Slashdot Log In
McColo Briefly Returns, Hands Off Botnet Control
Posted by
kdawson
on Tuesday November 18, @06:43PM
from the should-have-used-a-stake-through-the-heart dept.
from the should-have-used-a-stake-through-the-heart dept.
A week ago we discussed the takedown of McColo (and the morality of that action). McColo was reportedly the source of anywhere from 50% to 75% of the world's spam. On Saturday the malware network briefly returned to life in order to hand over command and control channels to a Russian network. "The rogue network provider regained connectivity for about 12 hours on Saturday by making use of a backup arrangement it had with Swedish internet service provider TeliaSonera. During that time, McColo was observed pushing as much as 15MB of data per second to servers located in Russia, according to ... Trend Micro. The brief resurrection allowed miscreants who rely on McColo to update a portion of the massive botnets they use to push spam and malware. Researchers from FireEye saw PCs infected by the Rustock botnet being updated so they'd report to a new server located at abilena.podolsk-mo.ru for instructions. That means the sharp drop in spam levels reported immediately after McColo's demise isn't likely to last."
Related Stories
[+]
Washington Post Blog Shuts Down 75% of Online Spam 335 comments
ESCquire writes "Apparently, the Washington Post Blog 'Security Fix' managed to shut down McColo, a US-based hosting provider facilitating more than 75 percent of global spam. " Now how long before the void is filled by another ISP?
[+]
McColo Takedown, Vigilantes Or Neighborhood Watch? 194 comments
CWmike writes "Few tears were shed when alleged spam and malware purveyor McColo was suddenly taken offline last Tuesday by its upstream service providers. But behind the scenes of the McColo case and another recent takedown of Intercage, a ferocious struggle is taking place between the purveyors of Web-based malware and loosely aligned but highly committed groups of security researchers who are out to neutralize them. Backers claim that the effort to shut down miscreant ISPs is needed because of the inability of law enforcement agencies to deal with a problem that is global in nature. But some question whether there is a hint of vigilantism behind the takedowns — even as they acknowledge that there may not be any other viable options for dealing with the problem at this point."
[+]
Massive Botnet Returns From the Dead To Spam On 201 comments
CWmike writes "Gregg Keizer reports that the big spam-spewing Srizbi botnet, shut down two weeks ago when McColo was shuttered, has been resurrected and is again under the control of criminals, security researchers said today. As of late Tuesday, infected PCs were able to successfully reconnect with new command-and-control servers, which are now based in Estonia, said Fengmin Gong, chief security content officer at FireEye. The comeback confirms what researchers noted last week, that Srizbi had a fallback strategy. So, in the end, that strategy paid off for the criminals who control the botnet."
[+]
Estonian ISP Shuts Srizbi Back Down, For Now 185 comments
wiedzmin writes "In response to the recent resurrection of the Srizbi botnet, an Estonian ISP has shut down the hosting company that was housing its new control servers. Starline Web Services, based in Estonia's capital Tallinn, had become the new home for the Srizbi botnet control center after the McColo hosting company (which was taken down earlier this month) has briefly come back to life last week, allowing the botnet to hand-off control to the Estonian network. After Estonia's biggest ISP Linxtelecom demanded that Starline Web Service be taken offline, the newly acquired Srizbi control servers went down with it. However, as the rootkit is armed with an algorithm that periodically generates new domain names where the malware then looks for new instructions, it is only a matter of time before a new set of control servers is created and used to manipulate one of the biggest spam botnets in the world."
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

Uncongested Relief! (Score:5, Informative)
Reply to This
Re:Uncongested Relief! (Score:5, Insightful)
Speaking of wild fantasies about idealist notions... Ever wanted to be paid for work that wasn't asked for or justified at the time?
Reply to This
Parent
Alas... (Score:5, Insightful)
This is an example of the old saying "The Internet treats censorship as damage and routes around it".
Unfortunately, this is happening for the bad guys as well as us.
Reply to This
Re:Alas... (Score:5, Funny)
The Internet could route around McColo too, if say, it were burned to the ground in the middle of the night. Or barring that, some 'hard pipe-hittin' thugs' somehow gained access to the building and went on a smashing spree. Anyone want to set up a donation box to hire somee thugs?
