YaHooka Forums  

Go Back   YaHooka Forums > The Chronic Colloquials > Free For All
Home Register FAQ Social Groups Links Mark Forums Read

Free For All A place for thoughts and ideas that are out of place anywhere else.

Reply
 
LinkBack Thread Tools Rating: Thread Rating: 1 votes, 1.00 average. Display Modes
Old 06-30-2011, 07:47 PM   #1 (permalink)
I am different
 
Being's Avatar
 
Join Date: Jun 2006
Location: Rosamond, CA
Posts: 3,597
Thanks: 1,113
Thanked 547 Times in 351 Posts
Please, no fanboy wars

just want people to be aware

Massive botnet 'indestructible,' say researchers - Computerworld

Quote:
Massive botnet 'indestructible,' say researchers
4.5M-strong botnet 'most sophisticated threat today' to Windows PCs
Gregg Keizer

June 29, 2011 (Computerworld)

A new and improved botnet that has infected more than four million PCs is "practically indestructible," security researchers say.

"TDL-4," the name for both the bot Trojan that infects machines and the ensuing collection of compromised computers, is "the most sophisticated threat today," said Kaspersky Labs researcher Sergey Golovanov in a detailed analysis Monday.

"[TDL-4] is practically indestructible," Golovanov said.

Others agree.

"I wouldn't say it's perfectly indestructible, but it is pretty much indestructible," said Joe Stewart, director of malware research at Dell SecureWorks and an internationally-known botnet expert, in an interview today. "It does a very good job of maintaining itself."

Golovanov and Stewart based their judgments on a variety of TDL-4's traits, all which make it an extremely tough character to detect, delete, suppress or eradicate.

For one thing, said Golovanov, TDL-4 infects the MBR, or master boot record, of the PC with a rootkit -- malware that hides by subverting the operating system. The master boot record is the first sector -- sector 0 -- of the hard drive, where code is stored to bootstrap the operating system after the computer's BIOS does its start-up checks.

Because TDL-4 installs its rootkit on the MBR, it is invisible to both the operating system and more, importantly, security software designed to sniff out malicious code.

But that's not TDL-4's secret weapon.

What makes the botnet indestructible is the combination of its advanced encryption and the use of a public peer-to-peer (P2P) network for the instructions issued to the malware by command-and-control (C&C) servers.

"The way peer-to-peer is used for TDL-4 will make it extremely hard to take down this botnet," said Roel Schouwenberg, senior malware researcher at Kaspersky, in an email reply Tuesday to follow-up questions. "The TDL guys are doing their utmost not to become the next gang to lose their botnet."

Schouwenberg cited several high-profile botnet take-downs -- which have ranged from a coordinated effort that crippled Conficker last year to 2011's FBI-led take-down of Coreflood -- as the motivation for hackers to develop new ways to keep their armies of hijacked PCs in the field.

"Each time a botnet gets taken down it raises the bar for the next time," noted Schouwenberg. "The truly professional cyber criminals are watching and working on their botnets to make them more resilient against takedowns or takeovers."

TDL-4's makers created their own encryption algorithm, Kaspersky's Golovanov said in his analysis, and the botnet uses the domain names of the C&C servers as the encryption keys.

The botnet also uses the public Kad P2P network for one of its two channels for communicating between infected PCs and the C&C servers, said Kaspersky. Previously, botnets that communicated via P2P used a closed network they had created.

By using a public network, the criminals insure their botnet will survive any take-down effort.

"Any attempt to take down the regular C&Cs can effectively be circumvented by the TDL group by updating the list of C&Cs through the P2P network," said Schouwenberg. "The fact that TDL has two separate channels for communications will make any take-down very, very tough."

Kaspersky estimated that the TDL-4 botnet consists of more than 4.5 million infected Windows PCs.

TDL-4's rootkit, encryption and communication practices, as well as its ability to disable other malware, including the well-known Zeus, makes the botnet extremely durable. "TDL is a business, and its goal is to stay on PCs as long as possible," said Stewart, citing the technologies that make the botnet nearly impossible to knock offline.

Stewart wasn't shocked that the TDL-4 botnet numbers millions of machines, saying that its durability contributed to its large size.

"The 4.5 million is not surprising at all," Stewart said. "It might not have as high an infection rate as other botnets, but its longevity means that as long as they can keep infecting computers and the discovery rate is small, they'll keep growing it."

