money, do what they are told and get slammed anyway. What will be funny is when M$ themselves end up on this list. Who will they blame then?

      How to think like a manager 101: You are presented with two answers to a single problem. One; is to "task" the network/email admins to fix a problem. Two; involves blaming a large vendor. One of these answers actually lets you accomplish something, while the other doesn't. Which do you choose?

      --
      Mod me down with all of your hatred and your journey towards the dark side will be complete!
    3. Re:What, like the broadband ISP's do? by igb · · Score: 1

      Surely, the bot net operators have already gotten around that on cable networks and those companies that do this. All they have to do is make the bot mail through the company smtp.
      It means you have logs, however. And company mail servers can be run in a far more ``shoot first, ask questions afterwards'' mode because there are far fewer reasons for `abnormal' traffic: for example, a user sending high volumes of messages has fewer legitimate reasns.

      I run the whole internal network on RFC1918, with access in an out via proxy servers. The handful, and it is a handful, of machines that need untrammeled access to the Internet get put on a distinct VLAN with extensive IDS. This isn't fool-proof: one could imagine a bot that uses CONNECT to the http proxy to build a control channel and then spams out through the main mail servers. But once spotted, I'd have extensive logs to see what had happened. If it became prevalent, I'd run spam assassin outbound as well as inbound.

      ian

    4. Re:What, like the broadband ISP's do? by BVis · · Score: 1

      How to think like a manager 101: You are presented with two answers to a single problem. One; is to "task" the network/email admins to fix a problem. Two; involves blaming a large vendor. One of these answers actually lets you accomplish something, while the other doesn't. Which do you choose?
      Two. One requires work from your own people (who no doubt already have enough work for three people each), while the other involves forcing a big vendor to try to do something. If they don't, your ass is covered, since you can't control them. If you try to get your own people to do it, and they're not able to acceptably (on time/under budget), then you look bad.

      Management can be a logic-free zone sometimes. Too many companies are run by people who care more about the appearance of competence and efficiency than things actually getting fixed, and any manager that wishes to keep his/her job will play the game, even if it means things don't get fixed.
      --
      Never underestimate the power of stupid people in large groups.
  24. IT jitters by HW_Hack · · Score: 2, Insightful

    The school district I work for is about 80% macs and 20% PCs (running XP) - total number of machines disctrict wide is about 6000. I've asked if I could set up a Linux server and some diskless work stations as a usage test case ... by the response you would think I asked to install an open wireless node in the schools cafeteria. On the other hand if I'd just announced that I'd just installed 35 PCs that would be no problem and everyone would assume they're up to date + antivirus + etc.

    I could lock down that Linux box pretty tight etc. but Linux is not on their radar

    --
    Its not the years, its the mileage .....
  25. exposing == alienating potential clients? by Gary+W.+Longsine · · Score: 4, Interesting
    My company, Intrinsic Security generates as an artifact of product testing a certain amount of data about botnet and worm infestations on company and government networks. I have always tought that these kinds of public exposures would scare off clients, not only the companies named, but many other companies that would lose respect for a security company publically shaming potential clients. I definitely understand the frustation mentioned in the summary, as many people in IT consider themselves to be malware experts and they always think they have "solved" the "problem" by applying the latest antivirus definitions or tweaking their IDS rules. Most IT managers don't seem to really quite understand that the typical malware today is a radically different threat than they were five years ago. Keystroke logging is routine now, a drop-in module for malware authors.

    Am I wrong? Should I publish the list of companies that I know had bots on their networks in March?
    • 174 private corporations and government agencies
    • 48 schools & universities
    • 118 telecom companies (these are partly home DSL / cable modem circuits, partly private companies where the ARIN records are not delegated but rather managed by the ISP)
    --
    If you mod me down, I shall become more powerful than you could possibly imagine.
    1. Re:exposing == alienating potential clients? by Lord+Lemur · · Score: 1

      Yes. These companies aren't just exposing their information. These companies are exposing your families information.

      If you work your cards right, you could make them seem valiant for announcing such information, and attempting to resolve it.

      Or you might get canned.

      most likely canned.

      -Lemur

    2. Re:exposing == alienating potential clients? by InvisiBill · · Score: 2, Insightful

      For the last year Waters and Support Intelligence CEO Rick Wesson called companies they found spamming, Waters says. But in big companies they had trouble connecting with people who had authority to clean up the networks. Waters thinks corporate upper management--CIO level and above--still don't appreciate the dangers of bots. "We'd talk to mid-level security people who understood botnets but had no buy-in from the CIO," he says. "Or the CEO had never heard about it."

