Register (it's free)
Volconvo Debate Forums
Advertise Here »
Browse ad-free by donating
The Debate Forums Blogs | Donate Register (it's free) Chatroom Search Today's Posts Mark Forums Read  
  Volconvo / Debate Forums / Breaking News


This topic in Breaking News is about FBI tries to fight zombie hordes.

Reply
 
Thread Tools
Old Jun 14, 2007, 02:05 pm   #1 (permalink) (top)
Matt W
Moderator
 
Matt W's Avatar
 
Location: Reading, UK.
Posts: 6,075
FBI tries to fight zombie hordes

BBC NEWS | Technology | FBI tries to fight zombie hordes
Quote:
The FBI is contacting more than one million PC owners who have had their computers hijacked by cyber criminals.
The initiative is part of an ongoing project to thwart the use of hijacked home computers, or zombies, as launch platforms for hi-tech crimes.

The FBI has found networks of zombie computers being used to spread spam, steal IDs and attack websites.

The agency said the zombies or bots were "a growing threat to national security".
Such a shame it wasn't real zombies.....but a great title nevertheless!

Bugger about the PCs, though. How many here are concerned about their security measures?


I spent a lot of money on booze, birds and fast cars. The rest I just squandered.

-George Best, on being asked what he did with his footballing fortunes.
Matt W is offline   Reply With Quote
Old Jun 14, 2007, 03:04 pm   #2 (permalink) (top)
Milton Bradley
BANNED
 
Location: Ohio Province, Rep. of Comerica
Posts: 7,320
Not worried enough to let the FBI go poking around on there.
Milton Bradley is offline   Reply With Quote
Old Jun 14, 2007, 04:33 pm   #3 (permalink) (top)
Jubloz
Zolbuj
 
Jubloz's Avatar
 
Location: California
Posts: 1,267
Aww, and I was just about to grab my crowbar, too. :(


"Iron rusts from disuse; water loses its purity from stagnation... even so does inaction sap the vigor of the mind. " - Da Vinci
Jubloz is offline   Reply With Quote
Old Jun 15, 2007, 12:14 am   #4 (permalink) (top)
Jack
formerly Isherwood
 
Jack's Avatar
 
Location: San Diego, CA
Posts: 12,842
This is why I get so frustrated with computer owners (like my brother) who don't bother keeping their AV updated because "I don't do anything to get me in trouble on the internet". An always-on connection and outdated virus definitions combined with no protection at all from zero-day exploits makes for a potential zombie machine...which then relays worms and viruses onto other people's systems/networks.

You can't force people to be security conscious, but sometimes I wish you could.


The Forum Rules
Radical Atheist
Heathen Queer
Let's agree to respect each others views,
no matter how wrong yours may be.
(Ashleigh Brilliant)
Jack is offline   Reply With Quote
Old Jun 15, 2007, 08:46 am   #5 (permalink) (top)
Chris
Gamma-ray burst
 
Chris's Avatar
 
Location: Nashville
Posts: 6,216
I am extremely worried. This is the new virus. People arent going to send you an "I love you" virus now a days, they arent interested in harming your pc, they are interested in using it to make money for themselves. Like a parasite is willing to live in a host - they want your pc to be healthy so you unwittingly make them more money.

Crazy


Delusion- A persistent false belief held in the face of strong contradictory evidence. (i.e. religion)

Shared via G reader
Blog
Chris is offline   Reply With Quote
Old Jun 15, 2007, 12:29 pm   #6 (permalink) (top)
Apeman81
Hot Lava
 
Posts: 1,301
Quote:
Quote by: Matt W View Post
BBC NEWS | Technology | FBI tries to fight zombie hordes


Such a shame it wasn't real zombies.....but a great title nevertheless!

Bugger about the PCs, though. How many here are concerned about their security measures?
Indeed a great title!

When I first read it, I was hoping Sean (of the Dead) had been co-opted by the FBI for a special op.

Preach to the choir. Keep your computer, your computer. You paid for the processor and memory, why let someone else mess with it.
Apeman81 is offline   Reply With Quote
Old Jun 15, 2007, 01:53 pm   #7 (permalink) (top)
Mr.Vicchio
Navy Veteran
 
Mr.Vicchio's Avatar
 
Location: Texas
Posts: 6,031
You guys do realize that this is just an excuse for the FBI to root around your computer to find "terrorist materials" and if you let them in, you'll never ever let them out and they'll know everything they need to about you.


Einstein's "Theory of Relativity" is still being challenged to this day, but by consensus Global Warming is a fact... that's REAL science at work, why didn't Albert just go that route?
Mr.Vicchio is offline   Reply With Quote
Old Jun 15, 2007, 02:56 pm   #8 (permalink) (top)
Apeman81
Hot Lava
 
Posts: 1,301
Quote:
Quote by: Mr.Vicchio View Post
You guys do realize that this is just an excuse for the FBI to root around your computer to find "terrorist materials" and if you let them in, you'll never ever let them out and they'll know everything they need to about you.
I understand the slight paranoia. But if my system is open to "zombies", the FBI could get in as well.

