Slashdot Log In
Does Open Source Encourage Rootkits?
Posted by
ScuttleMonkey
on Mon Apr 17, 2006 06:33 PM
from the no-ulterior-motives dept.
from the no-ulterior-motives dept.
An anonymous reader writes "NetworkWorld reports that security vendor McAfee places the blame for increased numbers of rootkits squarely on the shoulders of the open source community. Others, however, do not agree. From the article: 'Rootkit.com's 41,533 members do post rootkit source code anonymously, then discuss and share the open source code. But it's naïve to say the Web site exists for malicious purposes, contends Greg Hoglund, CEO of security firm HBGary and operator of Rootkit. "It's there to educate people," says Hoglund [...] It's a great resource for anti-virus companies and others. Without it, they'd be far behind in their understanding of rootkits."'"
Related Stories
[+]
Ask Slashdot: A Closed Off System? 177 comments
AnarkiNet wonders: "In an age of malware which installs itself via browsers, rootkits installing themselves from audio cds, and loads of other shady things happening on your computer, would a 'Closed OS' be successful? The idea is an operating system (open or closed source), which allows no third party software to be installed, ever. Yes, not even your own coded programs would run unless they existed in the OS-maker-managed database of programs that could be installed. Some people might be aghast at this idea but I feel that it could be highly useful for example in the corporate setting where there would be no need for a secretary to have anything on his/her computer other than the programs available from the OS-maker. For now, let's not worry if people can 'get around' the system. If each program that made up the collection of allowed programs was 'up to scratch' and had 'everything you need', would you really have an issue with being unable to install a different program that did the same thing?"
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Scare Tactics and Get Real (Score:5, Insightful)
Simply because they use a domain name and the site is known does not make the information malicious. If you don't think rotating sites on rotating server exist to share compromised media and discussion about server cracking then you don't know anything. Rookit.com is open and out there, but the malicious people don't just stop here. Removing rootkit.com off the face of the earth would do zero to stop server compromises and rootkits.
And don't get me started about the quote..." make it advisable "to throw the computer away" if you want to be sure you got rid of the rootkit". Talk about scare tactics...sheesh. How often do you see a BIOS rootkit? And if you did, why don't you just reflash the BIOS? Or is this a sinister plan to make companies throw out old hardware to buy new so they buy new faster stuff to run Vista. That's it! It's all Microsoft's fault. Amazing how fast we can go do the jump off the bridge path.
Re:Scare Tactics and Get Real (Score:2, Interesting)
Maybe
Re:Scare Tactics and Get Real (Score:5, Interesting)
Parent
I have a project there, AFX Rootkit... (Score:3, Insightful)
Re:Scare Tactics and Get Real (Score:5, Funny)
$100.00 per Pentium 4 computer or laptop infected with a dangerous rootkit. Our trained professionals will seal each infected PC in a hypo allergenic bag and savely transport them to our facilitity for disposal and recycling.
I get paid AND get gobs of good gear to sell on ebay!
Thanks for the tip! this will go great with my DVD rewinding service!
Parent
Re:Scare Tactics and Get Real (Score:3, Insightful)
Re:Scare Tactics and Get Real (Score:3, Funny)
Man, I wish I had known about your service BEFORE I got hit with the $2 charge at the video store...
Baloney (Score:5, Insightful)
That's like saying Edison and Tesla are to blame every time someone gets electocuted.
Re:Baloney (Score:5, Insightful)
Guns are evil, drugs are bad, rootkits are bad, P2P is evil, etc...
We've heard this all before.
Concrete is bad because it could be used to make a shoe and keep a victim from struggling whilst they are dropped at the bottom of a lake.
Knives are bad because they may be used to kill someone.
2x4 pieces of lumber are bad because you could use it to knock someone off a motorcycle.
Baseball bats are really evil becuase gangs can use them for intimidation.
Crowbars, they should be illegal anyway, who uses them? We need to have nails that dissolve with water instead of trying to pry them up with this lethal weapon.