      So they decided after "much soul searching" to name offending companies. Their goal is to clean up the Internet, not embarrass people or make money, although Support Intelligence has gained some new business. But most companies are grateful to be told they have a problem, Waters says.

      This public disclosure is a last ditch attempt to get someone to do something. They've tried to report the problem, but sometimes nothing will get done until someone with letters after their name sees the company's name in the headlines (where customers can see it and income is affected).

      Are you in the same situation with your list?

    3. Re:exposing == alienating potential clients? by Maximum+Prophet · · Score: 1

      ..., but many other companies that would lose respect for a security company publically shaming potential clients.
      Let's do a thought experiment. For each of these "potential clients", estimate the potenitial that they might realistically become your client within a reasonable timeframe given your current advertising budget. Then estimate the percent of these potential clients that would have hired you, that won't. Compare that to the number of potential clients that don't even know your name, that might hire you after you embarass them in public.

      If a company is really your "potential client", that means you know the name of a decision maker that can spend the money to buy your product. If there's a problem with the company spewing spam, you can just call that decision maker for a polite, non-sales chat, and problem solved. This was not the case in this article. These people didn't have the ear of any decision makers in these companies, and thus couldn't get anything done.

      Remember, the best way to make sales, is to establish a non-sales relationship beforehand, person-to-person with a decision maker in the target company. Then when it's time to do business, that decision maker will do business with your company 9 times out of 10.
      --
      All ideas^H^H^H^H^Hprocesses in this post are Patent Pending. (as well as the process of patenting all postings)
  26. Re:Class Action risk for using Microsoft's Product by Reverend99 · · Score: 0

    Oh what a fucking idiotic statement. Ok. The world switches to Linux. You think the malware creators are going to just fall off the face of the earth or continue developing for Windows? You think that if an exploit is found in Linux, and even if it is corrected in 24 hours that a company with 100,000 desktops is going to apply that fix immediately?

    Fantasy is that way--->

  27. I misunderstood... by cliveholloway · · Score: 1

    I thought the article was about stuff like this.

    --
    -- Trinity in high heels carrying a whip: The donimatrix - there is no spoonerism
  28. Re:Class Action risk for using Microsoft's Product by techno-vampire · · Score: 3, Informative

    Some Linux distros have automatic online updating. Unlike Microsoft, they put out updates as soon as they have them instead of waiting for a monthly cycle. I remember one afternoon my system downloaded about a dozen updates, then, just after the updater finished, it checked again and found four more. If your company is using one of those distros, those 100,000 desktops will patch themselves within a few hours after it becomes available.

    --
    Good, inexpensive web hosting
  29. Compared to government agencies by pedestrian+crossing · · Score: 4, Insightful

    I think it is interesting that we see "report cards" that give government agencies low grades on security, but publicly-owned corporations get a pass.

    I seriously doubt that there are any botnets like this running on, say, the DoD network, yet they get a poor grade on security, while a frigging -bank- is pwned, and nobody is too bothered.

    --
    A house divided against itself cannot stand.
    1. Re:Compared to government agencies by Anonymous Coward · · Score: 0

      Maybe because we don't give a crap about somebody else's money, but we're all a little bit worried about the agency with the nuclear bombs?

    2. Re:Compared to government agencies by Anonymous Coward · · Score: 0

      So Sarbanes-Oxley is just window dressing? Sounds like there needs to be some enforcement...

    3. Re:Compared to government agencies by jc42 · · Score: 3, Insightful

      I think it is interesting that we see "report cards" that give government agencies low grades on security, but publicly-owned corporations get a pass.

      I'd suspect that this is mostly because info about government security problems is often available, while corporations (public or private) are generally very secretive about such problems. Journalists have a tendency to report news when they have information, and not report when they don't have information. People conclude that there are problems in government agencies, but not in corporations. But the correct conclusion is usually "We don't know whether the corporate world has these problems, because we can't get information from them."

      Maybe a better approach would be to surmise that, if an organization of any sort is hiding information, this means that it has something going on that it doesn't want us to know.

