tezza Posted March 28, 2012 Share Posted March 28, 2012 Law-abiding citizen turns cyber-vigilante A self-describer "law-abiding citizen" has posted attack plans against the Sality botnet on the Full Disclosure security mailing list, along with a tongue-in-cheek warning not to enact them since that would be illegal. "It has come to my attention that it is not only possible but easy to seize control of version three of the botnet, and, more importantly, take it down. Sadly, doing so would require breaking the law. For this reason, I have to request that nobody perform the steps I am about describe," the author says, with more than a hint of irony. The details of the plan are in an online archive and contain SQL injection tools that can be used to add a copy of an encrypted version of the AVG Sality removal utility into the botnet. It also has a Python script that, the author claims, will get an updated list of targets from the botnet's P2P network. The author also suggests the paranoid should open the file via a locked down virtual system to avoid any possibility that this is a hoax designed to infect security researchers. The posted plans are for attacking version three of the Sality code, but security companies report the botnet controllers have already started to upgrade to a new version, so even if the attack works, the effect would be muted. The current version installs a keylogger, VoIP cracking tools, spam relays, and some experimental malware combinations The Sality botnet is one of the bigger botnets, thought to be about the same size as Rostock, and was first spotted in June 2003, according to a recent a white paper from Symantec. It was apparently named after the Russian town of “Salavat City”, although the command and control servers are thought to be in the US, UK, and the Netherlands. There are removal tools out there for it, but some people aren't using them. In terms of its hosts, Symantec reports over a fifth of the infected PCs that form the botnet are in Romania, with Brazil and India the next most common. http://www.theregist...ake_down_plans/ Link to comment Share on other sites More sharing options...
tipo Posted March 29, 2012 Share Posted March 29, 2012 There are removal tools out there for it, but some people aren't using them. In terms of its hosts, Symantec reports over a fifth of the infected PCs that form the botnet are in Romania, with Brazil and India the next most common.this is what made me switch to defensewall...5-6 of my friends were infected with sality (a couple of weeks ago) and didn`t know about it.they were using AVs(avast, avira - the free versions).so then i realized: no av in the world could keep up with the malware beeing created every day... Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.