Slashdot Mirror


Are Computer Crooks Renting Out Your PC?

An anonymous reader writes "Brian Krebs recently posted an interesting piece looking at an invite-only service marketed on shadowy underground forums that lets crooks 'rent' or 'buy' access to individual botted PCs that can be used to tunnel traffic. The story looks at the mechanics of renting out bots, and the author traces some of the infected systems back to real businesses. From the post: 'The Limited; Santiam Memorial Hospital in Stayton, Ore.; Salem, Mass. based North Shore Medical Center; marketing communications firm McCann-Erickson Worldwide; and the Greater Reno-Tahoe Economic Development Authority.'"

14 of 208 comments (clear)

  1. Are Computer Crooks Renting Out Your PC? by WrongSizeGlass · · Score: 5, Funny

    No. I'm so busy surfing /. that I don't have any spare CPU cycles to rent out.

    1. Re:Are Computer Crooks Renting Out Your PC? by fuzzyfuzzyfungus · · Score: 4, Insightful

      Don't forget Adobe Reader. I've lost count of the number of Reader security advisories that apply to basically every OS they release binaries for. It isn't often you see news of an exploit vector for Solaris; but Adobe manages it.

    2. Re:Are Computer Crooks Renting Out Your PC? by PopeRatzo · · Score: 5, Funny

      Actually it is window's fault that it's insecure by design.

      It's not so much that Linux is necessarily more secure, just that the botnets can't get their software to run on it. Something about not having the right drivers, is what I heard.

      Yep, that's what I heard all right.

      Oh, take it easy...

      --
      You are welcome on my lawn.
    3. Re:Are Computer Crooks Renting Out Your PC? by Threni · · Score: 4, Insightful

      Exactly. "Are Computer Crooks Renting Out Your Windows PC?" would be a better headline.

    4. Re:Are Computer Crooks Renting Out Your PC? by Anonymous Coward · · Score: 4, Insightful

      You forgot to mention that:
      Linux users have a better common sense then the rest.
      Linux users use legitimate repos when they install any software.

      I think the mac users fit in there as well, but with only linux and windows as experience, I really can't speak for them.

    5. Re:Are Computer Crooks Renting Out Your PC? by DarkOx · · Score: 4, Insightful

      Right on I am getting real tired of "I run X" where X is most of Linux therefor I am secure. That attitude alone tells me you are probably making big mistakes all over the place. Arrogance does that. Its true people writing those comments are probably safer than Joe Public with his OEM crap ware laden Windows XP installation, out of date virus defs, and default Windows firewall configuration, 3000 never applied updates waiting, and logged in as an Administrator, but that is pretty low bar to be above!

      I do IT security for a living, here is a hint. Whatever software you are using take steps we all read about, firewall, antivirus if that makes sense for your platform, don't elevate permissions when your don't have to, keep your box update, and after you have done all those things continuously check to make sure you are still doing them and above all use common sense at all times, always think before you click!

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    6. Re:Are Computer Crooks Renting Out Your PC? by CapOblivious2010 · · Score: 5, Insightful

      Linux users have a better common sense then the rest.

      True enough, but that doesn't say anything about the security of linux... it merely says that people who are smart enough to get linux to work for them are also smart enough (on average) to avoid all the crap that idiot windows users fall for.

    7. Re:Are Computer Crooks Renting Out Your PC? by Tablizer · · Score: 4, Informative

      That "Web 2.0" /. interface indeed is a CPU hog, full of polling JavaScript. Fortunately, they still allow the old-style as an option.

    8. Re:Are Computer Crooks Renting Out Your PC? by melikamp · · Score: 4, Insightful

      Windows is trivial to secure with a wealth of free services from MSFT SE to AVG to Comodo CIS to Avast.