I invite neither.
Apeman81 is offline   Reply With Quote
Old Jun 15, 2007, 04:48 pm   #9 (permalink) (top)
Jubloz
Zolbuj
 
Jubloz's Avatar
 
Location: California
Posts: 1,267
Quote:
Quote by: Mr.Vicchio View Post
You guys do realize that this is just an excuse for the FBI to root around your computer to find "terrorist materials" and if you let them in, you'll never ever let them out and they'll know everything they need to about you.
Great, so now I have to combat zombies and the FBI?! :eek:








Yes, that was a joke.


"Iron rusts from disuse; water loses its purity from stagnation... even so does inaction sap the vigor of the mind. " - Da Vinci
Jubloz is offline   Reply With Quote
Old Jun 15, 2007, 05:02 pm   #10 (permalink) (top)
Technosoul
Volcanic Erupter
 
Posts: 8,657
They should get their men in black on that right wasy.

The only way they can get into your compter to take it over for their useages is when you open e-mails or P.M.s (etc.). In businesses that would be nearly impossible not to do. But private computer owners can simply not open e-mails from anyone they do not know.

Sort of like the old "don't talk to strangers" advice.

I no longer even use my e-mail services anymore. And I might discontinue opening private messages as well.

Not sure how the FBI can stop them, that would be interesting to find out more about. The best bet would be to have the hardware and software computer companines find way to build in firewalls to keep the Zombie Bugs out.
Technosoul is offline   Reply With Quote
Old Jun 15, 2007, 11:22 pm   #11 (permalink) (top)
Jack
formerly Isherwood
 
Jack's Avatar
 
Location: San Diego, CA
Posts: 12,842
Quote:
The only way they can get into your compter to take it over for their useages is when you open e-mails or P.M.s (etc.)
That hasn't been the only way for a while. Exploits have been found embedded in jpegs, pdf's and audio files, as well as the ever-popular buffer overflows and scripts.
Quote:
This past December, a new family of worms was discovered. The family, Santy, attacked Web applications written in the PHP scripting language. Santy is interesting for two reasons: First, its worms used Web search engines to locate likely targets; second, a Santy variant exploited a generic flaw in PHP applications, rather than a specific vulnerability.
2005 Worm Propagation and Generic Attacks

Quote:
Other worms can use multiple methods of spreading. The MyDoom worm, which started spreading in January 2004, attempted to copy infected files into the folder used by Kazaa, a file-sharing program. The Nimda worm, from September 2001, was a hybrid that had four different ways of spreading.
CBC News In Depth: Internet

Quote:
Another common way for a virus or spyware to spread is by piggybacking on other software that you download. If you just can't resist the latest toolbar, file-sharing gizmo, coupon dispenser or email enhancer, you may be at risk. Often these and other downloads come with malware, free of charge.
How Does a Virus Spread?

Quote:
Several new Adobe pdf vulnerabilities were recently announced.
The author claims these are basic vulnerabilities in the pdf api or architecture. The author tested his poc's against Acrobat reader and Adobe professional.

The details are available here.
Hacker Anthology - Operation n
Hacker Discovers Adobe PDF Back Doors

Here is a quick risk assessment.

How widely deployed is the application?
Adobe reader is widely used and deployed. (9)

Are vendor patches available?
No patches currently available (10)

Is mitigation available and if so how complete is the mitigation?
No mitigation is currently available. (10)

Is user participation required?

Yes. The user first has to download or click the link to a pdf. (5)
So some user interaction takes place.
I have not tested the POCs but several people have and their results do not match. Depending on who tested it you may have to click allow.
See this discussion on who tested the pocs and their results.
Network Security: Detailed info on Re: [Full-disclosure] Backdooring PDF Files

Is the vulnerability cross platform?

Yes. Any exploits will still have to run system dependant malware on the end host but there are plenty of malware binaries that could be used. (8)

Is proof of concepts or exploit code available?
The poc for two of the vulnerabilities are publicly available (10)
SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc

Quote:
The first example of a working program designed to exploit a bug in Microsoft's GDI+ library—which allows malicious code to be run simply by viewing a JPEG image—has been found in the wild.

EasyNews, a provider of Usenet newsgroup services, claimed it had already found two images containing code designed to take advantage of the flaw—by downloading remote control software to infected machines. In theory, this would give the creators of the images access to both files on infected machines, as well as giving them the ability to run remote programs on them.
2004 Windows JPEG Exploit Ventures into the Wild


The Forum Rules
Radical Atheist
Heathen Queer
Let's agree to respect each others views,
no matter how wrong yours may be.
(Ashleigh Brilliant)
Jack is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT -4. The time now is 12:15 am.

Sponsors (become a sponsor)
UK Car Insurance, Beauty Salon, Coach Handbags, Miele Vacuums, Plus Size Bras, Gambling, Bullhorn, Horses for Sale, Ventrilo Server, liquid vitamins, weight loss, Smiley Central, Monetise your website, Ventrilo Server, Dyson Vacuums, Hydroponics & Grow Lights, Offshore banking, beauty salons, Offshore banking, Connecticut Electric Rate, Retail Electric Providers Cirro Energy, LasVegas Vacations, Web Design, homes in hudson, Affordable Web Hosting, Texas Electric Rate Cirro Energy, Security Audit, Guy Factor, Gun Forums, Loans Loans Home Loans in India Loans Web Advertising
Powered by vBulletin Version 3.7.1 Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

© 2003–2008 Volconvo.com

1 2 3 4 5 6 7 8 9