Researcher sets up illegal 420,000 node botnet for IPv4 Internet map
theregister.co.uk
theregister.co.uk
Interestingly, I fell for the sensationalist headline of the Register instead of clicking the original HN link entitled "Port scanning /0 using insecure embedded devices" (which I saw and ignored).
I wonder if it will be same here on HN!
Coming from a technical/academic background, good copy is not something that is emphasised - are we missing a trick?
Copy matters.
> This Is A Bad Title With No Relevance; If You Revert To It You're A Bad Editor And You Should Feel Bad
...and then give the link a more sensible (but slightly editorializing) title when I submit it to HN, and see what happens. :)
The exponential suppression of new articles is deliberately harsh. The first few early upvotes are critical. Getting them early and often requires either the right hook or a voting ring.
Copy matters in the real world too.
The HN guideline about linking to the original source would be lovely if it meant people stopped linking to the Reg.
http://www.thoughtcrime.org/software/sslstrip/
Assuming DNSSEC isn't in use, controlling someone's DNS settings is enough to carry out an SSL stripping attack!
[1] http://manned.org/webmitm/8187425a
[2] http://samiux.blogspot.com/2011/05/howto-sniffing-ssl-with-e...
According to the report, designing the botnet took six months.
Highly illegal, yet highly intriguing that building a 400k+ node botnet is this damn simple.
I mean rtm's Internet worm was supposed to be the great wake up call - and thirty years later look !
Exactly... And the very fact that even people don't see anything wrong with "autonomous cars", probably "because this time the company in charge is going to create a separate network whis is really secure" is precisely part of the problem.
We live in a world were people who are supposed to be smart enough to program all these machines and set up all these infrastructure are thinking: "Nothing can ever go wrong with this".
As a result we have more and more insecurity and the problem is only going to get worse.
And I've got a bridge to sell to people who think that autonomous are never going to get hacked...
https://www.google.com/?q=tadayoshi+kohno+automobile
EDIT: Sorry, I didn't mean to sound like such a jerk about it :-)
OTOH, I was talking about autonomous cars. AFAIK none of those was hacked yet (but regular cars were hacked, as proven by your link).
Peace!
Why do autonomous cars need to be on a network at all? The ones I built were never remotely accessible...
That doesn't actually say he infected 420,000 machines, does it?
To further verify our sample data, we developed a small binary that could be uploaded to insecure devices.
https://news.ycombinator.com/item?id=5395009> Our binary ran on approximately 420 thousand devices.
"I had to spend USD15 to run 8 medium EC2 instances for 16 hours to only find 200++ million hosts"
https://news.ycombinator.com/item?id=5406233
and another study was done using EC2 instances:
> But it soon found it was getting competition from a malicious botnet dubbed Aidra and the researcher adapted the binary to block this competitor where possible[...]
I too wonder if this is some deep principle at work or just something obvious.
(On a related note: I think I remember HP demonstrate a remote mitigation tool in '07 that would use exploits to pop messages to logged in users or even shut down the machine.)
s = socket.socket(socket.AF_INET, socket.SOCK_RAW, socket.getprotobyname("icmp"))
for address in addresses:
s.sendto(pkt, (address, 1))
s.close()
At the same time, I had tcpdump running, i.e. "tcpdump -i en1 icmp[icmptype] == icmp-echoreply" to capture the replies.Why in the heavens would you reboot obviously badly administrated machines quite literally half across the globe if you otherwise took every initiative to not harm the target machines and keep your foot print as small as possible? (lowest possible priority, watchdog) Killing the process and removing the files should have been more than enough and you just don't know what a reboot could do to these systems; regardless of how much the admins of those machines are to blame.