      (Applying this to the Bush Administration rapidly leads to a high degree of suspicion. ;-)

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    4. Re:Compared to government agencies by businessnerd · · Score: 1

      In regards to Bank of America, they didn't get hit as bad as the summary implies. If you look at the description for the Bank of America "botnet", you'll find that it wasn't exactly a botnet. One machine popped up spewing some spam and it was shut down pretty quickly. Another server popped up about a week later and that one was shut down in a few hours. I wouldn't exactly call that pwnage. Even still, it is scary that anything like that is happening at a bank. Fortunately, it seems the admins over at BoA are more or less on top of things.

      --
      "It's not whether you win or lose, it's how drunk you get." -- H. J. Simpson
  30. Would prefer outing spam buyers by mattr · · Score: 2, Interesting

    I would be far more interested in a list of companies buying spam and profiting from spam. Names, addresses, phone/fax/email. Having reported this stuff and been hit once recently myself and not recovered from it yet, that is the only thing I want to see now. Get those blasted bankers, insurance and real estate agents into some concrete confinement!

    1. Re:Would prefer outing spam buyers by mattr · · Score: 1

      Incidentally the crackers who ruined my server were trying to run a Bank of America phishing scam. Is there something about BoA that makes them an easy target? I can guess all sorts of lousy things but I'd like to know if anyone has real info.

  31. Canary by pedestrian+crossing · · Score: 4, Insightful

    What I'm saying is that blocking outbound port 25 isn't going to stop cleverly-written spambots.

    Absolutely. But -if you are monitoring your FW logs-, you will see the not so cleverly-written ones, and they can be your "canary in the coalmine". If you are seeing any denied outbound attempts, you know that either someone (or some software) is going against policy, or you have a workstation weakness that is being exploited, and you follow up on it.

    Sure, this doesn't guarantee that you don't have a problem (ie., cleverly-written malware). You must take a layered approach to security strategy to be effective. Discounting a layer because it doesn't take every single possibility into account is ridiculous. That's why you have depth built into your security strategy, because no single layer works for everything.

    That is the problem with most "security solutions" that are being peddled to CIOs, they claim to be a single magic bullet when real security solutions are more about correlation and follow-up from different layers. Not sexy, but very effective.

    --
    A house divided against itself cannot stand.
  32. Re:Class Action risk for using Microsoft's Product by ozbon · · Score: 1

    "Fdisk it from orbit and restore from a known good backup - it's the only way to be sure."

    Brilliant! I may have to change my sig...

    --
    I say we take off and nuke it from orbit. It's the only way to be sure...
  33. Re:Class Action risk for using Microsoft's Product by Greventls · · Score: 2, Insightful

    There is still a week or more of a delay to test the patches. If the security patch is a major overall, it could take months. Where I work didn't upgrade from Windows 2000 until last year. We still haven't installed IE7. There is a week to 2 week delay between MS releasing a patch and it getting deployed. Programmers need to test their systems to make sure the patch doesn't blow anything up. I can't see any corporation relying on Linux's automatic updates and just keeping it at that.

  34. Re:Class Action risk for using Microsoft's Product by thogard · · Score: 1

    A windows botnet can cost as little as $.10 a host. A Solaris botnet can be worth hundreds of dollars per machine because the compromised systems are tend to be better connected and if the initial controller hasn't woken up the sysadmin, there is a good chance the machine might have a good long run. I expect that an os x botnet will be worth several dollars per machines since mac users are more likely to have fast unlimited broadband than your average window users. Linux users are harder to fit into the demographic slots but they are just as likely to have a machine on a 100 meg connection as a dailup connection. Since there is more money in hacking the other systems and less competition, why aren't more of them attacked?

  35. I blame yahoo/freehosting companies by cheekyboy · · Score: 1

    And soon to be myspace.

    All these bots use common resources like yahoo/geocities for either mailing out or storing online content/payloads.

    Seriously, yahoo etc... should have an active role with at least 10-30 people constantly scanning their networks/servers for bot hosters/emailers.

    Is it that hard?

    --
    Liberty freedom are no1, not dicks in suits.
  36. I think they are on to something. by Anonymous Coward · · Score: 0

    There is this one guy in my office who is covered head to clothes, looks really, really
    big, and sounds like a trashcan when walking by. He also sounds like Soundwave whenever
    he talks.

  37. Re:Class Action risk for using Microsoft's Product by Anonymous Coward · · Score: 0

    The fact that criminals will always continue to attack networks does not mean that these attacks will always be equally successful. If we make a crime more difficult and less profitable, it will occur less; that's economics.

    Nobody is suggesting that better systems will make botnets completely disappear, and it's asinine of you to pretend that they are.

