Korean DDoS Bots To Self-Destruct
tsu doh nimh writes "Several news sources are reporting that the tens of thousands of Microsoft Windows systems infected with the Mydoom worm and being used in an ongoing denial of service attack against US and S. Korean government Web sites will likely have their hard drives wiped of data come Friday. From The Washington Post's Security Fix blog, the malware is 'designed to download a payload from a set of Web servers. Included in that payload is a Trojan horse program that overwrites the data on the hard drive with a message that reads "memory of the independence day," followed by as many "u" characters as it takes to write over every sector of every physical drive attached to the compromised system.' ChannelNews Asia
carries similar information."
You have to imagine if these computers are all infected with this one trojan, they are probably infected with god only knows how much other spyware, malware, backdoors, and spambots. This might just be a GOOD thing; when these compromised twits wake up to a completely wiped drive, it might be the thing that drives them to read up on computer security a little bit, perhaps switch to a more secure browser, buy a router with a hardware firewall, etc. Not to mention, it will also wipe out all the aforementioned crapware.
At least this way they'll get cleaned up and (possibly) patched, right?
Compare it with biological malware. Ebola causes more damage than AIDS, but it's less of a concern, because it kills the host dead pretty quickly. AIDS causes more havoc, because the host survives for such a long time.
about time windows boxes self destructed... people might start to question windows security issues more if their boxes died rather than just slowed down...
Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
Precisely my thought on reading the summary -- good riddance to some severely compromised systems on the one hand, and on the other, I sincerely hope the users gain a clue.
Getting hit with the clue bat hurts. Otherwise, folks tend not to remember.
Cheers,
"What in the name of Fats Waller is that?"
"A four-foot prune."
u in binary (yeah, I know what you meant):
1010 0101
I would have expected
0101 0101
which is "U"
(or 1010 1010, but that doesn't seem to be a nice ASCII character I can type)
Hmm, maybe it is a capitalization error on someones part, or maybe they just like the palindromic nature of 1010 0101?
Let's hope the guy who's good at curing cancer is also good at making backups...
Seriously. It overrides every attached HD. How well does a RAID stand up to that in terms of data protection? Or an attached USB HD?
> From The Washington Post's Security Fix blog, the malware is 'designed to download a payload from a set of Web servers. Included in that payload is a Trojan horse program that overwrites the data on the hard drive with a message that reads "memory of the independence day," followed by as many "u" characters as it takes to write over every sector of every physical drive attached to the compromised system.'
Did the washington post writer get this wrong, or is this a misreported urban legend? The "trojan horse" part doesn't make any sense -- the computer is already compromised.
Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
Sucks to be running Windows.
*gets back to work in gedit*
It's better to vote for what you want and not get it than to vote for what you don't want and get it.
- E. Debs
I'm glad there's a happy ending to this story. Thousands of unpatched windows machines will cease to exist, hurray!
Over at Yahoo ( http://tech.yahoo.com/news/ap/20090710/ap_on_hi_te/as_skorea_cyber_attack ) they are reporting that there are only 86 IP addresses causing the outages:
"SEOUL, South Korea -
Cyber attacks that caused a wave of Web site outages in the U.S. and South Korea
used 86 IP addresses in 16 countries, South Korea's spy agency told lawmakers
Friday, amid suspicions North Korea was behind the effort."
Now, I'm a little skeptical that they didn't mean ISP instead of IP, but if it is true that there are only 86 hosts generating this much fanfare, then the network admins should be strung up with cat6 for not just blackholing these punks at the edge router. I guess we get the best govt. IT we can afford, right?
Contrary to popular belief, life is not a bitch. It is far far worse.
Actually, it CLEARLY is a plot. It should be pretty obvious to everyone...
It was designed to attack less important government websites, while keeping collateral damage to a minimum... No attempts on the power grid, FAA, etc., and no private companies affected.
Joe Lieberman went up before a room full of press and cameras and said, (roughly) "If this was someone sending us a message, we got it loud and clear."
Plus, it launched on July 4th, not a particularly significant day for North Koreans... And while anybody could look it up, who here can say they know the dates of big Chinese holidays? Really?
And now, it's doing exactly what good worms NEVER do... Killing their hosts, and themselves, suddenly, flagrantly, and unnecessarily. Exactly what any of us would wish to do with zombie PCs.
So, it seems pretty damn likely it was in fact anti-malicious. Some misguided white-hat who thinks drawing attention and cause a small bit of undeniable pain is the only way to make things get better. Frankly, it sounds like the ideal NSA fund raiser...
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
Why don't YOU get a clue? Punishing the user of an insecure OS will not do a damn thing. It will not do a damn thing to increase security. There will just be lots of people who are fucking upset because they lost a whole heaps of important files or memories (e.g. photos). It is not THEIR fault that windows is so fucked up (is it)? So, why do you take delight in them losing their data?
So, I hit YOU with you so called "clue bat" and I hope your meagre brain manages to parse it. I hope you remember this.
Cheers,
It sounds more like the destruction of evidence. But then again, why'd I want to do that if I was already identified as the culprit? What could I gain? If anything, I'd want the attack to continue indefinitly, even after I've been wiped out, so to maximize the damage to my enemy even if I should not survive it.
To anyone playing chess: If you can't save your queen, make sure you can trade it for his.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
I'd be scrambling now to get that day off. Failing that, I'll find a doc that writes me a sick leave, if necessary for a bribe. Failing that I'd quit.