Stewart pointed out that TDL-4's counter-attacks against other malware was another reason it's so successful.

"That's so smart," he said, adding that disabling competing malware -- which likely is much easier to detect -- means it has an even better chance of remaining on the PC. If other threats cause suspicious behavior, the machine's owner may investigate, perhaps run additional security scans or install antivirus software.

TDL-4's makers use the botnet to plant additional malware on PCs, rent it out to others for that purpose and for distributed denial-of-service (DDoS) attacks, and to conduct spam and phishing campaigns. Kaspersky said TDL-4 has installed nearly 30 different malicious programs on the PCs it controls.

But it's able to remove any at will. "TDL-4 doesn't delete itself following installation of other malware," said Golovanov. "At any time [it] can ... delete malware it has downloaded."

This is one dangerous customer, Stewart concluded.

"For all intents and purposes, [TDL-4] is very tough to remove," Stewart said. "It's definitely one of the most sophisticated botnets out there."

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@computerworl d.com.
__________________
R.I.P. Gov

Quote:
Originally Posted by The Rev View Post
It's not a bad thing. We all chubbed a little on that one. The Reps really needed to be called out on their obstructionist ways. It's like they're stuck in Gingrich mode, and can't get out. They really need to reinvent themselves, bring in some new people, and really REALLY become the party of self-reliance and small government they'd like us to believe they are. Right now, they just seem like a bunch of pies.
Being is offline   Reply With Quote
The Following User Says Thank You to Being For This Useful Post:
Suliman (07-01-2011)
Old 06-30-2011, 07:53 PM   #2 (permalink)
Clear Light
 
The Rev's Avatar
 
Join Date: Oct 2002
Location: In my head, somewhere.
Posts: 17,865
Thanks: 5,017
Thanked 5,419 Times in 2,864 Posts
Botnets sound pretty badass.



The Rev
__________________


Budforce - My Friend
August 29, 1973- May 25, 2012


The Rev is online now   Reply With Quote
Old 07-01-2011, 02:40 PM   #3 (permalink)
ҰÅĦǾΏҜλИ
 
Suliman's Avatar
 
Join Date: Jun 2008
Location: Hawaii
Posts: 553
Thanks: 501
Thanked 124 Times in 94 Posts
Malware that destroys other Malware? whatWhatWHAT?
Suliman is offline   Reply With Quote
Old 07-01-2011, 03:31 PM   #4 (permalink)
Learner
 
Sir-Ex's Avatar
 
Join Date: Jul 2001
Location: Edmonton, Alberta
Posts: 11,416
Thanks: 1,726
Thanked 3,818 Times in 2,258 Posts
Clearly the work of skynet
__________________
Smile

Ditch the cigs!!!!!!
Sir-Ex is offline   Reply With Quote
The Following 3 Users Say Thank You to Sir-Ex For This Useful Post:
AfroHorse (07-02-2011), Home Wrecker (07-01-2011), Terry (07-04-2011)
Old 07-03-2011, 01:10 PM   #5 (permalink)
Yahookan Zealot
 
Cerpin Taxt's Avatar
 
Join Date: Jun 2002
Location: Canada
Posts: 7,213
Blog Entries: 1
Thanks: 843
Thanked 1,919 Times in 1,011 Posts
Wait a minute, I know how this ends... we trade in the security of our computers for our ability to use P2P networks, right?
__________________
Step Back. Evaluate. Recognize.

"All memory is really a form of regurgitation of undigested experience."
-Alan Watts
Cerpin Taxt is offline   Reply With Quote
Old 07-04-2011, 06:44 PM   #6 (permalink)
restore the republic
 
profit's Avatar
 
Join Date: Apr 2005
Posts: 1,255
Thanks: 818
Thanked 357 Times in 237 Posts
hb gary is pussy shit. they got raped by lulzsec (for the lulz)
im more worried about stuxnet than skynet
__________________

Cowardice asks the question - is it safe?
Expediency asks the question - is it politic?
Vanity asks the question - is it popular?
But conscience asks the question - is it right?
And there comes a time when one must take a position that is neither safe, nor politic, nor popular; but one must take it because it is right.
- Dr. Martin Luther King, Jr.

follow https://twitter.com/#!/curtiswm - sub http://www.youtube.com/user/66sicksfishstix
profit is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:39 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Inactive Reminders By Icora Web Design