  38. IT divisions in big companies? by moeinvt · · Score: 2, Interesting

    "I was technically proficient BEFORE I got those certificates."

    "I know many others who also have these certificates. Their capabilities range from extraordinarily adept, to blithering idiot."

    So how did you get technically proficient if you weren't a blithering idiot(but willing to learn) at some point? How did you learn without a few stumbles? As you pointed out, the certifications are often your way in the door. I think it's hard to become technically proficient with a large network without experience.

    "there is a very wide gulf between [training] and someone who really performs well on the job."

    My career has diverged from administrative work, but very early on I was supporting the windows environment of a telemarketing group with ~150 PCs. "Idiot" is an unfair characterization. I'd say "blundering novice". A lot of things went wrong, but can you blame me for taking the job? Unfortunately, companies don't advertise "Wanted: blithering idiot with certifications".

    I'm not lumping you into this group, but your tone is eerily similar to a category of "proficient" people who smugly take delight in the ineptitude of others.

    1. Re:IT divisions in big companies? by azrider · · Score: 2, Interesting
      You said:

      So how did you get technically proficient if you weren't a blithering idiot(but willing to learn) at some point?
      Later on, you say:

      "Idiot" is an unfair characterization. I'd say "blundering novice".
      Trust me, there are some "blundering novices" in every organization. They tend to either learn from having their feet put to the fire, or they get out. That said, based on 30 years in the business, there are very definitely enough "blithering idiots" in the organization to make your life either interesting (best case) or damned miserable (normal case).
      --
      And ye shall know the truth, and the truth shall make you free.
      John 8:32(King James Version)
    2. Re:IT divisions in big companies? by RollingThunder · · Score: 1

      There's a big difference between being ignorant (novice) and being stupid (idiot).

      The ignorant person will still ask the right kinds of questions, and have a half a clue which direction they should be looking. The stupid person will either sit there and wait to be spoon-fed, or charge off randomly trying things that have no relevance to the issue at hand, mucking things up worse.

      It's all about the way the person thinks. A person with a sharp mind and good general troubleshooting skills can pick up the details easily; the dullard will never excel and only achieves mediocrity with herculean effort by trainers.

    3. Re:IT divisions in big companies? by AB3A · · Score: 1

      Please don't confuse education for experience. I know more educated idiots than I'd like to. They learn to regurgitate all sorts of things back on a test, but they somehow can't apply a damned thing they've "learned."

      That's why when I said idiot, I meant it. Some people learn from experience and some do not. The ones who can not learn from any experience whatsoever are the idiots. They are thankfully few, but they do exist. And in large companies, where education and certificates seem to be the currency where people get ahead you will eventually encounter one of these educated and certified idiots.

      I was not discussing inexperience. Inexperienced people can still learn on the job. They observe. They ask questions. They're not stupid. This is not an elitist attitude.

      I don't parade my certificates all over the place. You mistake me for someone who is actually deluded by such things. I get these damned things to get paid well and to use as a credential for those who don't seem to have the capacity to understand anything else. Those people exist too. I don't know why they see the world that way, but the fact that they exist and that they're in charge is reason enough for me to have to placate them. So I do.

      --
      Nearly fifty percent of all graduates come from the bottom half of the class!
  39. Re:Class Action risk for using Microsoft's Product by SolarCanine · · Score: 1

    In any company that's running 100,000 desktops, there's not a snowball's chance in hell that automatic patching is enabled on them - Corporate IT better damn well be reviewing those patches in a controlled environment and then rolling them out after they've been shown to conform to corporate standards and are safe in that network context.

  40. Bank of America phishing spam by Gary+W.+Longsine · · Score: 1

    I laughed, I cried, I wished I had mod points to shower upon you.

    --
    If you mod me down, I shall become more powerful than you could possibly imagine.
  41. Bad summary: It's a WINDOWS problem. by toby · · Score: 1

    Headline and/or summary should state clearly that this is limited to MICROSOFT WINDOWS desktops.

    Eliminate those, and you're a good deal closer to solving the problem.

    --
    you had me at #!
  42. More companies by tooz · · Score: 1

    CRN's got some more info on this story, including a list of compromised companies that are slated to be posted on that blog, but aren't up yet. They've also got a list of "good" companies that haven't (yet) been spotted generating any spam.

  43. also in the spirit, by toby · · Score: 1

    I rarely read replies. But thanks for yours, it made me smile.

    --
    you had me at #!