Rustock allows multiuser remote access to Windows clients in contravention of its license agreemenposted by Pogo_Fuzzybutt at 3:03 PM on March 22, 2011
I thought a common cleanup mechanism was to use the botnet against itself. Once you control a tier of the command structure, as happened here, couldn't MS distribute a self patching/removal mechanism, and let the nature of the botnet heal itself?posted by delmoi at 3:25 PM on March 22, 2011
I doubt that would be legal. What happens if the cleanup damages the system that it's installed on? There's always a chance of screwing something when remotely patching something, especially if the system is compromised at a low level. It isn't like being part of a botnet prevents from having critical date on it.
I'm always slightly confused by botnets; do enough people leave their computers on permanently that this works? Surely if enough people turned off their computers the botnet would cease to function (assuming of course that they are in the same timezone).Why would you turn your computer off? I doubt it's a significant component of your power bill. If you leave it on you don't have to wait for it to boot up, and you can run servers if you feel like it.
Sony is using terms of service violations (among other things) to go after George Hotz over his PS3 crack. Ends rarely justify the means.I think there was a recent court decision making EULAs enforceable if the user actually reads them, thus we've got this new generation of EULAs where you have to scroll down and read the whole thing. But how could you prove Hotz actually agreed to the EULA? I suppose he might have have had a 'regular' PS3 Live account or something, but in terms of the hacking, don't you think he could have gotten around the whole 'click OK' thing?
For my next botnet, I will set it to contact the emergency secret IP address 180 days after it is last able to contact the normal control hosts.The thing is, if you hard-code an IP address, they'll be able to see what it is. The trick is digital signatures. You include a digital signature for commands, then if the bots lose their master signal, you can just set them all up to form transient P2P networks and scan the web google style to search for signed messages. You could make the signatures look like markov-style autogenerated text to make them harder to notice. With a million nodes, scanning lots of the web wouldn't be too hard for them.
« Older Even Japan’s infamous mafia groups are helping out... | Though Roald Dahl is better kn... Newer »
This thread has been archived and is closed to new comments
posted by GuyZero at 2:00 PM on March 22, 2011