Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Knock, Knock, Knock
Kelly Martin, 2004-02-20

If hundreds of thousands of people are still blindly clicking on attachments in their email, is there any hope of mitigating the threat of hundreds of thousands of compromised systems with open backdoors?

Comments Mode:
Knock, Knock, Knock 2004-02-20
Dmitriy (1 replies)
Knock, Knock, Knock 2004-02-24
Keith (4 replies)
Knock, Knock, Knock 2004-02-26
Anonymous
Knock, Knock, Knock 2004-02-27
Farzad
Knock, Knock, Knock 2004-03-01
Anonymous
Knock, Knock, Knock 2004-03-01
www.mobasoft.com
Knock, Knock, Knock 2004-02-20
Anonymous (2 replies)
Knock, Knock, Knock 2004-02-25
Anonymous (1 replies)
Knock, Knock, Knock 2004-03-03
Anonymous
Knock, Knock, Knock 2004-02-21
Anonymous
Ok Double Sided Swords 2004-02-21
Anonymous
Knock, Knock, Knock 2004-02-24
Jack (1 replies)
Knock, Knock, Knock 2004-02-28
Anonymous
"Sure, yeah, a worm/backdoor writer *could* implement port-knocking to protect the backdoor. But you are forgetting one important thing....

they don't /care/ about the security of their victim's machines."

When an owned machine is a commodity to be used and traded, sure you care about making sure you retain control over it and it isn't just picked up by the next person doing a port scan. Or worse yet as the case with mydoom.a some "helpful" worm comes along and uninstalls and patches the owned system because you just left the door open.

Dont get me wrong, I dont think he made a case for how port knocking will help viruses spread and with that "dump user" hook I would assume that is what the article would be about. That is more a case about more virulent viruses.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/221/25214#25214
Knock, Knock, Knock 2004-02-25
Anonymous
Knock, Knock, Knock 2004-02-26
fndude@hotmail.com
Knock, Knock, Knock 2004-02-27
Anonymous
Pretty easy solution 2004-02-27
Potato Head
Knock, Knock, Knock 2004-03-01
Robert Townley







 

Privacy Statement
Copyright 2009, SecurityFocus