blademaster
I'm moving to Brazil
+2,075|6924
Well just learned this today you wont find this in everyday news, the storm botnet --> is a botnet, a group of "zombie" computers controlled remotely."The botnet reportedly is powerful enough as of September 2007 to force entire countries off the Internet, and is estimated to be able to potentially execute more instructions per second than some of the world's top supercomputers."[1]

So basically it almost brought the whole U.S. internet to the halt like 2 weeks ago or so, right now its function at 7% sending spam and malware and the code is so well executed and hard to decipher the code. The people  are blaming Russian Business Network (RBN) but the RBN is say that they did not do it.

just a small article here about it you can find other on the netz


Some more history on the storm botnet for those of you who are interested (Read it so you get an better idea about the story).

The Storm Botnet is a distributed computer network consisting of computers remotely controlled without their owner's knowledge. Computers in the Storm Botnet are home and small office machines running the Microsoft Windows operating system which have been infected by the Storm worm. Storm got it's name as the worm was first spread though spam email with the subject "230 dead as storm batters Europe." Today, the Storm Botnet is considered to be the largest botnet in the world, with as many as 5 million computers under it's control. Efforts to combat Storm have been met with targeted resistance, suggesting that artificial intelligence and automated adaptive defense techniques are being utilized.

The Storm worm, termed Nuwar by Microsoft but popularly referred to as Storm, was first identified in January 2007. Within one week of it's discovery, the worm had successfully infected over one million personal computers. This success is credited to the ambiguous yet catchy email subject lines in propagation emails, which like the original "storm" subject often referred to current news events. When these email messages are opened in an insecure email client such as Outlook or Outlook Express, an executable attachment downloads and installs several malware packages to the host computer. Usually, in addition to a trojan and a worm update, a rootkit is installed on the host computer, thereby masking any evidence of infection.

In fact, the Storm rootkit had been proven to disable any anti-virus programs running on the computer while leaving it's executable file running. The updated worm then mutates slightly, harvests email addresses in the email client and browser cache, and sends itself to those addresses. Unlike other worms which have a master computer hard-coded into their code, the mutated Storm worm contains only a list of other Storm-infected machines with which it can communicate, but not the address of the botnet master. Communication between each Storm node and the master is performed in a P2P fashion, with each machine functioning as both a slave and as a messenger between nodes.


Once a computer is infected with the Storm worm, it becomes part of the Storm Botnet. With 250,000 nodes active at any particular time, the Storm Botnet is estimated to range between 2 million and 5 million computers total. This provides the network with more RAM, disk space, and computing power than many of the world's most powerful supercomputers. However, Storm's strength is not in it's shear computing resources but rather in it's distributed nature, as the computers consisting of the botnet have more available bandwidth than most countries have in their entirety.


References [1] Spiess, Kevin. "Worm 'Storm' gathers strength", Neo Seeker, September 7, 2007.

Last edited by blademaster (2008-01-28 11:59:46)

FFLink
There is.
+1,380|6970|Devon, England
At least I'm safe.

I don't give a damn about Emails telling me about current events
CrazeD
Member
+368|6952|Maine
lol.

Firewall ftw.
bullit
Tank Troll
+71|6968|London, UK
Judgement Day.
Mr.Dooomed
Find your center.
+752|6607

It's the whole Shadow/One world government types trying to destroy our ability to share information and news freely to each other through out the world so we can be better controlled. Its starting unfortunately....This could only be the beginning... *QUe scary music*
Nature is a powerful force. Those who seek to subdue nature, never do so permanently.
.:ronin:.|Patton
Respekct dad i love u always
+946|7088|Marathon, Florida Keys
i guess this is why AGV has been picking up more things than usual lately. I dont know how i got this stuff anyway, i dont even use my email or look at pr0n.
https://i54.photobucket.com/albums/g117/patton1337/stats.jpg
FFLink
There is.
+1,380|6970|Devon, England

.:ronin:.|Patton wrote:

i guess this is why AGV has been picking up more things than usual lately. I dont know how i got this stuff anyway, i dont even use my email or look at pr0n.
Liar.
CrazeD
Member
+368|6952|Maine
Man, the new Die Hard movie is becoming reality, eh?
(T)eflon(S)hadow
R.I.P. Neda
+456|7108|Grapevine, TX
Well I would only recommend opening an email with an executable file with knowing a friend or contact is sending you one. Keep up your firewalls, AV and software firewalls up... The company I work for has over 5000 servers across the US, we havent had one affected with this, but alot of them get hacked with other SQL injections and stuff from bad coding...

