Turning Attackers' Tools Against Them
Tasha26 writes "The BBC has an interesting Web security snippet from the SyScan 2010 security conference in Singapore. In a presentation, security researcher Laurent Oudot released details of bugs found in commonly used attack kits such as Neon, Eleonore, and Sniper. These loopholes could be exploited to get more information about the attackers, perhaps identifying them, stealing their tools and methods, or even following the trail back to their own computer."
There should be bounties put on these folks spreading this shit.
A work that expires before its copyright never enters the public domain and thus enjoys eternal copyright protection.
...or did he behave irresponsibly and publish the bugs without giving the vendors time to issue patches?
Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
Meh... Thae fact that there are errors and vulnerabilities in web based tools just means that they were written by programmers who largely don't have peer code review, which is why so many computer viruses never get to trigger or release paylod, the only working part of them is the infection mechanism. Perhaps these vulnerabilities would aid n catching a script kiddie who had downloaded a poorly programmed tool and was dumb enough to launch from his own computer. Nobody with brains would launch from "home", they would use bots, which means the police will be storming an old age home with grandparents still using windows 95. I do applaud looking at hacking tools though, I workd for a company that used a stripped down, harmless version of the sub7 trojan to deploy software and it was far superior to commercial deployment solutions at the time.
sig loading.......
Do you really think that the creators of these "tools" aren't going to leave SOME way of getting back into them? To prevent them from being used against their own systems?
"Did you really think you could use my own spell against me , Potter?" -Severus Snape "HP: THBP"
[End Of Line]
In other news, researchers learn that script kiddies tend not to be very good software developers.
Want to improve your Karma? Instead of "Post Anonymously", try the "Post Humously" option.
This is great intel, no doubt. There's a bit of irony in reporting vulnerabilities in malware - can I get a CVE for that? Counter-attack has a bunch of potential issues, though. The primary one is attack attribution, and the other primary one is that it's not legal in many places (including the United States) to counter-attack your attacker. If you execute code or access a system without the permission of the system-owner, you're in the same crime category as the original miscreant.
Haven't they already taken the first step with compulsory driver signing in their 64-bit OSes? I hear there's a registry hack to disable it... for now. But MS would -love- it to be mandatory, they've been laying the foundations since the original "Trusted Computing Platform Alliance" days haven't they? I don't keep up to date on all this stuff so maybe it's not so true anymore.
ERROR 144 - REBOOT ?