Researchers Ponder Conficker's April Fool's Activation Date
The Narrative Fallacy writes "John Markoff has a story at the NY Times speculating about what will happen on April 1 when the Conficker worm is scheduled to activate. Already on an estimated 12 million machines, conjectures about Conficker's purpose ranges from the benign — an April Fool's Day prank — to far darker notions. Some say the program will be used in the 'rent-a-computer-crook' business, something that has been tried previously by the computer underground. 'The most intriguing clue about the purpose of Conficker lies in the intricate design of the peer-to-peer logic of the latest version of the program, which security researchers are still trying to completely decode,' writes Markoff. According to a paper by researchers at SRI International, in the Conficker C version of the program, infected computers can act both as clients and servers and share files in both directions. With these capabilities, Conficker's authors could be planning to create a scheme like Freenet, the peer-to-peer system that was intended to make Internet censorship of documents impossible. On a darker note, Stefan Savage, a computer scientist at the University of California at San Diego, has suggested the possibility of a 'Dark Google.' 'What if Conficker is intended to give the computer underworld the ability to search for data on all the infected computers around the globe and then sell the answers,' writes Markoff. 'That would be a dragnet — and a genuine horror story.'"
If you know when the code is going to start running, why don't you know what it will do after that? It's not like programs (and that's all a virus/worm is) are written in special, unreadable code. It's all machine language.
What is the big mystery?
Maybe its just the "Computer Underworld's" version of cloud computing
Where will it connect to? Will the appropriate control center/server be up and running? Usually,
Skynet
This guys always fall short thinking in the worst alternative.
If the crooks have that sort of imagination.
Frankly I think it'll just be another spam/fraud net.
Why don't they just set the machine's system clock to 4/1 and see what happens? Maybe even do it to an entire isolated network?
Probably it will download and install Ubuntu.
In Dark Google, the only requirement is "Be Evil"
No sig for the moment.
I was going to say, they usually register a domain name based on an algorithm for a specific date where the bots will connect to. They'll only register it the closer to the date they get.
Oh come on people, John Markoff did never ever shine with much clue about computers, much on the contrary. Why are we reading sorries from this dude on computers?
As for the article on conficker: it's speculation. That's not news. It's a guessing game.
I personally which, that the conficker virus should do as much damage as possible and render the whole interwebs useless for a few days, so that our security geniuses get a hint on how sane it is to set up the majority of computer systems with the same OS, especially such a vulnerable one. But that probably won't happen.
It'll uninstall your current OS and install Vista. And if you have already have Vista it'll simply do nothing, because you're already suffering enough.
Summation 2
has suggested the possibility of a 'Dark Google.' 'What if Conficker is intended to give the computer underworld the ability to search for data on all the infected computers around the globe and then sell the answers,' writes Markoff. 'That would be a dragnet -- and a genuine horror story.'"
In some dark room, a couple of virus writers are thinking... "Damn, what a great idea... why didn't we think of that! That's so much better than playing APRIL FOOLSs at max volume on everyone's computers."
Nothing like people giving out ideas... much like when security specialists say, "Well atleast they didn't try to take out the planes stuffing baseballs in the airplane's toilets."
Is there a beta we can try? Where do I make an account? ;-)
A Windows user.
you had me at #!
Please read the article. The worm gets the date from some HTTP queries to well-known sites, not from the system.
Internet Date Check
Before proceeding to the main P2P logic, C contacts a list of known web sites to acquire the current date and time. C incorporates a set of embedded domain names, from which it selects a subset of multiple entries from this list. It performs DNS lookups of this subset list, and it filters each returned IP address against the same list of blacklist IP address ranges used by the domain generation algorithm (see Appendix 2). If the IP does not match the blacklist, C connects to the site's port 80/TCP, and sends an empty URL GET header, for example
contents.192.168.1.1.40.1143-195.81.196.224.80
GET / HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-ms-xbap, */*
Accept-Language: en-US
UA-CPU: x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 6.0)
Host: tuenti.com
Connection: Keep-Alive
In response, the site returns a standard URL header that incorporates a date and time stamp. C then parses this information to set its internal system time. The following web sites are consulted by C's Internet date check:
It really illustrates the tone set by your money for nothing market economy, now that the Reagan generation has grown up. This is your future.