Found this on wikipedia:
Computer security expert Joe Stewart detailed the process by which compromised machines join the botnet: attempts to join the botnet are made by launching a series of EXE files on the computer system in question, in stages. Usually, they are named in a sequence from game0.exe through game5.exe, or similar. It will then continue launching executables in turn. They typically perform the following:[27]

   1. game0.exe - Backdoor/downloader
   2. game1.exe - SMTP relay
   3. game2.exe - E-mail address stealer
   4. game3.exe - E-mail virus spreader
   5. game4.exe - DDoS attack tool
   6. game5.exe - Updated copy of Storm Worm dropper


If you see those in your running processes its probably to late, get professional help!
Ender2309
has joined the GOP
+470|6850|USA

(T)eflon(S)hadow wrote:

Well I would only recommend opening an email with an executable file with knowing a friend or contact is sending you one. Keep up your firewalls, AV and software firewalls up... The company I work for has over 5000 servers across the US, we havent had one affected with this, but alot of them get hacked with other SQL injections and stuff from bad coding...

Found this on wikipedia:
Computer security expert Joe Stewart detailed the process by which compromised machines join the botnet: attempts to join the botnet are made by launching a series of EXE files on the computer system in question, in stages. Usually, they are named in a sequence from game0.exe through game5.exe, or similar. It will then continue launching executables in turn. They typically perform the following:[27]

   1. game0.exe - Backdoor/downloader
   2. game1.exe - SMTP relay
   3. game2.exe - E-mail address stealer
   4. game3.exe - E-mail virus spreader
   5. game4.exe - DDoS attack tool
   6. game5.exe - Updated copy of Storm Worm dropper


If you see those in your running processes its probably to late, get professional help!
with something like this i'd say its better to just reformat entirely. its one of those rare things in which you want to be absolutely positive you trashed it completely.
Xblade-3o5-
Oi, Suzy!
+113|7032|Florida, United States
I for one welcome our new computer overlords.


Can anyone say skynet?
Dwit
Member
+34|6789

Xblade-3o5- wrote:

I for one welcome our new computer overlords.


Can anyone say skynet?
"skynet"

nothing happens !
naightknifar
Served and Out
+642|6840|Southampton, UK

Xblade-3o5- wrote:

I for one welcome our new computer overlords.


Can anyone say skynet?
Skyent.


Guess not.
=NHB=Shadow
hi
+322|6645|California

naightknifar wrote:

Xblade-3o5- wrote:

I for one welcome our new computer overlords.


Can anyone say skynet?
Skyent.


Guess not.
lols terminator on fox tonight
san4
The Mas
+311|6967|NYC, a place to live
The Storm botnet is pretty scary. It's hard to tell if the people who control it are keeping a relatively low profile because they're smart or because they just don't have big ideas. Like telling Amazon they'll take the site down right before Christmas unless they're paid $10 million.
Reciprocity
Member
+721|6860|the dank(super) side of Oregon
hooray for the old people and women who proliferate this infection.
ig
This topic seems to have no actual posts
+1,199|6801
if i get banned for a bad post, im blaming this shit
bf2gammer
Member
+14|6500
so thats what that email was.
bf2gammer
Member
+14|6500

san4 wrote:

The Storm botnet is pretty scary. It's hard to tell if the people who control it are keeping a relatively low profile because they're smart or because they just don't have big ideas. Like telling Amazon they'll take the site down right before Christmas unless they're paid $10 million.
LOLZ thats a good idea.. wouldnt take much either
GunSlinger OIF II
Banned.
+1,860|6923
5 million computers sounds like a low number to me, am I wrong?
Kmar
Truth is my Bitch
+5,695|6880|132 and Bush

http://en.wikipedia.org/wiki/Storm_botn … the_botnet


Judgment day tbh..

[google]http://video.google.com/videoplay?docid=6547702701811013198[/google]
Xbone Stormsurgezz

Board footer

Privacy Policy - © 2025 Jeff Minard