Parent
Re:Baloney (Score:2)
Re:Baloney (Score:3, Informative)
Re:Baloney (Score:2, Interesting)
Re:Baloney (Score:5, Interesting)
No you're not.
"But even for me, there are limits. Should people be allowed to own fully automatic weapons? RPGs? Artillary? Landmines?"
Do you really think that the founders would have been worried about individuals owning RPGs when they were quite happy for individuals to own warships?
Hint: read Article 1 section 8 sometime, and look up 'letters of marque and reprisal', if you don't know what that means.
Parent
The problem is... (Score:4, Insightful)
Parent
You are dead wrong... (Score:3, Informative)
Re:You are dead wrong... (Score:3, Insightful)
Re:Baloney (Score:3, Funny)
Re:Baloney (Score:3, Insightful)
It's interesting how the same people who support Bush sending Americans to Guantanamo for allegedly planning on building a weapon, but insist on the unconditional right to bear arms.
Re:Baloney (Score:3, Interesting)
Yeah, because rootkits have so many other benign and benevolent purposes...
Re:Baloney (Score:2)
Of course, all this electrocution business just goes to show how much safer Edison's DC power would be, now doesn't it?
Hmm. Makes me wonder what kind of power source this vendor (or its backer) is hyping....
Re:Baloney (Score:3, Informative)
Ironically back when electrical grids were starting to take off there was a big fight over AC vs DC, with one marketing approach being to associate the opposing side with the electric chair. I think that somebody wanted to coin the phrase "getting westinghoused" for being electrocuted.
Can't say I remember the details though...
Re:Baloney (Score:3, Informative)
Topsy the roasted elephant (Score:3, Interesting)
Re:Baloney (Score:3, Insightful)
McAfee certainly doesn't want to take the blame when the computers that it is paid money to protect are infected...so it looks for a soft target. (And now you know what I think of McAfee. I didn't even bother to check that this was the same one...so believe at your own risk.)
Re:Baloney (Score:2)
Increased numbers != culpability (Score:2)
Re:Baloney (Score:4, Insightful)
They mass produce rootkits by the MILLIONS.
Idiots.
-Hackus
Parent
Phhhbt... (Score:5, Funny)
Re:Phhhbt... (Score:2)
Marketing disguised as "Research" (Score:3, Interesting)
Business protection? (Score:4, Interesting)
Semantics (Score:5, Informative)
Also, the majority of the article is not about this issue, despite it being both the title and the Slashdot title. Instead, it's about current trends in rootkit design.
Does Open Source Encourage Rootkits? (Score:5, Insightful)
Re:Does Open Source Encourage Rootkits? (Score:2)
Hello, McAfee? We're trying to help you! (Score:5, Insightful)
Full disclosure is the best way to force the holes that make the rootkits possible to be addressed sooner rather than later. McAfee should be grateful that these things are getting posted where they can use them to make their offerings more secure. Instead, they come off as a bunch of whiners.
Access to info == Potential to do bad things (Score:5, Insightful)
OSS is bad, must outlaw it. (Score:2)
Security vendor FUD (Score:5, Insightful)
Security by obscurity has been proven time and again not to work. Nobody would find a security hole if it didn't exist. Likewise, if one does exist, if one person can find it so can someone else. The responsibility lies squarely with the developers.
Time for a bad analogy (seeing as how this is Slashdot and all): If the door of your house/apartment/room/basement was made of balsa wood rather than a decent hardwood (or a reinforced steel-belted Faraday Cage for you tinfoil-hatters), it would only be a matter of time before someone worked this out. And regardless of whether they boot your front door in and make off with your home entertainment system, or simply leave you a note that says "This door is so thin I can hear you whacking off to Buffy reruns from across the hall (by the way your dinner's getting cold, son)" you can bet if one person can work it out, so can someone else. And the next person might not just leave you a note. So, if the door is your responsibility you better fix it ASAP, or risk the consequences. And if not, you better fry the ass of whoever is responsible, or you'll still risk the consequences yourself.