      Wow. Do you realize that AV software is largely ineffective against new viruses? Here is a typical scenario out of my life: a friend wants me to fix a Windows PC infected with a virus. Sometimes the virus is apparently racing the AV, and sometimes the AV is disabled. But there is always AV. So what good is it? The only useful feature of an AV software is that there is a slight chance it will behave unusually after the machine is infected, and so alert a user of an intrusion sometime in the past (that is, of course, only if the virus is destructive or buggy).

      So on one hand you acknowledge that Windows is insecure by default, and should be secured. But to secure it, you want to install a piece of software that slows the computer down, while failing to prevent many viral infections.

      You also fail to address the biggest issue with securing Windows: it is theoretically impossible. Because the software is proprietary, it is insecure by any sensible definition. It is insecure for you as the user, although it is made to provide "security" for Microsoft. Not for any technical reason, but solely because of Microsoft's greed, you have a backdoor in your OS that only Microsoft (you hope) can use. Whatever other security holes there are, you propose to fix with other proprietary programs, each having its own backdoor.

      When Linux becomes a big enough target IT WILL BE PWNED.

      Linux kernel will be pwned? As in, once Linux reaches X% desktop share, all of the sudden a bunch of kernel exploits will be found? How? The value of a kernel exploit today, either local or remote, is already enormous. If they are already found at the rate they are introduced, then what does the popularity have to do with it?

      Or did you mean, Linux-based OSes will be owned? All of them at the same time? Or one in particular? And then which one? I am not surprised seeing Android in trouble: every android phone sold today is a proprietary platform, and the proprietors happen to be incompetent. This does not mean that we won't be able to install Debian or Slackware on a phone a few years from now and enjoy rock-solid security.

  2. Are Computer Crooks Renting Out Your PC? by 1s44c · · Score: 5, Informative

    Are Computer Crooks Renting Out Your PC?

    No, I don't run windows and I set it up right.

  3. I knew it by fwarren · · Score: 5, Funny

    Windows Vista was not that bloated. Microsoft was just monetizing spare CPU cycles on the Russian Black Market.

    --
    vi + /etc over regedit any day of the week.
  4. Hospitals are no surprise by HangingChad · · Score: 4, Informative

    >Santiam Memorial Hospital in Stayton, Ore.

    I used to provide tech support for doctors offices and hospitals and I can tell you for a fact that their computer security ranges from "bad" to "OMFG!!". Seriously, there were places I wanted to take a shower after leaving because their workstations were so riddled with spyware and trojans.

    --
    That's our life, the big wheel of shit. - The Fat Man, Blue Tango Salvage
  5. There are reasons for that... by damn_registrars · · Score: 5, Interesting

    Santiam Memorial Hospital in Stayton, Ore.

    I used to provide tech support for doctors offices and hospitals and I can tell you for a fact that their computer security ranges from "bad" to "OMFG!!".

    That happens for several reasons:

    • The software they use as part of their work requires admin access (bad vendor programming)
    • The hardware they need to access requires admin access (more bad vendor programming)
    • They consider needing an additional password for admin function to be "too inconvenient" (bad user education)
    • They didn't need to do it when they used 3.x/NT/98/etc ... why should they need it now? (also bad user education)
    • They were told that their anti* software would protect them, even without ever updating it - or anything else (bad vendors meeting up with badly educated users)
    --
    Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
    1. Re:There are reasons for that... by dwarfsoft · · Score: 5, Informative

      Most of the "Bad Vendor Programming" I've seen in this situation did not actually require Admin Access, but required specific permissions set for Users to be able to get the programs to function. The reason that these users were ever added to Local Admin was due to "Bad IT Admin" more than anything else.

      After I re-trained the one guy who kept adding users into Local Admin on how to determine (regmon/filemon/procmon) which folders/files/regkeys needed additional permissions (and how to manage a local group for those settings) and he continued to do it, I was only too happy to remove his access to be able to change any security settings or add any users to any groups. Problem was solved.

      It wouldn't surprise me if far too many people in those Workstation Admin roles don't fully understand security, particularly in places like Hospitals where Doctors think they have the authority to tell everybody how things should be done.

      --
      Cheers, Chris