There is no way anyone in support will survive that day without a ringing in his ears.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Bots and other malware that do no appreciable harm to their hosts have made users complacent about keeping their systems clean (or preferably secure). In the meantime, the collateral damage of spamfloods, spyware, and DDOS attacks has been inflicted on the whole community. An exemplary episode in which the infected machines actually suffer may wake users up again. Windows users are, as usual, the witless accomplices/culprits in this case, but Macs can be just as easily penetrated (demonstrated in the hackfests each year), and poorly administered Linux/BSD/Solaris systems can also be vulnerable.
Let the vendors of protective measures celebrate! Sales of anti-virus, anti-spyware, anti-rootkit, firewalls, and so forth may benefit. The publicity may even cause some security holes to be patched, and better practices to become default. Maybe the rest of us will benefit...
Those who can make you believe absurdities can make you commit atrocities. - Voltaire
Greetings and Salutations...
First off, I fear this is a hoax, simply because we are hearing about it BEFOREHAND. One of my favorite comments (said about a recent event where some flake was arrested after some very vocal threats against our President) is "Real assassins don't tell you they are coming to kill you".
Secondly, if it were me, I would overwrite the hard drive with "DEADBEEF". Not only is it traditional, but, it has a certain charming truth to it that would add amusement.
regards
dave mundt
YAB - http://blog.beemandave.com/
If you have a disk-to-disk backup solution, most likely both sets of data will be hosed from this virus. Unless backups take place on tape, or the drives are rotated for off-site safety, the victim is fucked!
As much I'm happy to hear this virus self destruct, no one deserves irrecoverable data loss.
The hardware abstraction doesn't matter if all the virus does is make read/write calls using the OS like any other application. In other words, if Windows has a volume mounted, then the virus will be able to see it and whack it out of commission.
Life is not for the lazy.
It's a sequence of 01 repeating. The fact that it comes out as "U" is probably coincidence.
Point taken. However, most people in the U.S think that their leaders are full of crap. Not much different than most parts of the world.
However, in North Korea, the average citizen has practically zero access to information from the outside.
So if brainwashing was say... at a 3/10 in the U.S, it's a 10/10 in North Korea. I mean, come on, your hands rotting off by picking up a piece of paper? It's not like the levels of bullshit are equal in the scope of the lies they represent or their damage.
I did not bring up the point to say America is "number one" and that our crap does not stink, just wanted to point out that with all the brainwashing going on in North Korea it is fact that the average North Korean hates and fears us. To say that July 4th is not a significant day in their lives is just incorrect. That's all I was sayin'.
And anything that may get the average S. Korean to take computer security seriously and not roll their eyes dismissively when you make secure practice recommendations, is a plus in my book.
Well, to be frank, Y2K didn't happen partly because it was hype, sure, and partly because everyone jumped on it and if there was serious systems which could fail, they were fixed. Claiming that all it was hot air would be going in same absolutes like claiming that it could have definitely caused end of the world.
This time, I am not so sure that it is Y2K type. It could be pure sensationalism, sure, but such virus can be written by anyone. I simply see it as virus authors so far haven't been interested of causing damage to PCs - mostly because they need them to do their DDoSing and spam spewing.
user@ubuntubox:~$ stfu This server is going down for shutdown NOW!
Right.... because hoping some good will come of a computer intrusion is just like hoping for the deaths of people to make a political point.
It's not a small amount, but considering there are 100s millions of machines around the world it is a pretty small amount.
How many machines out there have a HD failure everyday? I'm guessing it is less than 50,000, but probably not much lower. Google and wiki searching only gave me numbers like 3% annualized failure rate up to 13%.
Once the system is rebooted what kind of error message will they see? OS not Found from the bios? I wonder how many users will simply think their harddrive failed.
Wouldn't work with a free press. However, no such press exists in north korea.
those are outright lies by politicians. disconnected and ridiculous
in north korea you are talking about a concerted effort since birth to convince your citizens the world outside your borders are full of bloodthirsty tribes ready to destroy you at a moment's notice
not that there doesn't exist people who believe that in the west, but there isn't a concerted effort by the government to create that belief
comparing real brainwashing in north korea with the worst example of demagoguery that you could find in the west: not even remotely in the same league
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
We are trying to get to a stage where people can use computers without having to know about charsets, antivirus, backup, updates and firewalls or have a 'driving' license just to look at some porn. In my experience firewalls and virus scanners do nothing but slow down a Windows PC and provide another deluge of popups that nobody can understand.
Windows seems to be going in the opposite direction. Is this just to keep the money slushing around in the 'fixing Windows' industry?
Good riddance to computers that require $200 worth of repair for just 'clicking the wrong link'... Whatever that means.
If you want a car analogy then cars today are being supplied with 1000 buttons on the dash, one starts the car, and another stops the car. Pressing the wrong one will cause your car to stop functioning for you, but it will happily put viagra advertisements on it's radio and drive around town all day annoying people.
At least Google seem to have the right idea with Native Client. I would add a link but how would you know if it was a 'wrong link'?
Remember kids, manually type in those URLs!
okay so you believe: that a 2000 year old cosmic, Jewish zombie, born of a virgin mother; will offer you eternal life if you HAVE DINNER WITH HIM and telepathically accept him as your master so he can remove an evil force, present on all humans because a woman who was made from the rib of a man, who was constructed of dust, was convinced by a talking snake, to eat a cursed apple, from a magical tree growing in a mystical garden a little while after the universe was created around 6000 years ago.