Dutch Police Takedown C&Cs Used By Grum Botnet
wiredmikey writes "Dutch authorities have pulled the plug on two secondary servers used by the Grum botnet, a large botnet said to produce about 17% of the world's spam. According to researchers from FireEye, the backup C&C servers were located in the Netherlands, and once word of their existence was released, Dutch authorities quickly seized them. While any C&C server takedown is a win, the impact may be minimal, as the two primary servers are fully active, and the datacenters hosting them are unresponsive to fully documented abuse reports. That being said, FireEye's Atif Mushtaq noted that the botnet does has some weak spots, including the fact that Grum has no failback mechanism, has just a few IPs hardcoded into the binaries, and the botnet is divided into small segments, so even if some C&Cs are not taken down, part of botnet can still remain offline. The removal of the C&C servers shines light on how quickly some law enforcement agencies work, given that proof of their existence is just over a week old."
I'm increasingly in favour of ISPs not routing packets from any infected machine, no matter what it's infected with.
That will remove 75% of the public from the internet, you say? Fine, I say. Until the time they learn to operate a computer in the most basic of ways, the internet will be better off without their zombied boxes spewing spam and being used for DDSing.
I don't even care what OS they use. If you can't secure whatever one you pick and operate it in a safe manner, then sorry, no internet for you. We don't tolerate putting up some factory with no pollution controls and causing air quality problems for whole cities. We don't let people fly aircraft who are unqualified to do so. The internet is a public commons, and we need to stop tolerating the incompetent ruining that commons for everyone else.
>>quickly some law enforcement agencies work, given that proof of their existence is just over a week old.
Young agency?
The quality of first post trolls has really decreased in the last few years.
This may come across as pedantic, but I honestly thought that, since "takedown" is a noun, the Dutch police had takedown C&Cs that were being used by the Grum botnet (because that is what the damned headline says, so I think my confusion is understandable). "Take down", the verb, is two words, not one, and what you meant to use.
Yes, Slashdot, grammar does matter, when you try to use a noun as a verb (which it cannot be used as). And I can understand not editing the summary (who wants to do work, after all?) but the headline? Really?
"None can love freedom heartily, but good men; the rest love not freedom, but license." --John Milton
I had to look up "C&C" (for those who don't know, it stands for "Command and Control"). It's easy for me to blame the editors, submitter, etc, for necessitating this, but then again, it took just seconds to look it up. Still, it's a nuisance, and honestly in the end I think it's an art on the part of the editors/submitter to know whether or not explaining them is necessary. So, for what it's worth, as far as I'm concerned: FAILURE!
I'm surprised there's not more voluntary cooperation among ISPs to blackhole unresponsive datacenters hosting botnet command infrasturcture.
Is the money for hosting that kind of stuff that good, or is it one of those semi-political things where those data centers are in a country like Russia where the difference between organized crime and the government depends on what time of day it is?
I have a feeling that as long as the takedown of two servers, secondary servers even, is news, the herders are laughing.
The submitter's grammar 'does has' some weak spots.
Silence is a state of mime.
"Takedown" is a noun; "take down" is a verb. This headline was hard to read.
1. Announce the C&C server IPs to the world.
2. Watch Anonymous DDoS them so hard the host will have to choice but to kick them to protect the rest of their datacenter.
And the best part is that the operators of the servers have no legal recourse at all, because that would mean revealing their identities.
How do they respond to cruise missiles? Or a squad of SEALS with sachel charges? Or even just blackholing of all their IPs?
Warning: this article may contain humor, sarcasm, parody, and perhaps even irony. Read at your own risk.
Send some stealth tanks to find the source of the missiles, follow up with APCs and Tick Tanks.
Flame tanks.
Chemical missile.
If you go by the title, ("Dutch Police Takedown C&Cs Used By Grum Botnet") the Command and Control servers operated by the Dutch police for takedown purposes are being used by the "Grum" botnet.
To match the summary, it should be Dutch Police Take Down C&Cs Used By Grum Botnet. (The Dutch police have taken down the servers that the "Grum" botnet uses for command and control.)
One word: noun or adjective
Two words: verb
One space radically changes the meaning.
You mean all the other C&C servers, kiddie pr0n stashes and what not?
I was promised a flying car. Where is my flying car?
How about sending a white bunny?
I was promised a flying car. Where is my flying car?
Either that or the quality first post trollers have really decreased in speed in the last few years.
When our name is on the back of your car, we're behind you all the way!
Now where am I going to get my hyperdestructive upgradeable weaponry!? There are no Gadgetron offices in this galaxy and I really don't want to be stuck using MegaCorp's crap for self defense and taking down supervillains. Their household products are more dangerous than their pathetic weaponry! What am I supposed to protect myself with, a used B20 Crotchitizer?
"Christ what a design! I could eat a handful of iron filings and PUKE a better emergency pump than that!"
You advocate apathy! That's where You go wrong. Regarding filtering (which is better than doing zero as you seem to advocate, which in turn, makes me suspect you're a botnet master yourself actually). Blacklists and filtering are far better than your do nothing approach (which is the easiest thing to come up with, despite you stating other ideas are "so easy to come up with", I don't see you suggesting better. Yes, you're horseshit is even easier and ANY FOOL can be an apathetic do nothing that talks a lot but does nothing which you definitely show us you are ALL about). Why don't you do us all a favor and shut up, ok? Thank you.
From the article:
"In my opinion, taking down the top three spam botnets—Lethic, Cutwail, and Grum—is enough for a rapid and permanent decline in worldwide spam level," he said. "We still have to deal with small players, but I am sure that, after seeing the big players being knocked down, they will retreat as well."
Very optimistic! There's too many colo/virtual host sites out there that simply don't give a rat's ass that large swaths of their
bandwidth and IP space are being used by spammers. They're everywhere! And I've given up telling them. Even "legit" ISPs
like Integra have routinely ignored my notices in the past, so I've simply given up, I haven't the time or inclination to help any
more. They're using spammers to help pad their bottom line.
Reduced, sure, but go away? And another big botnet will appear again in the future, I have no doubt at all.