Microsoft Offers $250,000 Reward For Botnet Info
Orome1 writes "Microsoft decided to extend their efforts to establish the identity of those responsible for controlling the Rustock botnet by issuing a $250,000 reward for new information that results in the identification, arrest and criminal conviction of such individual(s). 'While the primary goal for our legal and technical operation has been to stop and disrupt the threat that Rustock has posed for everyone affected by it, we also believe the Rustock bot-herders should be held accountable for their actions.' Residents of any country are eligible for the reward pursuant to the laws of that country."
will successfully direct attention away from Microsoft's failure to secure their operating system?
Where's my reward?
What?
I wonder if they rake in 250k a month (or week) renting such a botnet? May start leading to some entertaining extortion...
I work for the Department of Redundancy Department.
That there's some seeeeerious cash. Obviously, it's time to form us up a posse and find these mofos. Who's in boys (and girls)??!!
Let me guess, you get the $250,000 in pennies? Or maybe you get it, only to die an hour later?
SJW: Someone who has run out of real oppression, and has to fake it.
Wouldn't it be the ultimate irony if Rustock reared up and shutdown Microsoft's reward/bounty site? If I had a spare $250k laying around I'd pay to see that.
That botnet is run by a rogue newspaper called News of The World, and the ring leader is one James Murdoch. Where do I collect my reward?
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Hiring a security team/ firm to go do it for them. But Microsoft forgets... the internet community hates you, maybe they could enlist the fine people who made Windows Vista as a reminder.
Not every problem can be solved by throwing money at it, as Murdoch has learned.
Does Micro$oft have any other resources that could be applied to the problem?
... now back to the bit mines.
a $250,000 reward for new information that results in the identification, arrest and criminal conviction of such individual(s)
I don't suppose "MS, your security sucks" would qualify as new information, although that's "who's" ultimately responsible for the success of this botnet. Oh well.
Sometimes the light at the end of the tunnel is the headlight of an oncoming train.
Focus blame on bot herders, no need to fix software problems.
Join the Slashcott! Feb 10 thru Feb 17!
You know it's gonna happen.
Maybe they give me 10$ for linking to this news.
Time for the botnet owner to cash in with some new, yet unthreatening info?
I wonder if the prize is actually 25,000 Windows XP home OEM licenses?
The money is currently tied up in Escrow after the PRINCE died, and we need your help to LIBERATE it. For your efforts, WE will pay you THE SUM OF $250000 (TWO HUNDRED AND FIFTY THOUSAND US DOLLARS).
Send your Name, Address, Social Security Number, a recent photo, and your Bank account info to:
MICROSOFT RUSTOCK INFO
C/O MR SIPHO DLAMINI
512 MAIN STREET
ABUJA, NIGERIA
Also, we will send you a free sample of our new herbal PEN?IS ENLARGEMENT system.
One wonders, are they working at all with Steve Linford and Spamhaus? If not, why not? I know of no other well-researched collection of information, nor any other man well versed in who's sending spam.
I have to applaud their strategy...let the coders doing all the work for the criminals, give in of the source code for some dough for a great relocation to some hot palm tree filled island...in the mean time giving away trade secrets belonging to the underground cybermafia....to totally devastate their revenu stream, and this will be superb! I cant wait till their start doing it.....
WARNING : Reverse Psychology Joke ahead.
The herder is my neighbor that I really dislike.
She has been spasming people with noise too much recently.
.
Can I have my 250K now ?
*ring*
- Hi, I'm Bob from Microsoft Happy Hunting Customer Care. How can I help you?
- Hi, the name of the Rustock botnet master is "John Doe". Now let's talk about the 250K$...
- I'm sorry Sir, but we already knew that, so no bucks for you. Have a nice day!
Mastering the English language is fucking easy: all you have to do is to put an f* word in every fucking sentence.
A week ago I was reading on Slashdot how the cops somewhere were claiming Microsoft had become the experts at botnet hunting. Many commentors asked what their secret was.
