Jump to content

Sality botnet takedown plans posted online


tezza

Recommended Posts

Law-abiding citizen turns cyber-vigilante

A self-describer "law-abiding citizen" has posted attack plans against the Sality botnet on the Full Disclosure security mailing list, along with a tongue-in-cheek warning not to enact them since that would be illegal.

"It has come to my attention that it is not only possible but easy to seize control of version three of the botnet, and, more importantly, take it down. Sadly, doing so would require breaking the law. For this reason, I have to request that nobody perform the steps I am about describe," the author says, with more than a hint of irony.

The details of the plan are in an online archive and contain SQL injection tools that can be used to add a copy of an encrypted version of the AVG Sality removal utility into the botnet. It also has a Python script that, the author claims, will get an updated list of targets from the botnet's P2P network. The author also suggests the paranoid should open the file via a locked down virtual system to avoid any possibility that this is a hoax designed to infect security researchers.

The posted plans are for attacking version three of the Sality code, but security companies report the botnet controllers have already started to upgrade to a new version, so even if the attack works, the effect would be muted. The current version installs a keylogger, VoIP cracking tools, spam relays, and some experimental malware combinations

The Sality botnet is one of the bigger botnets, thought to be about the same size as Rostock, and was first spotted in June 2003, according to a recent a white paper from Symantec. It was apparently named after the Russian town of “Salavat City”, although the command and control servers are thought to be in the US, UK, and the Netherlands.

There are removal tools out there for it, but some people aren't using them. In terms of its hosts, Symantec reports over a fifth of the infected PCs that form the botnet are in Romania, with Brazil and India the next most common.

http://www.theregist...ake_down_plans/

Link to comment
Share on other sites


  • Replies 1
  • Views 855
  • Created
  • Last Reply

There are removal tools out there for it, but some people aren't using them. In terms of its hosts, Symantec reports over a fifth of the infected PCs that form the botnet are in Romania, with Brazil and India the next most common.

this is what made me switch to defensewall...5-6 of my friends were infected with sality (a couple of weeks ago) and didn`t know about it.they were using AVs(avast, avira - the free versions).so then i realized: no av in the world could keep up with the malware beeing created every day...
Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...