TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Massive Indestructible Botnet

102 点作者 seanharper将近 14 年前

15 条评论

Xk将近 14 年前
&#62; TDL-4's makers created their own encryption algorithm<p>Two comments about this<p>-- I give it maybe a week or two against a good cryptographer. You never, ever invent your own encryption algorithm.<p>-- Even if the encryption algorithm happens to be secure against differential/linear/slide/boomerang attacks, I bet there will be an implementation flaw. It's really hard to get implementation right on those things, even if you have an almost perfect algorithm.<p>Not that that all really matters -- anything that it's encrypted can be decrypted since they key lives on the computer -- but the fact that they created their own encryption algorithm gives some insight in to their minds. Namely, that they they they are smarter than they really are, and that despite all of that, they don't know enough about security to stick with AES.<p>&#62; and the botnet uses the domain names of the C&#38;C servers as the encryption keys.<p>... what? That kind of defeats the entire purpose of encryption when they key is something like that. Besides, what are they using this encryption for. It seems more likely they want a check on the integrity of messages. And even still, a MAC is equally worthless since it's not public/private key.<p>Either (1) this botnet is really weak or (2) the writers of this article have distorted the truth.
评论 #2713640 未加载
评论 #2714322 未加载
评论 #2712745 未加载
评论 #2712821 未加载
评论 #2713584 未加载
JonnieCache将近 14 年前
Anyone got a link to a source with some info that isn't aimed at someone with the technical expertise of the average pensioner? There was no information in this article.<p>Who <i>are</i> these people that read the front pages of both Hacker News and computerworld.com?<p>EDIT: This is more like it: <a href="http://www.securelist.com/en/analysis/204792157/TDSS_TDL_4" rel="nofollow">http://www.securelist.com/en/analysis/204792157/TDSS_TDL_4</a><p>EDIT2: That link was just an initial analysis of the infection vectors, here's a more full analysis of the payload and suchlike <a href="http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot" rel="nofollow">http://www.securelist.com/en/analysis/204792180/TDL4_Top_Bot</a>
评论 #2713206 未加载
fragsworth将近 14 年前
In my opinion, a very poorly written article, but here are some of the main points:<p>1. estimated 4.5 million infected machines<p>2. it infects the Master Boot Record<p>3. it uses the Kad Network (<a href="http://en.wikipedia.org/wiki/Kad_network" rel="nofollow">http://en.wikipedia.org/wiki/Kad_network</a>) to issue commands to the clients (No idea how, the article did not explain this)<p>4. it disables competing malicious software<p>5. it acts as a malicious software manager; they install software for their "customers" to temporarily use
Vivtek将近 14 年前
So at what point does a botnet cease to be a parasite and start to be a symbiote?<p>If TDL-4 keeps your machine free of other malware at the cost of engaging in the occasional DDoS....<p>Actually, wouldn't TDL-4's owners possibly earn <i>more</i> money by doing remote management and tuning of 4.5 million PCs than they could by selling malware connectivity?
zitterbewegung将近 14 年前
Indestructable isn't the right word to describe this. More like very resilant or resistant. Title is very linkbait and the reporting looks like its based off of phrases by security researchers.
hook将近 14 年前
So that's how some videos on youtube have millions of hits before anyone has heard of them...
saalweachter将近 14 年前
Is it just me, or does this article read like a sales brochure for TDL-4?
kaze将近 14 年前
Wouldn't it help to have a read-only bootup DVD to scan the MBR?
评论 #2713100 未加载
Joakal将近 14 年前
Not even a software firewall can pick up connections? I always look to firewalls for abnormal activity.
评论 #2712938 未加载
noglorp将近 14 年前
Fancy cryptography, p2p networking, with web-based command and control: indestructible 'new' type of botnet, or practically identical to Zues? You decide!
extension将近 14 年前
<i>TDL-4's makers use the botnet to plant additional malware on PCs</i><p>Whoa, it's the evil app store!<p>Could this be used to take the botnet down? Pay them to install something and sneak in an antidote?
评论 #2714345 未加载
评论 #2713573 未加载
leon_将近 14 年前
good old fdisk /fixmbr ;)
评论 #2713133 未加载
gorgoroth666将近 14 年前
security ? who cares ?
bromagosa将近 14 年前
Why is anybody on Earth still using Windows?
评论 #2713898 未加载
评论 #2714784 未加载
评论 #2714367 未加载
评论 #2714241 未加载
评论 #2713978 未加载
评论 #2716498 未加载
koko775将近 14 年前
Next thing you know it'll be asking to be uploaded onto a mining colony on some asteroid!
评论 #2723167 未加载