Computer Experts Unite to Hunt Worm

N

Nehal

The Powerstick comes with nine connectors for use with Apple iPod/
iPhone, Sony Ericsson, LG, Samsung, micro USB, mini USB, Nokia and
Palm Treo. ...... supplying Symbian phones such as Sony Ericsson,
Samsung and LG. Google has the Android Market for the T-Mobile G1 and
the soon to be released HTC Magic. ...Examples are the LG Vu and
Samsung Eternity sold by AT&T and the LG Voyager sold by Verizon
Wireless. AT&T's flagship phone, the iPhone from Apple
(Nasdaq: ...After making a large impact in the music player market
with the Apple iPod, Apple entered the growing mobile market. In 2007
Apple entered the mobile market ...No TV or computer? There are mobile
offerings on iPhone and iPod are now available, plus AT&T and
Verizon Wireless video products. ...Samsung heeft op het Mobile World
Congress de Samsung Omnia HD aangekondigd; een telefoon met een groot
3.7 inch touchscreen-display en de mogelijkheid om ...<img href=
"http://farm4.static.flickr.com/3631/3381657574_7b70cb9259.jpg"/>
 
A

Agile Consulting

Computer Experts Unite to Hunt Worm

March 18, 2009

nytimes.com/2009/03/19/technology/19worm.html

An extraordinary behind-the-scenes struggle is taking place between
computer security groups around the world and the brazen author of a
malicious software program called Conficker.

The program grabbed global attention when it began spreading late last
year and quickly infected millions of computers with software code that
is intended to lash together the infected machines it controls into a
powerful computer known as a botnet.

Since then, the program’s author has repeatedly updated its software in
a cat-and-mouse game being fought with an informal international
alliance of computer security firms and a network governance group known
as the Internet Corporation for Assigned Names and Numbers. Members
refer to the alliance as the Conficker Cabal.

The existence of the botnet has brought together some of the world’s
best computer security experts to prevent potential damage. The spread
of the malicious software is on a scale that matches the worst of past
viruses and worms, like the I Love You virus. Last month, Microsoft
announced a $250,000 reward for information leading to the capture of
the Conficker author.

Botnets are used to send the vast majority of e-mail spam messages. Spam
in turn is the basis for shady commercial promotions including schemes
that frequently involve directing unwary users to Web sites that can
plant malicious software, or malware, on computers.

Botnets can also be used to distribute other kinds of malware and
generate attacks that can take commercial or government Web sites off-
line.

One of the largest botnets tracked last year consisted of 1.5 million
infected computers that were being used to automate the breaking of
“captchas,” the squiggly letter tests that are used to force applicants
for Web services to prove they are human.

The inability of the world’s best computer security technologists to
gain the upper hand against anonymous but determined cybercriminals is
viewed by a growing number of those involved in the fight as evidence of
a fundamental security weakness in the global network.

“I walked up to a three-star general on Wednesday and asked him if he
could help me deal with a million-node botnet,” said Rick Wesson, a
computer security researcher involved in combating Conficker. “I didn’t
get an answer.”

An examination of the program reveals that the zombie computers are
programmed to try to contact a control system for instructions on April
1. There has been a range of speculation about the nature of the threat
posed by the botnet, from a wake-up call to a devastating attack.

Researchers who have been painstakingly disassembling the Conficker code
have not been able to determine where the author, or authors, is
located, or whether the program is being maintained by one person or a
group of hackers. The growing suspicion is that Conficker will
ultimately be a computing-for-hire scheme. Researchers expect it will
imitate the hottest fad in the computer industry, called cloud
computing, in which companies like Amazon, Microsoft and Sun
Microsystems sell computing as a service over the Internet.

Earlier botnets were devised so they could be split up and rented via
black market schemes that are common in the Internet underground,
according to security researchers.

The Conficker program is built so that after it takes up residence on
infected computers, it can be programmed remotely by software to serve
as a vast system for distributing spam or other malware.

Several people who have analyzed various versions of the program said
Conficker’s authors were obviously monitoring the efforts to restrict
the malicious program and had repeatedly demonstrated that their skills
were at the leading edge of computer technology.

