Showing posts with label for-the-lulz. Show all posts
Showing posts with label for-the-lulz. Show all posts

14 April, 2009

"GhostNet" linked to the "Waledac" botnet

Conficker.C-infected computers have shown activity recently, according to security analysts and software/network engineers, so it seems the threat is not over...yet.

It's main activities (identified activities, that is), are:
  • downloading (malware from other botnets, mainly the spammer-botnet "Waledac", better known as the re-animated Storm DeadNet "Valentines e-mail spammer botnet")
  • linking (assumably to other malicious botnets)
  • communicating (assumably with it's creators).

It is also reported to flash rogue anti-viral software ads directed at users of these infected machines.

Darknet.co.uk had this article to explain (excerpt from article below):

“Fear is used, universally, as a means to control people,” said Sendio CTO Tal Golan. “Governments use it. Large businesses use it. So it should come as no surprise to anyone that ‘cyber-bad guys’ use it.”

At the moment, the rogue anti-virus software comes from sites located in the Ukraine (131-3.elaninet.com.78.26.179.107) although the worm is downloading it from other sites, according to Kaspersky Lab.



Hmm. No, not surprising at all if you ask me.

31 March, 2009

Like I said...

Like in my previous post, a lot of IT professionals are also realizing the global network threat that is upon us.

Crackers (like everybody else) are now able to hookup to a decent Internet-connection with "broadband"-sufficient bandwidth, which also means; crackers are now globally able to take down multi-national corporation networks without too much hassle (provided they're not secured too much, not that it can't be bypassed, it just takes a lot longer to do it).

While researching how to protect my domain and network @ home, I discovered this article @ computerworld.com, entitled "100% Cure for Conficker": http://blogs.computerworld.com/100_cure_for_conficker

Steven J. Vaughan-Nichols (Cyber Critic) advises people to jump over from traditional DNS systems, to OpenDNS. After switching my static DNS adresses in my router(s), I found some interesting features in OpenDNS, like the ability to stop phishing-attack attempts, or advanced adress-filtering. They've gone through the works and secured the OpenDNS system to be as secure as can be, without crippling day-to-day performance.

For example, you have to be a registered OpenDNS user with a/multiple registered and confirmed IP-adress(es) to use name resolving through OpenDNS.

28 July, 2008