Hackers return fire at security patches

Steven Deare, ZDNet Australia
20 September 2005 08:37 AM
Tags: hacker, hackers, dos, bot, symantec
Hackers have hit back against major security patches issued by the likes of Microsoft, with a marked rise in self-installing robot programs that allow an unauthorised user to control a computer remotely.

In a report on robot program ('bot') activity for the period January 1 to June 30 2005, Internet security vendor Symantec found an average of 10,352 bots online per day.

This compared with an average of 5,000 bots per day around December 2004.

Bot networks are compromised computers on which attackers have installed software that listens for and responds to commands -- commonly over a chat channel -- allowing remote control of the computers.

The rise in bot activity follows the release of Microsoft's Service Pack 2 in August 2004, a free download issued by the vendor to combat a range of security exploits. Prior to its release, 30,000 bots per day had been recorded in July 2004.

The 2005 rise was a sign that hackers and malicious users were fighting back against vendor patching, according to the report.

"It is likely that bot network owners have been required to modify their attack methods in order to maintain viability in the face of these changes," the report said.

Coinciding with the rise in bots, the report found denial of service (DoS) attacks jumped by 680 percent in the same period, to an average of 927 per day. Bot networks are commonly used to execute DoS attacks.

"This increase in DoS activity is largely due to the corresponding increase in bot network activity. It may be related, at least in part, to financial motivation, as DoS attacks have been reported in extortion attempts," the report said.

Symantec also found such bot networks were available for hire. The report detailed an example from a chat service, whereby a bot network owner advertised the size, capacity and price of the network he was offerring. Customised bot binary code was available for between US$200 and US$300.

"These communications indicate that it is not uncommon for those who maintain control of these bot networks to provide full or partial access to the compromised systems for a fee," the report said.

The report was compiled via 24,000 sensors monitoring network activity in over 180 countries.
Advertisement

Talkback 2 comments

    SafeJaina -- 22/09/05 (in reply to #120121282)

    *sighs* Is the world ever going to be safe?

    MisleadingAnonymous -- 22/09/05

    This article is very misleading. It tries to portray the bot activity as a reaction to security patches and upgrades but presents no evidence that the criminals are doing anything they weren't already intent on doing.

    If anything, the updates, especially firewalls that reduce the effect of newly discovered vulnerabilities by keeping the ports hidden, have made it harder of the bot controllers. Much like the way security cameras have changed the difficulty of shoplifting. It hasn't eliminated the problem but it is a different fight than before.

Add your opinion


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured