Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Catching a Virus Writer
Kelly Martin, 2004-06-02

With the consumer WiFi explosion, launching a virus into the wild has never been easier and more anonymous than it is today.

Comments Mode:
Catching a Virus Writer 2004-06-03
Anonymous (1 replies)
Catching a Virus Writer 2004-06-08
Roger
Virus companies hire virus writers 2004-06-04
Me (2 replies)
Virus companies *use* virus writers 2004-06-04
Almost Anonymous (1 replies)
Virus companies hire virus writers 2004-06-07
Hardly Anonymous (1 replies)
Virus companies vs the thin red line 2004-06-09
Almost Anonymous
Catching a Virus Writer 2004-06-04
Anonymous
wifi and a good time was had by all 2004-06-05
x (4 replies)
wifi and a good time was had by all 2004-06-08
RogueClient (1 replies)
wifi and a good time was had by all 2004-06-09
Oxfordshire goths
wifi and a good time was had by all 2004-06-08
R0V3N (1 replies)
attacks on the poster "x" 2004-06-09
junctionboxmodeming
wifi and a good time was had by all 2004-06-09
Definitly Anonymous
Catching a Virus Writer 2004-06-07
jb (2 replies)
Catching a Virus Writer 2004-06-08
Roger
> I have found irc bots on peoples computers and it really is not that heard to find out where they are accessing eg Connects to a predefined IRC channel, using its own IRC client, and listens for the commands from the attacker. I mean get real.. just get on the network.

Problem is that a lot of them are in (or bounced through) countries that aren't particularly co-operative. We could use technical measures to disconnect them, but that is ethically dubious, and likely to hurt a lot of innocent bystanders. Also, some of the smarter ones use many redundant servers. For example, if you read the recent Security Focus article on Beagle, you'd notice that altogether, various incarnations used eighty-two different hosts to "phone home"; many of these hosts were in Russia. Others were on free throw-away accounts at free usage websites, which were discarded within days - after they had collected control lists of infected PCs, and before the AV companies had reverse engineered (or in some cases, even discovered) the new variant.

Nevertheless, there have been some attempts at technical intervention. For example on Steve Gibson's site:
http://grc.com
you can read about Steve's efforts to backtrack from a DDoS attack on his site, to an infected PC, back to the controlling IRC channel.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/246/26647#26647
Catching a Virus Writer 2004-06-09
Anonymous
Catching a Virus Writer 2004-06-07
frederik
Creating a Virus Writer 2007-08-21
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus