funsec mailing list archives

FUD or Fact: Storm retaliates


From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Thu, 25 Oct 2007 07:13:32 -0400

The Storm worm is fighting back against security researchers that seek
to destroy it and has them running scared, Interop New York show
attendees heard Tuesday.

The worm can figure out which users are trying to probe its
command-and-control servers, and it retaliates by launching DDoS attacks
against them, shutting down their Internet access for days, says Josh
Korman, host-protection architect for IBM/ISS, who led a session on
network threats.
from: http://www.networkworld.com/news/2007/102407-storm-worm-security.html


"As you try to investigate [Storm], it knows, and it punishes," he says.
"It fights back."

As a result, researchers who have managed to glean facts about the worm
are reluctant to publish their findings. "They're afraid. I've never
seen this before," Korman says. "They find these things but never say
anything about them."

And not without good reason, he says. Some who have managed to reverse
engineer Storm in an effort to figure out how to thwart it have suffered
DDoS attacks that have knocked them off the Internet for days, he says.

As researchers test their versions of Storm by connecting to Storm
command-and-control servers, the servers seem to recognize these
attempts as threatening. Then either the worm itself or the people
behind it seem to knock them off the Internet by flooding them with
traffic from Storm's botnet, Korman says.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: