Showing posts with label Botnet. Show all posts
Showing posts with label Botnet. Show all posts

Thursday, June 14, 2007

Anti-botnet campaign by FBI

Botnets are a major nuisance on the internet. These are a large number of computers having inadequate protection, that have been compromised and are under the control of people wanting to use these large number of computers (in many cases, in the thousands) for a number of activities such as launching distributed denial of service attacks where these computers together attach a web site or network, used as relays for mass distribution of spam and malware, used for phishing, click fraud, and a variety of other attacks.
How does a computer get compromised? The computer may be running a version of Windows that has a hole, and this hole has been exploited to gain control of the computer. In addition, the computer may not be having an active firewall and virus protection. Botnets are increasingly being found on the internet and cause a high degree of costs by causing down-time, by actual losses due to phishing and click fraud, etc. And the biggest problem is that users do not even know that their computer has been compromised; they find that their computer has gone slower, or becomes active suddenly, but there are no easy ways of knowing that their computer has been used by a crime or is compromised. Typically, when a computer has been infected and is a part of a botnet, it can be used to attack hundreds of other computers.
Given this situation, and the dangers posed by the menace of botnets, the FBI has been investigating and found more than 1 million botnet victims so far. Along with the Justice Department, the FBI has been running a program called Operation Bot Roast to disrupt botnets. They have caught people; however, as long as security patches determine the safety of a computer, there will be infected and compromised computers in the wild. Refer this article:


The FBI is working with industry partners, including the Computer Emergency Response Team Coordination Center at Carnegie Mellon University, to notify the victim owners of the computers. Microsoft and the Botnet Task Force have also helped out the FBI. Through this process the FBI may uncover additional incidents in which botnets have been used to facilitate other criminal activity, the FBI said in a statement.
Bots are widely recognized as one of the top scourges of the industry. Gartner predicts that by year-end 75 percent of enterprises "will be infected with undetected, financially motivated, targeted malware that evaded traditional perimeter and host defenses," and early reports from beta customers of a yet to be released product from Mi5 show how nefarious these infections can be. Mi5 says it installed a Web security beta product at an organization with 12,000 nodes and in one month detected 22 active bots, 123 inactive bots and was watching another 313 suspected bots. That may not sound like a lot, but those bots were responsible for 136 million bot-related incidents, such as scanning for other hosts inside the firewall.


It can get pretty hairy for people. Suppose the computer of a unsuspecting user is used to break into a protected military installation or a bank, or used to break down a major network, the first path for investigators will be to find the computers that were used, and in the case of a compromised computer, the owner will have no idea.
This will also start to increase pressure on software companies to make their software more secure from the ground up, such that they do not land in the situation where the security of the system is dependent on patches.

Thursday, May 10, 2007

Data breach at University of Missouri Computer Database

A hacker managed to access and download information from a computer database (owned by the University) that contained information on names and social security numbers of around 22,000 current and former employees and students. In a sign that officials realized that keeping this information was not safe, there was a project to removed social security numbers from unnecessary computer systems, but the project was not complete. Refer this report at DailyTech:


More than 22,000 current and former University of Missouri employees and students are at risk of identity theft after a hacker reportedly accessed a computer database containing names and Social Security numbers.
Campus IT people discovered the intrusion on Friday morning -- the hacker exploited a hole in a campus web site that is used "to make queries about the status of trouble reports to the university's computer help desk."
The school suffered a similar intrusion in January. In that incident, a hacker was able to secure more than 1,000 Social Security numbers and the passwords of around 2,500 users of an online grant application program.

The shocking thing is that this has happened before in January, and yet this happened again. Now, it is true that computer systems security is an evolving field with constant battles between security folks and hackers, but the fact remains that one would have expected a greater show of urgency towards making systems safe.
Now, the university is faced with the prospect of sending out letters to everybody who could be affected, including former employees and students. And stealing of social security numbers is very different from stealing of credit card information because a database of stolen social security numbers can cause immense identity theft cases.

Friday, May 4, 2007

Busy week for Microsoft patching

Next week promises to be a busy week for systems administrators of companies where there are a number of Microsoft systems. These would consist of security updates for Windows, Office, Exchange and Biztalk. Microsoft normally does not disclose details of the updates, but this article provides some details of what the expected updates would be.
These are one of the issues with using Microsoft updates, in terms of the number of updates that need to be installed on a regular basis. And many of these updates require reboots, causing downtime on systems that are in regular use. Doing downtime on a production system requires some amount of coordination and making sure that users are aware of this downtime. Refer this article:


Two of the seven bulletins slated for the May 8 release involve Windows, three affect Microsoft Office, and one each impact Microsoft Exchange and the cryptography API within BizTalk Server. At least five of the seven updates will be pegged critical, Microsoft's highest threat score in its four-level system, according to the advance notification posted today.
As usual, Microsoft did not disclose details of the updates, but intelligent guesses are not difficult. One of the Windows updates, for example, will likely be a fix for the DNS (Domain Name System) zero-day bug found in all editions of Microsoft's server line, including the current beta of Windows Longhorn Server. While researchers predicted last month that Microsoft would issue an out-of-cycle fix for the DNS server service flaw, the company's security team instead has repeatedly blogged that it would probably wait until the regularly scheduled patch day.
If Microsoft issues the seven updates, users will have seen 29 bulletins in the first four months of the year, and at least 49 patches; more than half of those will have been marked critical. During the first five months of 2006, Microsoft issued 20 updates with 36 patches.

These are a significant number of updates. The biggest problem is that in the time that Microsoft releases a patch, the information about the bug is already being exploited by hackers. Microsoft normally releases a patch with some delay after reporting, while trying to make sure that information about the defect is not available publicly. However, with a reported market in defects, it would seem to be losing this battle.

Wednesday, February 14, 2007

Effect of spyware and adware

In a case that has caused a lot of disquiet, a teacher has been convicted of exposing seventh-grade students in the US to pornography and could face a long sentence. Read the CNN article.
She has been convicted of having a computer in the classroom in which students were able to see ads showing inappropriate content.
Her defence: When she was not in the classroom, some students clicked on a link for some hair styles that also loaded spyware and adware pop-ups on the computer, and since the computer did not have a firewall (and probably not having the latest patches), these pop-ups started appearing faster than she could control them. A pretty strange case, after all, if by mistake you land up on a site, and you do not have pop-up protection, then the number of pop-ups that can get opened can be over-whelming.
One main point that emerges from this case is that it is absolutely necessary that a machine be running a firewall and has all the latest patches.

Sunday, January 28, 2007

Botnets threatening the internet

Botnets are computers that had security holes and are under the control of hackers. In this status, they can be used by hackers to send spam messages, take part in attacks on other computers, and similar such negative actions. One tends to think that these are small percentages, but in the latest estimation, it is estimated that upto 25% of all computers are compromised.
Vin Cerf, one of the net luminaries, compared the spread of botnets to an epidemic. Read the article here.
It is very difficult to halt the spread of these botnets unless security is built into operating systms and applications from the beginning.