Slashdot Mirror


Storm Worm Strikes Back at Security Pros

alphadogg writes "The Storm worm, which some say is the world's biggest botnet despite waning in recent months, is now fighting back against security researchers that seek to destroy it and has them running scared, conference attendees in NYC heard this week. The worm can figure out which users are trying to probe its command-and-control servers, and it retaliates by launching DDoS attacks against them, shutting down their Internet access for days, says an IBM architect."

10 of 371 comments (clear)

  1. In soviet russia... by riceboy50 · · Score: 5, Funny

    The bot-net probes you.

    --
    ~ I am logged on, therefore I am.
  2. The Latest Bond Script by eldavojohn · · Score: 5, Funny

    *An overweight bond sits at a computer desk littered with Payday bar wrappers and graphic novles. He struggles to breath as he brushes at the cheetohs crumbs stuck in his stubble. A blinking light flashes on his monitor and he reaches up with his stubby fat fingers to press the 'Accept Transmission Now' key. The video feed of an equally bloated and zit faced man, though somewhat less pastey white, comes up.*

    Cats: Good evening, Mr. Bond, I was just hitting up some 3 am Taco Bell for fourth meal ... I would like to discuss your latest attempts to probe my botnets on the interweb.
    Bond: *wheezes at the site of his archnemisis* Cats! I should have known it was you! You won't get away with this diabolical scheme!
    Cats: Oh won't I, Mr. Bond? I have all of the world's computers trapped to do my bidding. What would you say if I told you I could bring any website to its knees with a DDOS attack? I noticed you have an apache http server running, Mr. Bond. Perhaps sharing pictures with your loved ones!? Well, I hope a billion attempts to access those images won't ... SATURATE YOUR BANDWIDTH!
    Bond: My GOD! You've gone mad with power, Cats. You're a madman! You'll never get away with this. How do you even keep your franken net in check? What happens when it turns on you?
    Cats: Oh, I think I will, Mr. Bond, Caribbean law is quite kind when it comes to orchestrating botnets. Prepare to say goodnight. Good luck making your raiding schedule, I hope you won't miss those 50 DKP!
    *Bond's screen slows to a crawl as he rushes to turn off Apache*
    Bond: Nooooooooooo!

    --
    My work here is dung.
  3. This pro ain't afraid, come on Stormbot, bring it. by Anonymous Coward · · Score: 5, Funny

    .. I'm still waiti

  4. Re:Counter-DOS by GoodbyeBlueSky1 · · Score: 5, Funny

    Is that you Zapp Brannigan?

    --
    why? forty-two.
  5. Re:Contact the users by Intron · · Score: 5, Funny

    hmmm... We need to get the word to 10 million infected users. I know! Maybe we could hire someone to send an email to all of them!

    --
    Intron: the portion of DNA which expresses nothing useful.
  6. Re:Wait a minute... Isn't this the plot of The Mat by Jaysyn · · Score: 5, Funny

    You can, but it usually hurts really, really badly.

    --
    There is a war going on for your mind.
  7. Re:Kung Fu Style? by Fizzl · · Score: 5, Funny

    I see that you are heard the word "spoofing". Now go learn what it means.
    No, you cannot establish a tcp or any other connection masquerading as someone else. Care to guess why?

  8. Re:Contact the users by zrq · · Score: 5, Informative

    ... the OpenSSH log showed hundreds of attempted logins under the names of I think Doug and Samantha or something like that, so it seems likely they put a back door into OpenSSH as neither of those accounts were in the old passwd file ...

    I see a lot of these all the time, they seem to be cycling through a list of names. At the moment they are trying account names like 'root', 'linux', 'admin', 'test', 'testftp', 'webmaster' etc. and user names like 'melissa', 'danny', 'nicholson' etc.

    I don't think this means that they added a SSH back door, just that they have enough compute resources to try hundreds of combinations of likely names and passwords in the hope they get lucky.

  9. Re:A very simple solution. by Culture20 · · Score: 5, Insightful

    There was a time in England when a bloke could talk about the gay time he had passing a fag around amongst his friends behind the school (fun/happy time passing a cigarette around) without any double entendres. Language evolves. Change your manner of communication or prepare for misinterpretation.

    string Hackers="hardware hobbyists"
    string Crackers="Saltines, safe-crackers, computer-criminals"

    ...
    Hackers="computer-criminals";
    Crackers="Saltines";

  10. Re:A very simple solution. by Anonymous Coward · · Score: 5, Funny

    Language evolves. Change your manner of communication or prepare for misinterpretation.


    Bookmark of cradle the desklamp, or coffee door bird the bubble wrap. Airport barcode of lunch train.

    Football.