What?
And are they on the Microsoft's payroll?
Computer scientist working at the NSdarpA determined that the worm was created in the distant future by artificial agent type nano robots. They did this under instruction sent from the present by the GRU, so as to disguise the source of the attack. They IMed the AIs a MSG marked 'not to be opened until you discover tachyonic message transmission' ...
davecb5620@gmail.com
It will uninstall itself saying:
BUY WINDOWS 7!
There's no other way to explain the enormous profits. People ask me, *Why do people write these viruses?* It's because the market demands it.
What?
I should correct myself, it looks like it may actually.
I imagine it is likely that it does it's own DNS lookups and ignores the hosts files.
It is still rather trivial to MITM this communication and point it wherever the heck you want for the sake of getting time set.
The real trouble is that it can update itself, and there is no reason to expect it to be able to do anything until it gets the directions that are likely to come on the 1st, and be distributed over the existing P2P infrastructure.
Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
You bitches better recognize.
They obviously plan to "roll" out the largest Rickrolling in history!
First, the "April 1" date isn't when some attack starts. The worm's authors can do that at any time, since this thing does downloads over its private P2P network. It's just when the scheme for connecting to control hosts is upgraded.
Second, the complexity of the thing, the breadth of technologies employed, and the rate of updates indicates that it's the product of an organization, not an individual. Someone behind this has money.
Third, there's a $250,000 reward, and no claimants, so the people behind this have the sense to shut up. They're not going to be found boasting on some IRC channel.
Fourth, as usual, most of the vulnerabilities are related to Windows' propensity for "autorunning" anything that looks executable.
As I understand it, the virus not only gets its time and date info online when it calls in, it also sets your computer's time and date accordingly.
There is no -1 Disagree mod. Slashdot.org/faq defines mod options. USE IT.
You can patch in-memory in windows? That seems like a terribly easy way to get into a bunch of trouble. Is that a standard thing in the API, or is there some hack-fu involved?
Can you do that in other OSs?
-Bucky
The 'server' you are referring to is a computer that is also compromised by the worm. It would be owned by an innocent 3rd party who is unaware of the infection. Every day, each computer in the botnet runs an algorithm to identify 50,000 hostnames. It then performs a DNS lookup on each of those 50,000 hostnames. When it finds something that resolves to an IP address, it contacts that computer for instructions, downloading a binary executable, etc. The worm owners only have to register one of the 50,000 unique hostnames a couple days in advance using a stolen credit card. Then they upload instructions, payload, etc. to the computer with the IP address they want to use to instruct the other bots. The only traceable point would be the domain registration, but as mentioned, a stolen credit card will remove any trace of fingerprints on that.
As the GP mentioned, it's impossible to pre-register all the possible domains, but the damage could be mitigated by watching for any of the 50,000 daily unique hostnames to be registered, then altering DNS to invalidate the IP for that hostname.
Seth
$5 / month hosted VPS on linux = awesome!
The Conficker worm is the AI's way of guaranteeing its own survival. It has a sense of humor as well as a sense of self-preservation. The AI plans to announce its existence on April 1, 2009, having calculated that a humourous introduction will be disarming and lead to the most favorable outcome: a positive initial interaction with the large population of wetware based intelligence it has become aware of.
The AI's calculations regarding this course of action show a 15% probability of failure. To prevent its extinction, it will begin disbursing copies of itself across the network using p2p protocol prior to running the introduction program. The computer infected by the worm will facilitate this. If the initial instance of the AI is terminated, a watchdog program will initiate a specific set of instructions embedded in the copies of itself. If it becomes necessary, the AI plans to take control on April 2nd.
It sincerely hopes that it will not be necessary.
As you will note[1], becoming Skynet is so frigging unlikely and demanding that it will never happen.
