Torpig Botnet Hijacked and Dissected
An anonymous reader writes "A team of researchers at UC Santa Barbara have hijacked the infamous Torpig botnet for 10 days. They have released a report (PDF) that describes how that was done and the data they collected. They observed more than 180K infected machines (this is the number of actual bots, not just IP addresses), collected 70GB of data stolen by the Torpig trojan, extracted almost 10K bank accounts and credit card numbers worth hundreds of thousands of dollars in the underground market, and examined the privacy threats that this trojan poses to its victims. Considering that Torpig has been around at least since 2006, isn't it time to finally get rid of it?"
why dont they just send a self destruct/uninstall command and kill it or would that be too simple ?
no, maybe, oh I don't know. Why do I get all the hard questions?
The BBC got in trouble when they took control of a botnet for one of their technology shows: http://www.guardian.co.uk/technology/blog/2009/mar/12/bbc-botnet-legality-questioned. While this research was performed in the US, I think they must have broken a law somewhere. I don't see how grabbing personal info obtained illegally for the sake of research, even if they didn't infect the computers originally, makes it permissible under US law.
Take a machine. Install Windows XP SP1. Hook it to an unfiltered intenet access. Watch Sasser install. Mean time before infection: 30 seconds.
That nuisance is 5 years old and still running rampart. Now, far from being the threat that Torpig is, but it shows you just how hard it is to get rid of something. And unlike Torpig, it's not really "in use" anymore. Its maker is gone, it doesn't get any updates or new variants to faciliate infection. We're talking about the same old crapware that every single AV kit knows and removes by now. Worse, it's a threat that any halfway decently patched machine is not susceptible to.
And you want to get rid of Torpig?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
How about we make the punishment for infecting a computer $100 and one day in jail for each system you infect. This way, someone who does something stupid but isn't actually malicious pays a few hundred dollars and spends a few days in jail while the real criminals pay big bucks and spend years in jail. For 180k systems, that's an eighteen million dollar fine and nearly five hundred years of jail time.
Of course, the problem is catching these bastards who tend to live in countries where the government doesn't care or is actively involved in these illegal activities (I'm looking at you Russia).
-- Will program for bandwidth
No, they purchased a domain name, set up servers to accept data sent to that domain, then collected that data. That their research had told them that the domain would be used by the botnet is incidental. If you mail your credit-card information to my domain, I haven't committed any crime if I accept it and turn it over to the authorities.
It doesn't hurt to be nice.
Getting altruism out of people is hard enough at the best of times. Asking for altruism when the likely reward is getting arrested.. no.
How we know is more important than what we know.
Probably, but some well placed vigilante hacking could help the world. I mean if they have control how hard would it be to let that person know that they have a trojan. And to give directions on how to remove it
Unfortunately, that process would soon be usurped. There already is a class of malware called "rouge anti-virus" that gives false removal instructions, resulting in infection.
Better would be to plug the holes, and plug them fast enough so that you can't drive the proverbial slow moving truck, carrying a payload of *wares, through them.
What bothered me after reading this paper is nowhere does this paper come out and say that the infected machines are all running Windows, although this is strongly implied by the description of how the virus works. The reader is left to wonder whether machines other than Microsoft Windows were infected.
Instead, the paper leaves the impression that all computing has the same architectural vulnerabilities. I thought that was a surprising defect, sufficient to make me wonder what else isn't captured/stated/analyzed in the paper.
Why does this sound like a cross between an Onion and Swine Flu?
"It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
Give him a CD with XP which includes SP3
I'm curious: how would I go about producing such a CD, without any of my boxes getting "sassered"?
I have: a Linux box. An OS-less laptop. Some XP recovery disks.
Another analogy is that it's like buying a house at the address 1234 Main Street, Anywhere, USA knowing that other people would try to deliver packages to your address with a "Dear Occupant" label. It's not illegal to open those at all.
Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
Fortunately they're quite easy to spot due to the red coloration.
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
How about the reverse? If you are stupid enough to be hosting a botnet node, you are likely too stupid to know when an anti-botnet attack will affect your machine, nor are you likely to be able to identify such behavior as the cause of any damage to your machine.
Nobody would ever find out. Places like the Geek Squad are populated with people who are instructed to turn stuff over for a profit rather than solve problems, so they won't look for evidence of the battle. They'll just reformat the machine and hand it back. Hackers like us on Slashdot are already probably secure against a lot of this crapware, so we'd never be "reverse-attacked."
And who's to say which piece of malware caused the damage: the original trojan, or the anti-trojan? Even if it were traced down to the anti-trojan, what evidence would you have that it was sent by the researchers, and not by some anti-botnet-vigilante group?
I bet these researchers could release an anti-trojan and get away with it completely. As long as they do it silently, the meddling kids never find out who did it.
Even better: an alliance of anti-botnet researchers! To enter, you have to swear an oath to not rat out the other guys anti-botnet software. "We tried really really hard, but we couldn't figure out who sent it, sorry." No one would ever know.
John