|
|
|
No love for Microsoft s Waledac takedown |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Présentation : A couple of weeks ago, I wrote on the story that Microsoft had obtained a court order to take down numerous domains associated with the Waledac botnet. It s now been a period of time since then, did the takedown actually affect spam levels out of waledac According to Spamhaus in a statement granted to ZDNet, it had little effect, if any The throttling of Waledac, which Microsoft claimed to have achieved by means of legal action last week, has led to no appreciable reduction of junk mail coming from the botnet, anti-spam organisation Spamhaus told ZDNet UK on Tuesday. The amount of spam coming from Waledac before the takedown was less than one percent of all spam , and that hasn't changed much, said Spamhaus chief information officer Richard Cox. There's been a slight change, nothing major, and we would expect it to be a lot different. According to Cox, and Sophos Labs, Microsoft s targeting of Waledac is odd because it is such a small botnet and accounts for so little traffic I've been chatting to colleagues, and we don't understand why Microsoft took these measures against Waledac , said Cox. There are other botnets, for example Zeus, that do immense harm fraud-wise. Computer security company Sophos agreed that it had seen no appreciable difference in the amount of spam coming from Waledac after Microsoft's action. We can't see a direct correlation between Microsoft's takedown efforts and a reduction in spam from Waledac, said Fraser Howard, a principal researcher at Sophos Labs. In addition, there has been no noticeable reduction in spam volumes overall, according to Howard. If the botnet contributed significantly to spam, we would have expected to see a sharp step down in spam volumes, said Howard. There is no distinct difference between before and after the takedown. Not everyone agrees that the Waledac takedown was fruitless, though. Security company F-Secure said on Wednesday March 3 it had seen a drop in spam coming from Waledac zombies, and a decrease in the number of binary samples from Waledac-related messages. Microsoft might have decapitated Waledac , it should be interesting to watch, said F-Secure researcher Sean Sullivan. Sullivan said the ability of the botnet to spread malware may have been severely inhibited by Microsoft's action. From 8 February to 21 February, F-Secure detected 58,913 instances of Waledac malware attempting to circumvent F-Secure security software. After the takedown, from the 22 February until 3 March, F-Secure detected 1,113 instances. Despite this respite in Waledac attacks, Sullivan said F-Secure would not be surprised to see the botnet come back. So, according to this article, and some other sources I have talked to, here is the reaction to Microsoft s take down Waledac was a small player to begin with The takedown didn t do much at all Although in some places, it did have a noticeable effect Waledac will be back eventually The reason for Waledac s resiliency is that while several domains were taken offline, Waledac also relies on peer-to-peer traffic. In that regards, it doesn t matter if a domain is taken down because the nodes are not communicating with it anyway. Thus, if that is the case, then it suggests that Waledac doesn t rely on domains for spam distribution and instead uses it for something else, such as pointing to payload in spam.
Les mots clés de la revue de presse pour cet article : microsoft waledac Les videos sur SecuObs pour les mots clés : microsoft Les mots clés pour les articles publiés sur SecuObs : microsoft Les éléments de la revue Twitter pour les mots clé : microsoft
Les derniers articles du site "Terry Zink's Anti malware Blog" :
- FTC kills porn spam ISP - Hotmail to add more security features - A little bit of humor - Conficker - The Enemy Within - China to stop spying on its people humor kind of - What if Sideshow Bob were a spammer - No cyberattack on Wall Street - Cracks in armor is how phishers win - Why are there so few spam lawsuits - Email rules to live by, for marketers
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, microsoft, attaque, réseau, outil, vulnérabilité, audit, système, virus, internet, données, metasploit, présentation, linux, bluetooth, protocol, source, vista, scanner, réseaux, shell, rootkit, engineering, conférence, trames, paquet, téléphone, wishmaster, sysun, noyau, mobile, libre, botnet, https, téléphones, rapport, mémoire, scapy, google, patch, reverse, navigateur, snort |
| Mini-Tagwall de l'annuaire video : | | | | security, vmware, virus, biometric, metasploit, windows, lockpicking, password, botnet, tutorial, attack, network, linux, exploit, crypt, source, iphone, secconf, server, shmoocon, conficker, engineering, virtual, wimax, ettercap, rootkit, wireshark, reverse, hackitoergosum, cisco, internet, systm, hacker, firewall, wireless, openbsd, meterpreter, openssh, access, conference, knoppix, arduino, backtrack, brucon, remote |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|