For example, the Conficker worm already had been through several
versions when the alliance of computer security experts seized control
of 250 Internet domain names the system was planning to use to forward
instructions to millions of infected computers.

Shortly thereafter, in the first week of March, the fourth known version
of the program, Conficker C, expanded the number of the sites it could
use to 50,000. That step made it virtually impossible to stop the
Conficker authors from communicating with their botnet.

“It’s worth noting that these are folks who are taking this seriously
and not making many mistakes,” said Jose Nazario, a member of the
international security group and a researcher at Arbor Networks, a
company in Lexington, Mass., that provides tools for monitoring the
performance of networks. “They’re going for broke.”

Several members of the Conficker Cabal said that law enforcement
officials had been slow to respond to the group’s efforts, but that a
number of law enforcement agencies were now in “listen” mode.

“We’re aware of it,” said Paul Bresson, an F.B.I. spokesman, “andwe’re
working with security companies to address the problem.”

A report scheduled to be released Thursday by SRI International, a
nonprofit research institute in Menlo Park, Calif., says that Conficker
C constitutes a major rewrite of the software. Not only does it make it
far more difficult to block communication with the program, but it gives
the program added powers to disable many commercial antivirus programs
as well as Microsoft’s security update features.

“Perhaps the most obvious frightening aspect of Conficker C is its clear
potential to do harm,” said Phillip Porras, a research director at SRI
International and one of the authors of the report. “Perhaps in the best
case, Conficker may be used as a sustained and profitable platform for
massive Internet fraud and theft.”

“In the worst case,” Mr. Porras said, “Conficker could be turned into a
powerful offensive weapon for performing concerted information warfare
attacks that could disrupt not just countries, but the Internet itself.”

The researchers, noting that the Conficker authors were using the most
advanced computer security techniques, said the original version of the
program contained a recent security feature developed by an M.I.T.
computer scientist, Ron Rivest, that had been made public only weeks
before. And when a revision was issued by Dr. Rivest’s group to correct
a flaw, the Conficker authors revised their program to add the
correction.

Although there have been clues that the Conficker authors may be located
in Eastern Europe, evidence has not been conclusive. Security
researchers, however, said this week that they were impressed by the
authors’ productivity.

“If you suspect this person lives in Kiev,” Mr. Nazario said, “I would
look for someone who has recently reported repetitive stress injury
symptoms.”

Hi....I am also facing same problem
 
G

Greegor

Although there have been clues that the Conficker authors may be located
in Eastern Europe, evidence has not been conclusive. Security
researchers, however, said this week that they were impressed by the
authors’ productivity.

Can backbone servers filter this stuff before passing it?
Or tag it for monitoring purposes?
 
N

Nehal

The Powerstick comes with nine connectors for use with Apple iPod/
iPhone, Sony Ericsson, LG, Samsung, micro USB, mini USB, Nokia and
Palm Treo. ...... supplying Symbian phones such as Sony Ericsson,
Samsung and LG. Google has the Android Market for the T-Mobile G1 and
the soon to be released HTC Magic. ...Examples are the LG Vu and
Samsung Eternity sold by AT&amp;T and the LG Voyager sold by Verizon
Wireless. AT&amp;T's flagship phone, the iPhone from Apple
(Nasdaq: ...After making a large impact in the music player market
with the Apple iPod, Apple entered the growing mobile market. In 2007
Apple entered the mobile market ...No TV or computer? There are mobile
offerings on iPhone and iPod are now available, plus AT&amp;T and
Verizon Wireless video products. ...Samsung heeft op het Mobile World
Congress de Samsung Omnia HD aangekondigd; een telefoon met een groot
3.7 inch touchscreen-display en de mogelijkheid om ...{{http://
farm4.static.flickr.com/3431/3381772964_b3f136a6f9.jpg}}
 
B

Bluuuue Rajah

Actually it's not a bad idea if you read ALL of what was written. OP
seems to be suggesting releasing a (harmless) worm that's sole intent
is to target and destroy a nasty one. If it finds it, it kills it,
then kills itself. If it doesn't find it, it just kills itself. So
where's the problem?

It's illegal?
 