After all, what's this doing for us? It sounds almost like..well..treason! A foreign power is accessing systems in the United States and is using those systems to infect/enslave other systems. I wouldn't shed a tear if a black ops detachment traced the stuff back to its source and C4ed the offending equipment/operators in Russia or wherever they're coming from.
Reply to This
Parent
This just in! (Score:5, Funny)
Reply to This
this is great news (Score:4, Funny)
My penis thanks them, my very very large penis which is located in a recently refinanced home, that is.
Now as soon as my good friend MR AUSTINE OWOH is able to complete the transfer of my long lost uncle's estate from probate in Nigeria to my onshore checking account, I will be perfect, perfect with a very very large penis, that is.
Reply to This
Russian C&C is Actually Less Desirable (Score:5, Insightful)
Reply to This
Re:Let's turn TeliaSonera into a smoking crater ne (Score:5, Informative)
Reply to This
Parent
It's not the data, it's the cooperation. (Score:5, Interesting)
This pretty much shows how certain ISP's help spammers. Particularly since they did not IMMEDIATELY bring up their backup link. Instead they waited until the weekend.
Reply to This
Parent
Re:Let's turn TeliaSonera into a smoking crater ne (Score:5, Insightful)
Er, you can't communicate with a botnet with a harddrive, you know.
Reply to This
Parent
Re:Let's turn TeliaSonera into a smoking crater ne (Score:5, Informative)
Apparently TeliaSonera shut down the link as soon as they realised what was happening - the contract was through a proxy company.
See the Register [theregister.co.uk] article for more details.
So we can't really blame TeliaSonera.
Why the spamming bastards didn't just courier a hard drive to Russia instead is a mystery, though.
Reply to This
Parent
Re:Let's turn TeliaSonera into a smoking crater ne (Score:5, Interesting)
The article said they had to update the command & control data for the botnets. The 'nets won't let just any computer control them, and this Russian server probably wasn't on the master list, so they needed to get back online with their old DNS hostname first.
Reply to This
Parent
Re:Epic Fail. (Score:5, Interesting)
Let's say you rent some space anf open a small convenience store. You work hard and make a modest living. Then your landlord rents out the shop next door to a crack dealer who's thriving business attracts a swarm of lowlifes who destroy the neighborhood. Are you going to be upset with the neighborhood watch when they make a fuss, or are you going to be upset with your landlord?
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
And if the police do nothing?
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
If you have "malware" on your computer, your private data is already being exposed. It could just as well be a bot net operator whose combing through your data. Who'd you rather have digging through your infected computer?
Besides, the guys used possibly ill-gotten information that was true to convince the upstream provider to shut down the ISP. The experts didn't run into the data center, pulling plugs in a rage...though that might make a neat comic book. In truth, you should blame the upstream providers. Seriously, this isn't Governments running around meting out justice. This is companies listening to private organizations.
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
What are you smoking? Or rather, are you someone arguing a point without a clue.
Whether they had any legit customers is suspect. If they did, I'm sure they would have come to light very quickly.
No, your ISP will be notified about spam originating from its networks and they'll either deal with the user who is undoubtedly violating their TOS or the ISP's IP range will be entered into mail blackhole lists. Nothing new there.
Unlikely, and sadly you probably won't get punted off the net like you should. Instead, your computer will continue to be abused for the purposes of these criminals.
Your efforts to compare this to the drug war are completely irrational, as their causes and symptoms are wildly different. On top of that, there was no government involvement here.
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
Well, frankly, yes. An ISP that turns a blind eye to such activities as accused, is just as good as helping the bad guys. And guess what... this is a war where almost anyone is willing to take casualties to end it. Now the innocent bystanders know they were dealing with shit for an ISP and have a big sign in front of their face to move to someone more reputable. It is a win for everyone, except the nefarious spammers/botnet operators that were put out by it. There is no sympathy for these folks.
Reply to This
Parent
Re:So what's YOUR solution? (Score:5, Insightful)
1. I don't have a solution, I'm just considering the ethical aspect.
What is unethical about pointing out MASSIVE violation of terms of service by an ISP to their provider? The ISP has a duty to obey the terms they agreed to, and if it can't or won't it gets cut off. Just like you or I would get cut off by our upstream for violating whatever agreement we may have in place.
2. I'd rather deal with spam, malware, and con artists clogging the internet than vigilantes blowing holes in it.
Considering the sheer cost of cleaning up this bullshit, I doubt many share the same opinion. And the intenet was designed to route around holes in it. Theoretically at least.
