Storm Dismantled at USENIX LEET Workshop
An anonymous reader writes "The USENIX LEET workshop held earlier this week in San Francisco offered neat insights into the Storm botnet, including two papers showing the difficulty of accurately measuring the botnet's size, and one on the way it conducts its spamming campaigns (down to the template language used). There was a bunch of other cool work too, so check out the papers."
It should be http://www.usenix.org/event/leet08/tech/
Test your net with Netalyzr
Hey these people should be called meteorologists, as they are studying a "storm."
After reading the article, I'm impressed by both the ingenuity of the researchers in infiltrating the network, and also by the skills of the malware writers. Engineering a DHT-based network is no trivial matter, and the fact that people out there went through the trouble of creating one implies that the payoff must have been commensurate to the effort involved.
Scary.
I hate spam and what botnets do as much as the next fellow, to the point where I stopped checking email on a regular basis from a few accounts due to the insane amounts of spam I got, but I still have to admire the sheer beauty and audacity of putting together such a living thing. If only they could find a useful (even semi-legit) purpose for harnessing so much computing power.
Moved to http://soylentnews.org/. You are invited to join us too!
Does this run on Linux?
Is "dismantled" really the right word? Shouldn't it be "vivisected", since the botnet is still running?
Dismantled implies that it's shut down. Last I heard, it was still running, and sub-botnets (tropical depressions?) were being sold. Botnet franchising, if you will.
So now the creators can read this and adapt. Great.
"... With Your Humongous New Cock." (actual subject header of spam email received)
Seriously, we haven't had this kind of inspired ribald poetry since William Shakespeare.
I say bring it on, we need the spam entertainment.
SAVE THE BOTNET - SPAM IS ART
Dans la viande a bon marche, il est poesie
consider coffee a lubricant that helps one penetrate the coding zone
After reading up a little more on botnets, it's clear now that SkyNet will in fact originate as a spam and DOS attack/delivery "platform", which will become sentient, and try to kill us all by destroying the internet!
What is...?
So... three guesses what user-agent it's looking for.
Help stamp out iliturcy.
that the storm botnet is basically run by a government entity fronted by criminals, either the US or Russia.
How about this one: Designing and Implementing Malicious Hardware? Now that people are figuring out how to deal with Storm, we may have to start worrying about bogus ICs that will be designed to allow your computer to be compromised easily. Damn! Interesting, though. It was awarded "Best Paper".
Knowledge is the small part of ignorance that we arrange and classify. (Ambrose Bierce)
Funny, I got one with a subject line reading "Attention! Chi/d Pomo!"
A positive attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
next thing we know, it will be cracking google toolbar and getting a look at search histories associated with gmail accounts, and since all spam is invariably connected with some form of sex industry...
i cant wait to get the line "get a larger hadron collider with our revolutionary unix-based pill!"One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
I say bring it on, we need the spam entertainment.
ITYM "spamtertainment".Microsoft needs to quit screwing with the interface of Office 07 and spend some time doing something useful like creating a CD image of WinPE or even a bartpe plugin that includes a scanner for (at least) the major botnet software. Just release a new one every month or two, burn it, reboot, scan. I mean, really, this crap is getting ridiculous. MS just needs to take a bank of 1000 pc's, load xp with no service packs or security and live ip addresses, wait about 20 minutes, and then turn on the sniffers. I don't see how they are not on the receiving end of a class action lawsuit by now.
...when the guys behind it are still RUNNING it right now? I mean, sure it's a wonderful what these researchers were able to find out, but when the potential exists for even more serious crimes to be committed by means of this mechanism, why are we telling the people behind it what they need to think about when designing version 4.0?
Why not just take it over and use it for something constructive, like protein folding or something?
Oh, right -- because then we'd be breaking the law, and the botnet operators might sue us.