Top Stories
|
Storm Worm of a thousand faces21 Aug 2007 20:59 Mutating malware hits cat lovers, music freaksFire vs. FireBy Anonymous Coward
Posted Tuesday 21st August 2007 21:39 GMT
Time for someone clever to capture the Storm applet, disassemble it, and modify it a bit - so that it commits a DDoS on the botnet heerder. Then re-release it into the wild. Yes, that's illegal. So let the NSA do it, they don't seem to have any problem with breaking laws. I'm no expert butBy John Watts
Posted Tuesday 21st August 2007 22:35 GMT
Perhaps it will implode itself. Since there's no point in infecting an already infected machine I'd imagine it checks for itself. I'd guess it might do that by scanning potential hosts for itself to make sure it's not already there, which might eventual result in it DoS itself to death. With any luck it will disappear up its own arse. This wisdom comes with the aid of a bottle of cheap wine so I excuse myself for any implicit stupidity. Like I say, I'm no expert; but the most virulent of real (biological) viruses tend to wipe themselves out, so we can but hope. Re: I'm no expert butBy Misha Gale
Posted Wednesday 22nd August 2007 00:03 GMT
Sorry John, the vino has let you down. Storm doesn't spread directly host-to-host but by old fashioned email. So all it is likely to DoS are mailservers. Granted, if it drags down all the mailservers on the net it will stop spreading, but this won't be much comfort. Seriously though, researchers have been saying for years that AV companies need to move away from signatures. I can recall reading in this very organ an article advocating a whitelist approach rather than blacklisting known virii some years ago. Now we have polymorphic malware in the wild, and if the technique becomes widespread and sophisticated then conventional AV will be basically useless. Doh!By Ian McNee
Posted Wednesday 22nd August 2007 00:10 GMT
Same old story - have all the fancy security software you like but if you fail to engage your brain before you click...oops...pWn3d! This needs to stopBy Alan Donaly
Posted Wednesday 22nd August 2007 00:28 GMT
I get sick of law enforcement doing nothing about this sort of thing and spending all it's resources busting chip moders and other "violent criminals" I call bullshit on them if they say they can't find out who is responsible and burn them alive like they deserve. Easy to stop itBy Anonymous Coward
Posted Wednesday 22nd August 2007 01:03 GMT
Go into your spamassassin config, find the rule called "NORMAL_HTTP_TO_IP", change it's score from 0.7 (default) to 5000. restart spamassassin. done. I have done this on all the mail servers I take care of and none of my clients have any idea what all the fuss in the press is about. easy Binary AstraMetaPhysicsBy amanfromMars
Posted Wednesday 22nd August 2007 07:04 GMT
And when malware slips into something more comfortable and morphs into palware will it be embraced as Viable Open Source Servering to Community rather than Ego? Will its ID grow into AI Super Ego? Power with ever more Self Control.... to Plan a Stellar Path of Immaculate Choice? Shooting FishBy Stephen Meredith
Posted Wednesday 22nd August 2007 07:56 GMT
Looking for ways of blocking or removing the worm is like shooting fish.. better to ensure that the network is protected from DDoS using something like www.webscreen-technology.com to filter out the attack traffic and pulling the rug from under the spammers! Easy indeedBy Andrew Steer
Posted Wednesday 22nd August 2007 09:02 GMT
Just block all shortish emails bearing all-numeric http references. In procmail: # Catch-all for spam with numeric URLs - 18 Aug 2007 :0B: * <8000 * http://[0-9][0-9]?[0-9]?\.[0-9][0-9]?[0-9]?\.[0-9][0-9]?[0-9]?\.[0-9][0-9]?[0-9]? spamnumerichttp Good callBy Anonymous Coward
Posted Wednesday 22nd August 2007 09:29 GMT
Obviously not for everybody, but that is a cracking idea Andrew, thanks. @ amanfromMarsBy Anonymous Coward
Posted Wednesday 22nd August 2007 10:59 GMT
Anyone know who this complete twat is? More Roadblocking IdeasBy Sabahattin Gucukoglu
Posted Wednesday 22nd August 2007 12:50 GMT
