Bad Guys Use Open Source, Too
First time accepted submitter colinneagle writes "Open source has been so successful in giving us software like Linux, Apache, Hadoop, etc., why wouldn't the open source method work with other types of software? Probably no one expected that the criminals behind vast malware trojans would adopt open source methods to make their malware more dangerous, but they have. According to this report from Seculert Research, the makers of Citadel, a variant of the Zeus Trojan are using open source models to hone their code and make the Trojan more dangerous."
Their grammar's great, too.
-
>> Bad Guys Are Use Open Source, Too
All your base are belong to us
...Malware writers are using *gasp* coding to further their goals?!? Horrorz!
Consistency is only a virtue if you're not a screw-up.
Sure but what license are they using? I make sure all my malware is GPL3. None of that BSD licensed malware for me!
Are they do?
You can't handle the truth.
I guess the "takeaway" from this is that trying to produce working code with .Net or PowerShell is well-nigh impossible.
https://app.box.com/WitthoftResume Code: https://github.com/cellocgw
Why should only the criminal side of the malware equation get the benefits of open-source?
Do you speak it?
(Seriously - wtf is up with the article title? EDITORS DO YOUR JOB.)
Sort of anyway? Seems to that the networks of hackers and bad guy developers has always been sharing notes and code, and that this technique has long been used as an "intelligence amplifier" allowing a loose collection of bad guys who couldn't or at least didn't get real jobs to create some powerful malware tools. Which are often then used by someone else with slightly less coding sense and much more ambition to make some money, and to spread the idea of making money this way to others. The whole industry is a lot like multi-level marketing that way.
Probably no one expected that the criminals behind vast malware trojans would adopt open source methods to make their malware more dangerous, but they have.
That's just idiotic and the whole article reads as an advertisement for Seculert
that's like saying HEY bad guys use forks and kitchen utensils too
PANICK NOW
what is with the world and retard posts.....
To fit in with the Title, I formatted the rest of the post for your bleeding eyeball convenience: "Our software, such as Linux, Apache, hadob, and so forth, why open source won't work for other types of open-source software successful? Maybe a Trojan malicious programs opened behind the expected big criminals"
Bad Guys Also Use Closed Source Model! Bad Guys Even Use Software and Hardware! Bad Guys Breath Oxygen and Some Piss in Urinals. Ban all these evil tools of the bad guys!
In order to make sure that all computers are safe from the cancerous open source software movement which is obviously only useful to terrorists, pedophiles, hackers and pirates, an amendment will be added to SOPA legislation declaring all Open Source Software as illegal to posses, create or distribute. Anyone caught using open source software is obviously a terrorists, pedophile, hacker or pirate.
Thank you
The **AA controlled Congress of the United States
As long as they share their code with as many people as possible, it's all good. I wonder if they get Hans Reiser to sign-off their code?
this open source thingie is used for writing malware!! someone must stop them, all opensource must be deemed illegal, and richard stallman should be prosecuted for aiding criminals. if you don't believe me, go ask microsoft, they'll agree with everything i just said.
my sig pwns your sig
Is there a story in here somewhere?
Criminals are usually stupid, but eventually even they start to use modern methods. Nothing new or surprising.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
GUNs don't kill people, GNUs kill people!
When information is power, privacy is freedom.
... has gone to plaid.
I have four mod points left, but I am unable to find a post worth modding up or down. I think slashdot is about done. I haven't figured out reddit, yet. Is there anything else worth logging onto?
Their they're doing there hair.
Petty criminals are usually stupid (or just desperate).
There are lots of criminals that are smart, ripping people off every day, and not getting caught.
Or they just happen to be the ones funding the legislators.
Okay so some "bad guys" use open source software to improve there destructive ability. How many "bad guys" use closed source software to improve there destructive ability.
Use LGPL3, that way if it infects a proprietary executable it won't be a license violation.
When Argumentum ad Hominem falls short, try Argumentum ad Matrem
Bad guys use the toilet too. They also eat and sleep and such, and we could argue that this does indirectly help them make better malware. So?
Why wouldn't anyone have expected the bad guys to do this? They've been doing it for decades already. Back when it was dial-up BBS systems, the bad guys had BBS networks of their own with download libraries full of code and discussion boards full of people discussing and refining their techniques and making their viruses better. As programming and development methodologies have evolved, why wouldn/t we expect programmers and developers on the bad side would adopt them just like any other programmers?
