Razing Rustock

Pyro Pilots Lounge. For all topics *not* covered in other DBB forums.

Moderators: fliptw, roid

Post Reply
User avatar
Tunnelcat
DBB Grand Master
DBB Grand Master
Posts: 13743
Joined: Sat Mar 24, 2007 12:32 pm
Location: Pacific Northwest, U.S.A.

Razing Rustock

Post by Tunnelcat »

Speaking of spying on the net, here's the detailed scoop on how the government and Microsoft brought down the Rustock Botnet. Sure doesn't give me the warm and fuzzies that it won't be back. Like trying to squash flies, more will get into the house, especially if Rustock was state sponsored. Seems like more money went into this thing than your average lone hacker would've been capable of setting up.

http://www.businessweek.com/magazine/co ... 712001.htm
Cat (n.) A bipolar creature which would as soon gouge your eyes out as it would cuddle.
User avatar
snoopy
DBB Benefactor
DBB Benefactor
Posts: 4435
Joined: Thu Sep 02, 1999 2:01 am

Re: Razing Rustock

Post by snoopy »

Interesting.

Here's my take on cyber crime & botnets:

Both would take a major hit if individuals did two things:
1. Don't patronize the spammers, and delete their email without opening
2. Secure your own machines to the best of your ability, keeping up to date with anti spyware, anti malware, etc.
Arch Linux x86-64, Openbox
"We'll just set a new course for that empty region over there, near that blackish, holeish thing. " Zapp Brannigan
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16138
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: Razing Rustock

Post by Krom »

0. Don't install Adobe software.

The most common vector I've noticed lately is embedded adobe pdf exploits served up on compromised web pages. It is popular because it is cross-browser impacting IE, firefox, chrome, opera, safari, etc (anything adobe writes a pdf plugin for) and it has a huge installed user base.

Botnets specifically are different from other kinds of malware in how they behave on an infected system. Unlike things like the fraudulent "Antivirus 20xx" programs (which are for credit card theft) that pop up windows and spam your desktop endlessly, purpose built botnets run in the background and use methods to deliberately avoid attracting attention from the user.

I suspect this cat and mouse game will continue for a long time, it is one of the costs of the freedom we enjoy on the internet.
User avatar
Duper
DBB Master
DBB Master
Posts: 9214
Joined: Thu Nov 22, 2001 3:01 am
Location: Beaverton, Oregon USA

Re: Razing Rustock

Post by Duper »

Krom,

Do you have substitutes to recommend for flash and the like? Much of what is used now uses adobe of some kind.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16138
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: Razing Rustock

Post by Krom »

Flash is proprietary so unfortunately there is no substitute (at least pending widespread HTML5 adoption). But you can minimize the risk by using adblockplus and noscript in firefox to block/disable most flash content before it loads unless you expressly want to enable it on a specific site.

You can avoid the adobe pdf reader though, use an alternative reader such as foxit and don't install the browser plugins for it. Costs a little bit more effort but definitely sabotages the embedded pdf vector.
User avatar
TigerRaptor
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2694
Joined: Tue Feb 01, 2000 6:00 am

Re: Razing Rustock

Post by TigerRaptor »

I've been using a program called, Enhanced Mitigation Experience Toolkit for problems like that. Sounds like a mouthful. :P I configured FireFox, Foxit reader, Outlook and a bunch of others. Doesn't hurt to be a little safer.

How it works if any one is interested.

http://www.h-online.com/security/featur ... 02501.html

http://www.microsoft.com/downloads/en/d ... 5192c491cb
User avatar
Isaac
DBB Artist
DBB Artist
Posts: 7737
Joined: Mon Aug 01, 2005 8:47 am
Location: 🍕

Re: Razing Rustock

Post by Isaac »

What about installing adobe products on linux for chrome and firefox? I have the option for flash block, but I never use it. And also, I don't use the pdf reader from adobe (it's slow and fat). I use something else.
❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉
-⎽__⎽-⎻⎺⎺⎻-⎽__⎽--⎻⎺⎺⎻-★ ·:*¨༺꧁༺ :E ༻꧂༻¨*:·.★-⎽__⎽-⎻⎺⎺⎻-⎽__⎽--⎻⎺⎺⎻-
❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉
User avatar
Sirius
DBB Master
DBB Master
Posts: 5616
Joined: Fri May 28, 1999 2:01 am
Location: Bellevue, WA
Contact:

Re: Razing Rustock

Post by Sirius »

They may have different vulnerabilities, but I bet they still have vulnerabilities.
User avatar
Avder
DBB Material Defender
DBB Material Defender
Posts: 4926
Joined: Sat Oct 09, 1999 2:01 am
Location: Moorhead, MN

Re: Razing Rustock

Post by Avder »

I ★■◆●ing hate flash. Why cant they just implement an easily streamable version of .avi files to put on youtube?
User avatar
Sirius
DBB Master
DBB Master
Posts: 5616
Joined: Fri May 28, 1999 2:01 am
Location: Bellevue, WA
Contact:

Re: Razing Rustock

Post by Sirius »

Pretty much because nobody can agree on the codec to use thanks to BS politics.
User avatar
Avder
DBB Material Defender
DBB Material Defender
Posts: 4926
Joined: Sat Oct 09, 1999 2:01 am
Location: Moorhead, MN

Re: Razing Rustock

Post by Avder »

Seems to me if YouTube implemented it, everyone would have to support it.
User avatar
Spidey
DBB Grand Master
DBB Grand Master
Posts: 10809
Joined: Thu Jun 28, 2001 2:01 am
Location: Earth

Re: Razing Rustock

Post by Spidey »

Flash was really intended to display vector graphics, and have a web friendly file size…why it’s used for rastor movies, is beyond me.
Post Reply