The Internet's Public Enemy Number One

Moderators: Moderator, Global Moderator

Post Reply
NightStorm
Administrator
Administrator
Posts: 778
Joined: Mon May 17, 2004 4:05 pm

The Internet's Public Enemy Number One

Post by NightStorm »

[url=\"http://www.pcworld.com/article/id,138694/article.html?tk=nl_dnxnws\"]Source[/url]

[b][size=5]The Internet's Public Enemy Number One[/size][/b]
[b]The Storm Worm has infected so many machines that it's now one of the most powerful supercomputers.
Erik Larkin, PC World[/b]
[i][color=\"#808080\"]Wednesday, October 24, 2007 11:00 AM PDT[/color][/i]

A vastly powerful new supercomputer is on the loose. With more than a million CPUs and a petabyte of RAM, it completely dwarfs its next-largest competitor, IBM's BlueGene/L, which contains a paltry 128,000 processing cores and 32 terabytes of memory. And the new supercomputer is growing larger every day.

There's just one problem. This powerhouse isn't run by a university, or IBM, or a government agency. It's the Storm Worm botnet, capable of sending staggering amounts of spam and viruses around the globe, and launching devastating attacks against security researchers or anyone else who might oppose it.

A botnet (short for "robot network") is a corralled network of computers that are infected by bot malware and can be remotely controlled by a single individual. Estimates vary, but security researchers believe that the Storm Worm has anywhere between 1 and 10 million PCs unwillingly dancing to its tune.

[b]Tops in Hardware [/b]
Peter Gutmann, a computer scientist with the University of Auckland in New Zealand, notes that real supercomputers would likely outperform Storm's distributed network in traditional supercomputer benchmarking. But "where Storm leaves every conventional supercomputer in the dust is in terms of the sheer hardware resources (number of CPUs, amount of memory, and network bandwidth) at its disposal," he wrote in an e-mail.

Those network connections, likely numbering in the millions, are the most valuable resources for the crooks behind Storm. Botnet controllers, or "bot herders," sell their botnets' spam-sending or Internet attack services for a fee on the Internet underground. The more PCs and network connections a botnet has, the more spam or denial-of-service attack traffic it can send, and the more money it can make.

Who's behind the Storm Worm? No one knows for sure. Researchers at Finnish security firm F-Secure believe, for a few reasons, that the masterminds are Russian. They use a domain and host out of the notorious Russian Business Network. Inside their code, they refer to their hatred of Moscow-based security firm Kaspersky Lab. And some of their software uses the word bydloshka, which F-Secure researchers believe is a derivative of [i]buldozhka[/i], a Russian term of affection that translates roughly to "bulldog."

[b]Cunning Defense[/b]
Whoever is controlling the massive botnet is managing its spread and defense with great sophistication. They frequently change the well-crafted e-mail messages that trick users into installing the virulent bot. When the alert went out about a late-summer wave of [url=\"http://www.pcworld.com/article/id,136039/article.html\"]fake e-card notes[/url], Storm e-mail in September shifted to messages that pretended to promote Tor, a legit anonymous-surfing application. The [url=\"http://blogs.pcworld.com/staffblog/archives/005357.html\"]fake Tor e-mail[/url] used text and images from the actual Tor Web site, but any recipient who followed the download link and double-clicked the resulting tor.exe file installed Storm.

And once it has control of a PC, Storm will fight to maintain it. According to Paul Sop, CTO of Prolexic, which defends business clients against the type of Internet attacks that botnets launch, security researchers who investigate Storm-infected machines can expect swift retaliation.

"The Storm Worm [botnet] has the ability to defend itself," Sop explains. "When you scan it, it will tell another portion of the botnet to DDoS you." In a DDoS, or distributed-denial-of-service attack, a bot herder instructs some or all of the botnet to send a flood of garbage data to a particular victim. And often that flood is enough to knock a Web site offline, or to take down a researcher's Internet connection.

[b]Unique Defense[/b]
Storm is the only botnet Sop knows of with this kind of automated self-defense. What's more, it's sneaky about how it executes that defense. It won't launch the attack from the same machines that are scanned, or even ones with similar IP addresses, since that would make the attack's cause immediately apparent. Instead, it passes along the researcher's location to other parts of the Storm botnet, so the DDoS attack appears to come from somewhere else.

The Storm Worm has become so ubiquitous, it's even a star on YouTube, where an [url=\"http://www.youtube.com/watch?v=kH8cS1AkqiI\"]F-Secure video[/url] that shows the worm's spread around the globe has been viewed more than 850,000 times. (Check out the comments, where you'll find some viewers who are convinced that the worm was created by extraterrestrial forces.)

To help ensure that you don't become the next cog of the vast Storm Worm wheel, use a good antivirus program, and keep your applications up-to-date. The Storm Worm and other such malware frequently exploit known holes in old versions of software such as Internet Explorer, Firefox, QuickTime, and even WinZip to infect PCs.

Also, exercise extreme caution with any unsolicited e-mail, even if it appears to come from someone you know. And finally, to help determine whether your computer might have already joined the ranks of the living dead, see "[url=\"http://www.pcworld.com/article/id,134988/article.html\"]Proper ID for a Zombie PC[/url]."
[align=center]Image



[gamertag]NightStormDraco[/gamertag]

[twitter]NightStormDraco[/twitter]

[/align]
Marko
Global Moderator
Global Moderator
Posts: 960
Joined: Thu May 20, 2004 7:12 am

The Internet's Public Enemy Number One

Post by Marko »

I still don't understand how people get sucked in to opening these types of emails. In fact why bother reading them at all? All the emails that I get that are not from someone that I know get deleted straight away. Furthermore why would you go and click on download links from 'people' that you don't know in the first place?
Image
NightStorm
Administrator
Administrator
Posts: 778
Joined: Mon May 17, 2004 4:05 pm

The Internet's Public Enemy Number One

Post by NightStorm »

The Internet is full of fools. How else could we have been under attack for several years? The bot code that was used against us was so simplistic that there should have been no logical reason for the botnet to expand beyond a few dozen... the entire spread could have been blocked by a firewall (even Windows Firewall) and common sense. I won't even bother to mention the spreading he was doing throguh BitTorrent...
Seems that botnets are the new kiddie playtoy... it's about who can have a bigger one (my guess, they are trying to make up for lacking in "other" areas).
[align=center]Image



[gamertag]NightStormDraco[/gamertag]

[twitter]NightStormDraco[/twitter]

[/align]
Sylo-X-
Sr. Member
Sr. Member
Posts: 410
Joined: Wed Jul 21, 2004 5:52 am

The Internet's Public Enemy Number One

Post by Sylo-X- »

You would think people would learn though. There have been a few viruses that have gotten airtime on evening and morning news shows and on these news shows they warn internet users about infected e-mail attachments and urge users not to download anything from someone that they dont know. It amazes me how its spread as much as it has. But on a different note the coding must be amazing for it to have self defense measures like it does.
Image

I would love to change the world, but they won't give me the source code =(

My Killa Blog
Post Reply

Return to “Security”