DOJ Gets Court Permission To Attack Botnet
itwbennett writes "In an unprecedented move, the Department of Justice (DOJ) and the FBI have been issued a temporary restraining order that will allow the FBI and the US Marshal for the District of Connecticut to set up servers at the Internet Systems Consortium or other ISPs that would stop infected computers from continuing to spread the Coreflood virus, according to court records. This week, the DOJ and FBI seized five servers that controlled Coreflood-infected computers, the DOJ said in a press release. The agencies also seized 29 domain names used by the Coreflood botnet to communicate with the servers."
Not anymore...
What is the price of one piano compared to the terrible crime that's been committed here?
For justice, we must go to Don Corleone
The Connecticut criminal complaint said a Michigan real estate company lost more than $115,000 to fraudulent wire transfers because of the Coreflood virus. A South Carolina law firm lost more than $78,000, and a North Carolina investment company lost more than $151,000, the complaint said. A defense contractor in Tennessee lost more than $241,000 due to the botnet, the complaint said.
Emphasis mine. I wouldn't expect any less out of firms like this first of all. They really need to change the keyboarding classes in high-school to teach basic do-not-download-stupid-shit classes. And second of all, FTA:
"Botnets and the cyber criminals who deploy them jeopardize the economic security of the United States and the dependability of the nation's information infrastructure," Shawn Henry...said in a statement.
Obviously, the internet is now truly Serious Business. DHS, Ice-Raids, I hate to say it but as other /.ers have said in the past, we are entering the downward slope of the golden age of the internet, the gub'ment is now all up in our intertubes for good. Hide yo pron hide yo second life.
'We are trying to prove ourselves wrong as quickly as possible, because only in that way can we find progress.' RPF
ok, being a u.s. national issue, is this an all-american botnet?
This is a total waste of time.
Half the ones they seize are innocent bystanders. The rest are replaced for $16 bucks at some sleezey registrar. Probably most are simply
decoys and the ones of real importance are out of country.
Perhaps the Defense contractor whined, and that finally got the Fed's attention, but it seems to me that various private initiatives (like those by Microsoft and others) have been way out ahead of this.
Why not audit that Defense Contractor's IT procedures and practices. A bot net owning one of their boxes? Seriously?
Sig Battery depleted. Reverting to safe mode.
I haven't found the order itself, but the request is here
If that's what they were granted, it looks remarkably restrained. It actually specifies the servers in question (it's not just a blanket "We get to grab anything we claim is a C&C server, now or in the future").
The part the article seems to be going on about is "A permanent injunction that requires the Defendants to uninstall Coreflood on any computers not owned by the Defendants and authorizes the operation of a substitute command and control server to give effect to the Court's orders;" This is pretty radical, in that it lets the FBI operate the botnet at least in so far as to shut it down. But it doesn't give them any authority over computers which aren't already infected.
DoJ? Pssh, those guys are too bogged down in red tape.
We should leave this matter to DoD. Instead of deploying the drones in Pakistan, we should target the botnet controllers instead. If we're gonna do extrajudicial killings, might as well target people who actually harm the country.
Seriously. This is like taking aspirin for a cold. Doesn't cure anything but makes everyone feel better (except for the side effects, of course). Since they know about it, why not take the step to track down and arrest the 'money' behind it? Seems to me this is grandstanding rather than serious crime busting. And... if they want to do it properly, don't be stupid! Don't tell them you are coming!
The truly loyal subject will neither advise nor submit to arbitrary measures
This is essentially saying the security of the ISC itself is now unequivocally compromised by the Feds. Before, they had to at least pretend it wasn't.
I wonder if a DA can convince a Judge that TOR or Bittorrent are "criminial botnets".
Internet Systems Consortium or other ISPs
Since when is the ISC an internet service provider?
"Internet Systems Consortium, Inc. (ISC) is a non-profit 501(c)(3) public benefit corporation dedicated to supporting the infrastructure of the universal connected self-organizing Internet—and the autonomy of its participants—by developing and maintaining core production quality software, protocols, and operations." Other than hosting a few Open Source projects, the ISC doesn't act as an ISP to the best of my knowledge.
I guess they mean something to do with the F-root server at ISC and redirecting DNS requests for the control servers? Color me confused, and TFA isn't helping.
hide ur laptops, hide ur PCs, becuz theyz hacking ev'body up in here!
.. they need to steal someone else's botnet to do their spying now?
Just curious..
Insert
For THAT the executive branch seeks approval of one of the other two branches, yet when it comes to real physical war, that, you know, kills people, they do not feel the need.
I do not believe in karma. "Funny"=-6. Do good and forbid evil. Yours, Oft-Offtopic Flamebaiting Troll.