3. As to who's protecting them -- it's not a question of who but what. In this case, economics.
No. There are definately quite a few "who"s in this mix. Like the greedy bastards who look the other way while their customers commit felonies. They are accessories to the crimes of their clients if they don't cut them off for their criminal bullshit.
4. It has taken this long because until now people were restrained by ethical considerations prevalent within the community. However, a certain moral flexibility seems to be developing now out of frustration. This can only end badly.
Are you kidding? People have been black-holed for decades on the internet for stuff like this.
WHERE IS THE ETHICAL ISSUE WITH TELLING A PROVIDER THAT THEIR CLIENTS ARE IN GROSS VIOLATION OF THEIR ACCEPTABLE USE POLICY????
Or worse.
Either they need to act on it when its pointed out or they will find themselves having to screen their traffic for content because of some cockamamy law passed because they were KNOWINGLY looking the other way while the sold space to kiddy-porn traders after numerous people pointed it out.
Reply to This
Parent
Re:So what's YOUR solution? (Score:5, Insightful)
Canter and Siegel were kicked off their ISPs in decently short order 14 years ago (1994) after starting to spam. See:
https://secure.wikimedia.org/wikipedia/en/wiki/Canter_and_siegel
Anyone familiar with the history of spamfighting will be able to point to numerous examples every year since then, of escalating size and complexity.
Vigilantism is acting extrajudicially AND illegally as a community group to right a wrong or combat a criminal. It's an inappropriate model here - the response was entirely legal. It was done by people who, contrary to your assertion, were openly identified and stood and stand by their information.
If people were assassinating botnet operators or burning McColo datacenters down, THAT would be vigilantism. This is just community response.
Reply to This
Parent
Re:So what's YOUR solution? (Score:5, Interesting)
Actually, its my PROFESSIONAL duty. Good luck suing me for pointing out that you are committing a felony to your provider. I have the feds computer crimes department on speed-dial.
If a shit-ton of malicious crap and SPAM/malware are coming into MY client's network (causing ME and MY CLIENTS a material loss), or if my client's systems have been infected with a botnet controlled from YOUR IP space(a felony), it is your responsibility to address that when I tell you about it. If you don't I'll talk to YOUR provider. Or would you rather I call the FBI and tell them you're systematically attacking my client?
I don't even have to be involved actually, I can just tell MY client's providers (some of which are backbone providers) what I see coming from YOUR network and they have entire departments to deal with that type of shit. So you can fight Level 3 and Verizon for all I care. Your customers are attacking their customers, they can cut you off just as easily.
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
What's to prevent them from doing this every few months and leaving a trail of dead service providers in the wake of our new definition of "justice" as the botnet owners simply hop from one provider to the next?
That's simple - ISPs that value their continued existence will enforce their anti-spam/botnet policies rather than look the other way and take money from anyone who can pay. This isn't vigilantism, it's the upstream ISP dropping connectivity for contract violations when informed of the situation at one of their downstreams.
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
Sigh
Way to ignore the obvious facts here.
The ISP had the option of blocking off the spammers.
They did not. Eventually, ISP who do not stop spam will be disconnected. The ISP that supported this botnet SHOULD be a shambles, they became that when they decided not to stop their clients spamming.
What will prevent them from going to new ISP is that ISP probably dont like being put out of business completely.
This should be a salutory lesson for the next ISP that is told they are sending spam.
I see no ethical issues, unless you are a spammer.
But I suspect troll is closer to the mark.
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
The problem is, once you give the government jurisdiction to decide who can and cannot use the Internet, they will use that power to further their own interests rather than yours.
No politician will ever vote to decrease his own power.
Reply to This
Parent
Re:Epic Fail. (Score:5, Insightful)
if spam wasn't profitable nobody would be doing it
Not necessarily. Spam may not be profitable, spamming may be. If you convince someone to pay you to spam for them, whether or not the spam itself generates any profit, you hustled them out of the money.
Reply to This
Parent
Re:Can they hear me now? (Score:5, Interesting)
Please, dont do this.
These servers were plugged off on early monday (local moscow time), as soon we got contact with podolsk-mo. The networks of bad guys were:
62.176.16.0/22 (they got from local ISP)
91.200.144.0/22 (client's network)
Reply to This
Parent