Well, here is it. Apparently, Microsoft is taking the Crime Stoppers approach - payoffs for tipoffs. In truth, The Red Cross or Donald Trump could apparently be just as effective. Anyone with money to throw around could.
So yeah, well done MS. If you can't beat em, buy em, right?
Bill Gates/Steve Ballmer and teams...
1 Microsoft Way
Redmond Washington
So... do I win?
</end poor attempt at humor>
StarTrekPhase2 - The Five Year Mission Continues!
The patent for Clippy is reportedly valued at $250,000.
I don't think they made the terms-of-payment very attractive to the would be informant.
They want identification, arrest and conviction. Yeah, right! Those kind of rewards never pay out.
If I could finger someone, I would not trust to see it through to conviction and get the money.
Especially if the perpetrator is in China or Russia.
Do you think it would ever lead to conviction in that case, even if the culprit is known?
Microsoft should be a lot more bold here, and award to 250K for the identification.
Or maybe even split it up: 100K for identification, 100K for arrest and 100K for conviction.
Bram Stolk http://stolk.org/tlctc/
All I do is follow the guidelines I set down here, to the letter (& not just myself, or my friends or family either... but others that have applied this guide in the link next below (some of their testimonials are quoted below in fact or they use the same type of techniques in part I illustrated)):
http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&go=&form=QBRE
And, a decade++ before it, here:
http://web.archive.org/web/20020205091023/www.ntcompatible.com/article1.shtml
(In part of its "original prototype" I started working on while adminning "the official Windows help channel" on DALNET IRC in #Windows, circa 1994-2000)
Which NeoWin picked up on & rated pretty highly circa 2001, here:
http://www.neowin.net/news/apk-a-to-z-internet-speedup--security-text
---
That guide?
It's ALL ABOUT the best thing we have currently going: "Layered Security" & User Education really (the latter IS the "main problem" along with the botnet/malware-in-general makers imo!).
* And, yes - it works... proofs thereof (small sampling, I can produce many others upon request):
SOME QUOTED TESTIMONIALS TO THE EFFECTIVENESS OF SAID LAYERED SECURITY GUIDE I AUTHORED:
---
"Ever since I've installed a host file (http://www.mvps.org/winhelp2002/hosts.htm) to redirect advertisers to my loopback, I haven't had any malware, spyware, or adware issues. I first started using the host file 5 years ago." - by TestedDoughnut (1324447) on Monday December 13, @12:18AM (#34532122)
---
http://www.xtremepccentral.com/forums/showthread.php?s=672ebdf47af75a0c5b0d9e7278be305f&t=28430&page=2
"I recently, months ago when you finally got this guide done, had authorization to try this on simple work station for kids. My client, who paid me an ungodly amount of money to do this, has been PROBLEM FREE FOR MONTHS! I haven't even had a follow up call which is unusual." - THRONKA, user of my guide @ XTremePcCentral
AND
"APK, thanks for such a great guide. This would, and should, be an inspiration to such security measures. Also, the pc that has "tweaks": IS STILL GOING! NO PROBLEMS!" - THRONKA, user of my guide @ XTremePcCentral
AND
http://www.xtremepccentral.com/forums/showthread.php?s=672ebdf47af75a0c5b0d9e7278be305f&t=28430&page=3
"Its 2009 - still trouble free! I was told last week by a co worker who does active directory administration, and he said I was doing overkill. I told him yes, but I just eliminated the half life in windows that you usually get. He said good point. So from 2008 till 2009. No speed decreases, its been to a lan party, moved around in a move, and it still NEVER has had the OS reinstalled besides the fact I imaged the drive over in 2008. Great stuff! My client STILL Hasn't called me back in regards to that one machine to get it locked down for the kid. I am glad it worked and I am sure her wallet is appreciated too now that it works. Speaking of which, I need to call her to see if I can get some leads. APK - I will say it again, the guide is FANTASTIC! Its made my PC experience much easier. Sandboxing was great. Getting my host file updated, setting services to system service, rather than system local. (except AVG updater, needed system local)" - THRONKA, user of my guide @ XTremePcCentral
AND
This is 1 way to do so (via a .bat or .cmd script loaded @ bootup in your startup group, OR, via a logon script even - this is mine here @ home (with local disks & mapped drives (minues the NET USE command though for the latter))):
NET SHARE ADMIN$ /del /del /DELETE /DELETE /del /del /del /del /del /del /del /del /del /del /del /d /y /deletevalue loadoptions /set testsigning off
NET SHARE IPC$
NET SHARE DFS$
NET SHARE COMCFG$
NET SHARE FAX$
NET SHARE PRINT$
NET SHARE C$
NET SHARE D$
NET SHARE E$
NET SHARE F$
NET SHARE G$
NET SHARE H$
NET SHARE I$
NET SHARE J$
NET SHARE K$
NET USE *
bcdedit
bcdedit
---
OR, by setting these options here, in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer
AutoShareServer = 0
AutoShareWks =0
---
OR, even simpler still? Cut the "Server" service in services.msc...