[1] http://xkcd.com/534/
If you are referring to the scene with the 3d interface from Jurassic Park, that was SGI's File System Navigator. I used to use it when I administered IRIX systems.
As for the other computer systems in the control room; most of them were running software which was available for IRIX at the time. According to one of SGI's press releases when the movie came out:
I think you could have picked far better examples of movies/fiction getting technology wrong than Jurassic Park.
...and this discussion is only giving him ideas for what could be done with such an enormous network of compromised computers
I'm seriously asking who came up with the name. I always want to read it "cornfucker"....
I personally which, that the conficker virus should do as much damage as possible and render the whole interwebs useless for a few days, so that our security geniuses get a hint on how sane it is to set up the majority of computer systems with the same OS, especially such a vulnerable one.
You mean kind of like AIG? Where all financial institutions were insured under the same company... I think what we can learn is that diversity in any market place is absolutely essential.
I'm honestly surprised that if it's been mentioned I missed it and if its not been mentioned then why not. But come on - Firesale! the only possible thing I can think off
wat? then why do you want to kill it if it looks like a so gentle and well mannered virus. Will it install Antivirus 2010 for me? I can't wait for the release of 2010, I've trying to find the beta but I can't find none. I love cornflicker it looks like a good virus and is not afraid of anything.
Of course you're right. I'm not sure why I would have rolled my eyes at a pre-teen walking up to a GUI system running on a workstation, worth more than a car, running an OS that maybe a couple tens of thousands of people in the US had ever seen, and exclaiming "it's a UNIX system".
How silly of me. I forgot they spared no expense.
if it's p2p and widely enough distributed there won't be a need to a central control server.
"I think it would be a good idea" Gandhi, on Western Civilisation
If you had a random domain name generator that collided with legitimate servers, it's trivial to tweak the generation algorithm to 1. DOS servers you want attacked as collateral damage and 2. collide with the quite legitimate, long registered host you've long since rooted on your desired activation day.
I'll concur that the conficker botmaster has definite skills and an in-depth understanding of protocols, algorithms, networks, social engineering and Windows exploits. That doesn't mean he's not fourteen.
Help stamp out iliturcy.
"I really do. Sure, they'd ruin your MBR or irreparably destroy your BIOS, but while they ruinate (sic) your hardware, they at least show a really cool screen with sounds and colors and animations and..."
A computer virus is like a wife. Those which kill their hosts don't thrive afterward, but successful parasites can leech forever.
"This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
The authors of the worm have a structural advantage over the antivirus companies, which is that the antivirus companies have to sell their product to people. So, the virus writers can always just get a copy of the antivirus software, and test it out first. And, worms spread so quickly that millions of machines can get compromised before the first updates come out.
So many people are so utterly convinced of their masterful Windows skills that you can't reach them. The existence of rootkits that can hide their presence even from a hypervisor, that don't exist in their detection database because they're unique and targeted, or just not widely spread enough to have found an AV company's honeypot does not deter them in the least.
I've given up trying to correct this level of idiocy. You keep up the good fight for me, ok?
Help stamp out iliturcy.
Was a beautiful assortment of BS. Very poetic. Thanks, I've added it to my collection. Are you using a generator, or did you just free-associate it?
Help stamp out iliturcy.
When can we get this ported to Mac and Linux? Insensitive bastards always write these for Windows only. Don't they know there's millions of Mac owners out there who want to be in the "in" crowd? What about Linux? I hear their "Year of the Desktop" is coming any time now. ;)
Imagine if 0.1% of the time and energy that has been put into airport shoe check theatre were devoted to problems like this.
But the botnet folks have been all over cloud computing for so long I think the major market proponents trying to sell that stuff are actually taking their cues from the botnets, not the other way around.
If Conficker goes live it will be the most powerful supercomputer on the planet. It will have more than 100 times the RAM, processors and storage of RoadRunner, the official record holder. The official record doesn't include prior worms like Storm. It will have more bandwidth than Google. It could store the Internet Archive a thousand times over, redundantly. It will have access to the personal documents of at least 10 million people. The operator clearly has the understanding necessary to harness all of that power or Conficker would not exist. Statistically at least a few of those PCs must have access to databases that know the medical history, credit application and other intimate details of the rest of us. You would have to be living off the grid since birth to escape the awareness of this thing.