Apparently the defective software that permitted the viruses to run is sold out of Ireland (through the Netherlands and Dutch Antilles in an accounting blind called the "Irish Double-Dutch") by a company headquartered in Redmond, Washington, USA. Many Bothans died to bring you this information.
Help stamp out iliturcy.
Next you'll say the Internet itself was a DoD skunkworks project from ARPA. Who would believe that? Time to loosen the tinfoil hat.
Help stamp out iliturcy.
Amazing, the US government asking permission instead of forgiveness?
Maybe they will start getting warrants for wiretaps next, we can only hope.
Every morning I have to go through the quarantined spam looking for false positives. I've done this for MANY years now.
There are some days where the spam is wayyy down. Why? I usually can't tell. I did see it drop a little over a year ago when a large botnet was shut down (a US data center was taken off line, if I remember correctly).
In the last couple of days, we've had half the number of spam emails. That's a pretty significant reduction!
COREFLOOD C&C SERVERS + BOGUS NAME SERVERS LIST:
---
0.0.0.0 accounts.nethostplus.net
0.0.0.0 acdsee.licensevalidate.net
0.0.0.0 ads.antrexhost.com
0.0.0.0 a-gps.vip-studions.net
0.0.0.0 brew.fishbonetree.biz
0.0.0.0 cafe.antrexhost.com
0.0.0.0 coffeeshop.antrexhost.com
0.0.0.0 dru.realgoday.net
0.0.0.0 exchange.stafilocox.net
0.0.0.0 f1u.medical_carenews.org
0.0.0.0 imap.nethostplus.net
0.0.0.0 iogon.nethostplus.net
0.0.0.0 ipadnews.netwebplus.net
0.0.0.0 iu.medical_carenews.org
0.0.0.0 jane.unreadmsg.net
0.0.0.0 logon.nethostplus.net
0.0.0.0 marker.anlrexhost.com
0.0.0.0 mediastream.nethostplus.net
0.0.0.0 medical_carenews.org
0.0.0.0 medicalcarenews.org
0.0.0.0 ns1.cyberwatchfloor.com
0.0.0.0 ns1.diplodoger.com
0.0.0.0 ns2.cyberwatchfloor.com
0.0.0.0 old.antrexhost.com
0.0.0.0 onlinebooking.nethost.plus.net
0.0.0.0 onlinebooking.nethostplus.net
0.0.0.0 pop3.nethostplus.net
0.0.0.0 savupdate.1icensevalidate.net
0.0.0.0 schedu1es.nethostplus.net
0.0.0.0 schedules.nethostplus.net
0.0.0.0 spamblocker.antrexhost.com
0.0.0.0 taxadvice.ehostville.com
0.0.0.0 taxfree.nethostplus.net
0.0.0.0 ticket.hostnetli_ne.com
0.0.0.0 ticket.hostnetline.com
0.0.0.0 vaccina.medinnovation.org
0.0.0.0 vaccina.medinnovation.org
0.0.0.0 wellness.hostfields.net
---
Add those, as they are, to your local HOSTS file (in Windows, that's under %Windir%\System32\drivers\etc & Linux it's under your home user etc folder) & you're all set (you can't touch them, & they cannot "talk back to mama/communicate" back to said C&C servers...).
The person whom you replied to's link to this information led me to the actual .pdf files where this information is stored and yes, is publicly available too... I got it from the scanned .pdf files of the gov't.'s request to shut those servers down, & until they do? Protect yourself.
(I already had them in my HOSTS file, I verified said list against it to see IF I HAD THEM ALL, & luckily, I did... so, myself, my family, & my friends who use the HOSTS file I have with over 950,000++ known bad sites/servers/hosts-domain names blocked out in it, worked to protect they, AND myself, already, vs. this malicious threat COREFLOOD!)
APK
P.S.=> Alternately, you can add rules into your firewall rules table but, minus the leading "0.0.0.0" blocking "IP Address"!
(Doable in software firewall in Windows, or IPTables in Linux for example)
You can block them that way too...
OR
IF you have a firewalling router? Those also usually have entries for blocking in their interface for setup also (Linksys units, for example, do)...
I personally just find that editing a text file, HOSTS, is simpler/faster/easier to do (and portable easily across computers & even Operating Systems that use a BSD based IP stack - even ANDROID phones can use HOSTS, because they're a LINUX derivant, in fact...) ...apk
District of Connecticut?.......Wha? Is that near the general vicinity of New Yorkland?
So, today the feds are going after botnets. How will they eventually distort this in the future to go after you?
Is AFcore/Coreflood an XP only threat? Can it also infect Windows 7machines?
We would not have botnets and all this bullshit, 419, boiler houses, politicians changing minds, starting wars stealing oil etc the world is a peaceful place and I would cook food for people less fortunate than me, help children men and women. These cunts have destroyed society, so do not be fooled. I am a humanitarian. Ask yourself the question where do you stand?