---
I do ALL 3 for "layered security protection" here... & unless you need to set allowable shares? Don't... it's a waste!
If you do??
Then - Use ACL rights on the NTFS filesystem & set access to only USERS/machines you trust-can trust etc./et al!
APK
P.S.=> If you don't NEED any of those shares, services, or features thereof of them? CUT THEM OFF to protect yourself...
E.G.-> A std. non-networked system @ home doesn't, this is certain (plus, they chew up CPU cycles, RAM, & other forms of I/O you don't really need to be using if you are not using those services features anyhow (it'd be senseless to run things you do NOT need, & by default, they're turned on so that Windows is "network ready" outta the box, mainly for business networking (but this is a potential security "downside" though too)).
Now, A funny & GOOD "side effect" of doing this, on MY part, even on a LAN/WAN @ work on the job?
Well - I can still use/access most ALL of the features I need for programming or websurfing anyhow by doing so... & funniest part is, one of my co-workers tried "hacking" my system, AND COULDN'T EVEN SEE ME ON THE WORKPLACE LAN/WAN!
I am TRULY, "the ghost in the machine/deux ex machina", setup this way on a work place LAN even... & yet, I am able to do what I needed to on the job, online & otherwise on the local network too since my system was NOT acting as a server in the first place - merely a developer's workstation-node!
This CAN adversely affect mass applied updates to Windows though, or SMS type features etc., but if you apply those yourself, as I do, manually? No problem (or you can use Windows update too!)
... apk
Need to keep an outdated graphics card to be safe.
In the distance you hear an ominous moo.
In your Local Area Connection: Cut the "Client for Microsoft Networks" IF you don't need to be setting up shares for others to use...
---
1.) Click PROPERTIES button
2.) Uncheck "Client for Microsoft Networks"
3.) Highlite TCP/IP ipv4 (or ipv6 if you use it, I don't currently)
4.) Properties Button -> Advanced Button -> WINS Tab -> Check the "Disable NetBIOS over TCP/IP" checkbox
---
* DONE!
That's helpful as well, in addition to my other "layered security" methods above:
http://news.slashdot.org/comments.pl?sid=2333542&cid=36807248
vs. the problems you folks discussed here in this thread exchange!
APK
P.S.=> Again though, read that link I put up above too... because there are a COUPLE "tiny downsides" IF you need to set shares (Then, just use your ACL settings for NTFS filesystems rights for better security then, only, & restrict it to those you wish to allow into your disks/folders/files)
... apk
Kill all the fucking perverts and Billie B. and Stevie B.
Watch their bodies burn on YouTube. : ))
--//..
"Microsoft decided to extend their efforts to establish the identity of those responsible for controlling the Rustock botnet by issuing a $250,000 reward for new information that results in the identification, apprehension and crucifixion of such individual(s).
There. That's what they should have said.
When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
Microsoft never cared about international laws before. Pursuant to the countries laws my ass.
If you happened to be a botnet owner, and you turned yourself in to Microsoft, would they pay your lawyer fees and bail as well?
Just saying, some of the smaller botnets could make a lot of money that way.....