You can stop these mails just as you would stop any other mails originating from nonconformant mailers. OTOH, greylisting seems to be losing its effectiveness (well, duh, of course it is). I use an absence of MX record to stop them coming to my primary account, but they still get through forwarders. Here are a couple of other ideas ... 1. Fuzzy checksum the emails. Sure the binaries are morphing all the time, but surely all these emails have similar form? Haven't checked yet, but I'd be willing to bet Vipul's Razor can detect all major variants of these by now. Perhaps the AV industry should focus more on the vector and less on the actual payload. ClamAV has a good general-purpose scanning engine too, perhaps it could be adapted to scan vanilla plaintext emails for these telltail signs? Would be great for the milter interface - could reject the DATA outright (554 5.7.0 Go away, you f**king moronic end-luser.) 2. Internet mail is abused again. So how long is it before port 25 blocking becomes mandatory? I don't mind at all, provided that I can immediately and easily unblock myself without question. It goes without saying, of course, that the process requires authentication and can't easily be automated by a computer program, although I suspect that wouldn't be too long in the works before the VXers break that, too. Cheers, Sabahattin Well, I *am* an expertBy Dr. Vesselin Bontchev
Posted Wednesday 22nd August 2007 12:57 GMT
(Google me, if you don't believe it.) This thing is a Trojan. It doesn't spread by itself at all - not by e-mail, not by any other way. It gets *sent* to the victim by the attacker. However, the "attacker" is just a compromised luser machine - part of a botnet used to send other kinds of e-mail (like spam), too. Attacking it is of no use. The e-mails themselves contain an URL to a site where the malware resides. However, this is usually just a compromised site, too, so attacking it isn't of much use, either. At best, it's worthwhile contacting the webmaster, although sometimes the webmaster doesn't care. Sometimes the hosting sides use fast-flux DNS to disguise themselves, so getting hold of the particular host can be tricky. As for those who think that "signature-based" (a *very* inaccurate term) scanning is helpless against this thing - see this ("Nuwar" is an alternate name for this very same family of Trojan horses): http://www.avertlabs.com/research/blog/index.php/2007/08/15/keeping-up-with-nuwar/ Regards, Vesselin @ I *am* an expertBy Matt W
Posted Wednesday 22nd August 2007 15:55 GMT
Well, I'm reassured that experts, ostensibly with a doctorate, use terms like 'luser'. Go forth and multiply, troll. Same old storyBy Sceptical Bastard
Posted Wednesday 22nd August 2007 17:09 GMT
"... the success of Storm relies on the ability to dupe recipients into clicking on links and installing programs..." Says it all, really <sigh> Virtual Application .By amanfromMars
Posted Wednesday 22nd August 2007 17:48 GMT
Hi, Doc [Dr. Vesselin Bontchev], Does the response here tell you how easy it is to hide the Truth in the Open? Are you into Virtualised TelePortation within Quantum Communications Channels PGP2 Programming for Transparent Security? ....The Movement of IDers to Realisation Centres? Re: Same old storyBy Anonymous Coward
Posted Wednesday 22nd August 2007 20:52 GMT
Isn't it? Dozens of postcards, the last two sent by my parents from beyond the grave, were followed by emails from four strangers who claimed to know me well enough to want to provide links to pornographic pictures. Then I got membership details for four sites that somehow I can't remember signing up for. All variantions on the same theme. IP-based URLsBy Dr. Vesselin Bontchev
Posted Friday 24th August 2007 06:28 GMT
Oh, BTW, those who proposed to block e-mails with IP-only URLs in them - the authors of these Trojan horses seem to have heard about this approach, too, and have changed their creation so that the approach no longer works: http://feeds.feedburner.com/~r/McafeeAvertLabsBlog/~3/147411266/ The period for commenting on this story has finished |
Breaking Hardware News
Dell has announced it's incorporating touch-screen functionality - in the form of an easy-to-install firmware upgrade - on it's Latitude XT tablets.
Newsletter |