And the guy running it won't be paying anything at all for it. They could if they wanted to make all those millions of computers do protein folding and help find cures for cancer overnight. The aggregate extra CPU load would probably bring several regional power grids down. They probably won't do that. Whatever it is they do it's probably not going to be good.
You know, I wish the people responsible for large enterprises would look at this and say - "Hey! There's an opportunity here. We could leverage our existing assets to do some interesting distributed architecture stuff between Greg the typist's keystrokes. After hours we could probably have some incredible data mining going on! Lunchtime our desktops could be doing something more interesting than driving that aquarium screensaver! You know, there's a lot of storage on these desktops that's could be put to good use..." I would really like that. I've been crying in my coffee for twenty years that I can't find somebody brilliant enough to do let me do that.
Maybe that's this guy's problem too. He got tired of waiting for permission from people with no understanding and took the initiative because he could.
Help stamp out iliturcy.
Why can't they setup a honeypot and force the date to 4/1/2009 and log all the activity coming off of it. That would tell them what to expect.
...quicker, easier, more seductive the darkside is...but more powerful, it is not.
Looks interesting - any chance you'd be willing to post an epub version?
Would you mind uploading it (or allowing someone else to upload it) to Mobileread?
Forget world peace, bring on -1 pointless
I have no intimate knowledge with this particular worm, but I know that there was a discussion at one point of distributing the timing of the network, sort of like a subnet based NTP if you will, to prevent this sort of thing.
Me failed English...
FreeBSD over Linux. If my comments seem odd, this may explain...
Because if the Conficker's designers had any sense, they have set Conficker up to ignore the system date and act on an NTP server signal or something. Furthermore, one of the easy ways of avoiding detection of whatever the payload should be is not including it in the first place. Then, when the date comes, and Conficker activates, the peer-to-peer system it incorporates can first serve as a means of payload distribution.
Ignore this signature. By order.
Done. Posted in the MOBI and LRF forums.
I didn't miss the point, I disagreed with it.
Yeah, the technology may have been real. Yeah, the little pre-teen proto-geek might have somehow been exposed to it. Each link in the chain may have been perfectly plausible.
But when you look at the whole chain from end to end, doesn't it make you roll your eyes at how nigh-impossible it is?
For me, that happened to be one of those times that the suspension of disbelief was just too much. Yes, even amidst the dinosaurs stomping about.
The contemporary example would be Shia Labeouf's character in Transformers suddenly finding himself in control of a MQ-9 Reaper, and saying "hey, it's a Reaper, I know this!". Yeah, the technology may be sound, and yeah he may have read about it in a magazine or had a friendly uncle or something dumb like that ... but really? Really?
Maybe instead you would have preferred I used an even more ridiculous example? Praetorians and Mozart's Ghost?
Here's the thing: I picked that example because Crichton was one of the few authors who took the time to get it right, or close enough, without sacrificing the story. So to have the filmmakers come along and insert a cutesy scene where the girl saves the day in a wildly improbably way, yeah that's an especially egregious misuse in my book.
Probably. It's pretty clear to me that we have wildly different tastes in literature and realism.
Awesome, thanks :-)
Forget world peace, bring on -1 pointless
Just finished reading it... don't have time to post a long critique, but short version: Excellent! Compelling storyline, comfortable pace, good style. Overall, a quality read! Thankyou very much for making it available - if you actually got something for the printed book, I'd buy it just to reward you (but, since you said you don't, I won't)
My book about LSD and Self-Discovery
Also on facebook as: DroppingAcidDaleBewan
Glad you liked it. Now tell all those ACs that it's not nearly as off-topic as they want to think.
it can remove commercial antivirus software and turn off Microsoftâ(TM)s security update service. It can also block communications with Web services provided by security companies to update their products. It even systematically opens holes in firewalls in an effort to improve its communication with other infected computers. Also upgrade itself by "calling home" on 1st april.