B

Bluuuue Rajah

Can backbone servers filter this stuff before passing it?
Or tag it for monitoring purposes?

Backbones have to be fast. I they tried to program them to read the data
and test it, they'd lose so much bandwidth AT&T would go bust.
 
Z

zzbunker

It's illegal?

Well, most of these idiots don't now, or have ever cared what's
legal or illegal
in any electonic systems, not just computers.
So the people with actual advanced technolgy brains just keep
making
reproducing robots, drones, AUVs for the idiots, either way.
 
O

Onideus Mad Hatter

It's illegal?

Not necessarily. Depending on its specific function and abilities the
law can be easily bent to allow such a form, especially if it were
setup to where it creates an icon say in your taskbar, which would
allow for instant removal should you click on it and press "OK" with a
dialogue box explaining what it is and what it's doing. At that point
you're still giving people an option to not have it on their system
and as such can't technically be called a worm/virus.

--

Onideus Mad Hatter
mhm ¹ x ¹
http://www.backwater-productions.net
http://www.uncensored-inter.net


Hatter Quotes
-------------
"Freedom, true freedom, is nothing more than intellectual advantage over others."

"When I listen to people I don't really listen to what it is they're
saying, so much as what they're saying it for."

"Don't ever **** with someone who has more creativity than you do."

"You're only one of the best if you're striving to become one of the
best."

"I didn't make reality, Sunshine, I just verbally bitch slapped you
with it."

"I'm not a professional, I'm an artist."

"Usenet Filters - Learn to shut yourself the **** up!"

"Drugs killed Jesus you know...oh wait, no, that was the Jews, my
bad."

"The more I learn the more I'm killing my idols."

"Is it wrong to incur and then use the hate ridden, vengeful stupidity
of complete strangers in random Usenet froups to further my art?"

"Freedom is only a concept, like race it's merely a social construct
that doesn't really exist outside of your ability to convince others
of its relevancy."

"Next time slow up a lil, then maybe you won't jump the gun and start
creamin yer panties before it's time to pop the champagne proper."

"Reality is directly proportionate to how creative you are."

"People are pretty ****ing high on themselves if they think that
they're just born with a soul. *snicker*...yeah, like they're just
givin em out for free."

"How sad that you're such a poor judge of style that you can't even
properly gauge the artistic worth of your own efforts."

"Those who record history are those who control history."

"I am the living embodiment of hell itself in all its tormentive rage,
endless suffering, unfathomable pain and unending horror...but you
don't get sent to me...I come for you."

"Ideally in a fight I'd want a BGM-109A with a W80 250 kiloton
tactical thermonuclear fusion based war head."

"Tell me, would you describe yourself more as a process or a
function?"

"Apparently this group has got the market cornered on stupid.
Intelligence is down 137 points across the board and the forecast
indicates an increase in Webtv users."

"Is my .sig delimiter broken? Really? You're sure? Awww,
gee...that's too bad...for YOU!" `, )
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3420/3384255836_464aca0c18.jpg}}
 
B

Bluuuue Rajah

Well, most of these idiots don't now, or have ever cared what's
legal or illegal
in any electonic systems, not just computers.
So the people with actual advanced technolgy brains just keep
making
reproducing robots, drones, AUVs for the idiots, either way.

Which idiots are "these idiots."
 
B

Bluuuue Rajah

Not necessarily. Depending on its specific function and abilities the
law can be easily bent to allow such a form, especially if it were
setup to where it creates an icon say in your taskbar, which would
allow for instant removal should you click on it and press "OK" with a
dialogue box explaining what it is and what it's doing. At that point
you're still giving people an option to not have it on their system
and as such can't technically be called a worm/virus.

You watch too much tv.
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3654/3386985466_edcec18730.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3585/3386205401_d39afed077.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3654/3386219029_e13d8cf900.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3654/3386219029_e13d8cf900.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3654/3386219029_e13d8cf900.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3433/3386242373_126f683703.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3433/3386242373_126f683703.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3433/3386242373_126f683703.jpg}}
 
A

Agile Consulting

Samsung is a brand of Computers, Mobiles, ipode etc{{http://
farm4.static.flickr.com/3433/3386242373_126f683703.jpg}}
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top