Landlord won't give you a secure premises? Move out, and tell everyone about it. Or get a gun and a pit bull. Or barricade the door and use the kitchen window for access. Or all three. Windows has more holes than half a dozen slices of Jarlesberg? Switch to a more secure O/S, and add your voice to the complaints. Or install malware detection/removal tools. Or lock it down behind a firewall. Or all three. But don't just stick your head in the sand and hope nobody will notice, that approach just doesn't work.
If I were McAfee (Score:2)
McAfee? McAfee?!? (Score:2)
Mod McAfee (Score:5, Insightful)
Depends who you ask (Score:5, Funny)
MS: Oh let me asnwer, me me me me!
And the answer is..... (Score:4, Funny)
Headline doesn't match article... (Score:3, Interesting)
From the article: "The predominant reason for the growth in use of stealthy code is because of sites like Rootkit.com," says Stuart McClure, senior vice president of global threats at McAfee.
Again, to me, this isn't an "open source" problem as much as an "Internet/can we stop bad guys from getting together and working on bad things" problem.
I somehow doubt rootkit.com is that dangerous (or I have no idea if it's even malicious), but I think we're likely to see this general issue come up again with websites on bomb making techniques, biological weapons etc... What should the government/society do if there is a public website that researches technology that can be used to make mass casualty weapons?
Proliferation of rootkits mean opensource works (Score:5, Funny)
Who wants to be stuck with a closed source rootkit when your IRC channel and server change and you have no way to update it? Opensource empowers the user to take the best features of different rootkits to ensure that they get the rootkit that meets their needs.
Users can strip down rootkits to run on older hardware that would otherwise be discarded, or they can enable many new features that make these rootkits competitive with all of the current commercial rootkits currently being used.
With the proliferation and expansion of UNIX desktop software that tries to emulate more and more windows (mis)-features, I think the rootkits and opensource actually do a lot to ensure that the basic applicatio n and OS security model in Linux and GNOME and KDE desktop environments remain secure.
open source == freedom (Score:5, Insightful)
Live with it, it's better than the alternative.
Two words: Poor Journalism ... (Score:3, Informative)
If the journalist or her editor possessed the proper level of subject knowledge and/or integrity required for true journalism to occur, then this patently absurd question would never be asked in an article.
Problems with the article abound, but this lone article is far from the problem. Never the less, it is a quintessential example of the kind of absurd misunderstanding of the landscape of the subject matter combined with the complete disregard for the principle of the pursuit of truth as a core element of journalistic principle that is endemic to the disease of misinformation which fosters misinformation in society today.
A few points that should be obvious, but are missed completely by this article:
I could go on, but it is the misinformation propogated by piss poor journalism coupled with the lackluster education levels of the vast majority of the members of society in the free world that is the cause of most problems in the world today.
AntiVirus scare tactics: why the FUD keeps coming (Score:3, Informative)
Every time an AntiVirus company issues a fear mongering white paper, press release, or paid article placement in a magazine they get explosive coverage, dozens or hundreds of free articles written about them or their topic of interest, nearly all with links back to their original article. Within limits, bad publicity is publicity and publicity is good.
Meanwhile, companies like mine that are building next-generation network security systems (shameless link to Intrinsic Security AntiWorm [intrinsicsecurity.com]) and who try to be good network citizens must work a thousand times harder for links back to our web sites, don't get slashdot stories about us, don't get bazillions of blog entries linking back to us.
Mine is not the only company that suffers this problem. Every time a story by one of these highly bogus AntiVirus FUD spreading companies ticks you off, you should include at the end of your rant about it in your blog a few links to non-bogus internet security companies. We would greatly appreciate it.
Honestly, there are days when I feel like whipping up a FUD press release or scare mongering white paper. It would be easier than taking the publicity high road.
Re:Percentage? (Score:4, Funny)
0.01%
> What percentage of honda drivers are mass murderers?
80%
hope that helps you.
Parent
Freedom of speech? (Score:2)
If you teach them as a tool to avoid being ripped off however, you get away with it.
its all a grey area, and can get you put away if you are on the wrong side of the judge ( or the guy in the black van )