1. Release a strict GPL-licensed virus (along with source offer and all)
2. Make it infect your target's executables
3. Sue them for license breach!
4. Profit!
See? I did away with those pesky '???' bits!
Ya, no shit. I need an aspirin.
The author is right, nobody would have ever thought that the kind of people who lurk in the computer underground would ever use open source tools or methods to develop their malware. We all thought that "those people" were paying Microsoft for copies of Visual Studio and writing all of their code based explicitly on MSDN code samples.
Hey there Mr. Software Expert.
"Probably no one expected that the criminals behind vast malware trojans would adopt open source methods." Only a NetworkWorld writer wouldn't suspect that.
Even with the tremendous growth and availability of tools, the number of people worldwide that write code beyond the "hello world" level is still tiny. The people who write new code is a small fraction of that. The people who write functional new code is, yet again, another small subset.
Out of that tiny group of people, the number of people who understand systems well enough to write new and functional code that does anything significant is miniscule. ALL of your significant malware writers are software developers that are already part of that group.
It isn't that malware developers are some separate group of evil-doers who sprout up independently, like there is a special Malware developer factory somewhere. THEY ARE SOFTWARE DEVELOPERS. Not expecting them to use open source takes a degree of ignorance that is staggering.
You wear Trojans to *protect* from viruses.
Maybe they are the good guys, underdogs just trying to get by in a world that keeps pushing them down. You don't think people are going to fight back once they have been pushed around long enough?
Inject the terms open-source and malware into the blogosphere. Under no circumstance mention Microsoft Windows ...
Criminals, CRIMINALS I SAY ! Drive cars, ride on the bus right beside us, eat food, sleep and defecate just like regular people. Call on God or the wizard of Oz to do something. Please. Please. Oh woe. Oh woe we are doomed, so doomed. Oh grievous despair...
Russian hackers have accepted EUR800,000 in donations from customers of Nordea, Sweden's largest bank, after a sophisticated "phishing" campaign recruited customers into downloading a Trojan horse program that recorded their account login details.
The Russians had looked up the definition of "hacker" in the Jargon File and been inspired to leverage the creative power of open source Free Software. The first campaign took place in August 2006 and was detected a month later, having affected around 250 Nordea customers.
The emails claimed to be from the Nordea Open Trojan Foundation, telling recipients to install an anti-spam and donation tool. Their computers were then infected by the Trojan HaxDoor.RMS.w32, which installs itself in C:\WINDOWS\SYSTEM32 and sends your passwords to its creators, but only after you have read through and accepted the GNU General Public License and checked the README file for known problems. The email also included full source code.
Swedish police traced the attacks to Russia by looking at the contact details, including address and phone number, included in the README. They have filed over 100 bugs on the creators' SourceForge project and joined the mailing lists on the grass-roots marketing and publicity site SpreadHaxDoor.com.
A Nordea spokesman said the attacks have "quietened down" after the initial influx last Autumn. "We are constantly looking at the security of our online banking and many different measures are taken. We are updating our systems behind the scenes. Many already run on enterprise Linux distributions, but we will be moving desktops to Linux as well for more efficient funds transfer with less reverse engineering required, and may recommend that our customers do the same."
The Trojan only affects computers running Windows. "For unsupported platforms, we have an 'honor system' which gives our details so you can send some money in," said a spokesman for the hacker group. "We hope this will help and encourage contributors interested in porting the Trojan to other operating environments."
Photo: The penis on the 2 Eurocent coin.
http://rocknerd.co.uk
every related article I've ever seen on this site talks about how governments at all levels REFUSE to even consider OSS - what's changed?
do the TSA's strip search machines run Linux?
Can't wait for the CUDA and OpenCL virus packages.
Windows Anti-Virus 2015 Supercomputer Edition
Controversy and "negative" stories like this tend to stick in folks minds. Once, when I told an acquaintance of some years that I worked on Linux they asked if I was a criminal because they'd heard that criminals use Linux. So, as much as these stories are true, be wary of folks who trumpet them because they may be trying to tar-and-feather your community.
When you're holding the moon for ransom, you value stability in an application. Linux gives us the power we need to crush those who oppose us.
That's a bit worse than malware.
It's beyond idiotic. This kind of language might have been appropriate in OMNI in 1978 to describe an outburst of creative thinking by Robert Trivers in the early 1970s.
It would also have been appropriate in the same issue of OMNI to run an article about a race of beings—not nearly so clear thinking as Robert Trivers—who survive by drinking the fear of others.
http://blog.seculert.com/2012/02/citadel-open-source-malware-project.html