Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 30th, 2011, 05:55 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,201
Default Duqu hackers scrub evidence from command servers, shut down spying op

Quote:
By Gregg Keizer | Computerworld

The hackers behind the Duqu botnet have shut down their snooping operation, a security researcher said today.

The 12 known C&C (command-and-control) servers for Duqu were scrubbed of all files on Oct. 20, 2011, according to Moscow-based Kaspersky Lab
https://www.infoworld.com/d/security...ying-op-180485
  #2  
Old November 30th, 2011, 06:11 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

So now they regroup and show up elsewhere.
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old November 30th, 2011, 07:19 PM
Baserk's Avatar
Baserk Baserk is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Amstelodamum
Posts: 971
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

I can't make much sense from;
"The servers appear to have been hacked by bruteforcing the root password. (We do not believe in the OpenSSH 4.3 0-day theory - that would be too scary!)" link (Conclusion nr.3)

Rejection of a theory based on fear?
Why instead opt for the 'kinda seemingly bruteforcing a password in 8 minutes with afaics a few attempts' theory?
Anyone 'In-the-know' who can shed some light on this?
__________________
ROMANES EUNT DOMUS
  #4  
Old November 30th, 2011, 07:36 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,849
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

I'm sure i read that one of the AV vendors had grabbed ALL the data from at least one of the servers ? If so they have plenty of juice Not that i expect them to spill All the beans though, to us anyway

However they did say that they would publish more info later, still waiting !

Quote:
@ Baserk

Anyone 'In-the-know' who can shed some light on this?

Yeah, but as i've signed the Official Secrets Act, i'm sworn to secrecy, & if i did tell you i'd have to kill you Only kidding
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #5  
Old December 11th, 2011, 03:50 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,134
Post Re: Duqu hackers scrub evidence from command servers, shut down spying op

The December Windows Updates should tame some Duqu issues.
  #6  
Old December 18th, 2011, 09:03 AM
trismegistos's Avatar
trismegistos trismegistos is offline
Frequent Poster
 
Join Date: Jan 2009
Posts: 363
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

Quote:
Originally Posted by Baserk
I can't make much sense from;
"The servers appear to have been hacked by bruteforcing the root password. (We do not believe in the OpenSSH 4.3 0-day theory - that would be too scary!)" link (Conclusion nr.3)

Rejection of a theory based on fear?
Why instead opt for the 'kinda seemingly bruteforcing a password in 8 minutes with afaics a few attempts' theory?
Anyone 'In-the-know' who can shed some light on this?
I'm not in the know but interesting comments by posters in your link particularly coming from users Jesse Carter and Sam Crawford.
__________________
-http://www.veteranstoday.com/author/henderson/
-http://www.veteranstoday.com/2013/03/04/the-911-illusion-patsies-beneficiaries/
  #7  
Old December 18th, 2011, 12:50 PM
Baserk's Avatar
Baserk Baserk is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Amstelodamum
Posts: 971
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

Quote:
Originally Posted by trismegistos
I'm not in the know but interesting comments by posters in your link particularly coming from users Jesse Carter and Sam Crawford.
Interesting for sure! Thanks for reminding, Trismegistos.
__________________
ROMANES EUNT DOMUS
  #8  
Old December 18th, 2011, 03:05 PM
cozofdeath cozofdeath is offline
Infrequent Poster
 
Join Date: Dec 2011
Location: USA
Posts: 6
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

This crap is scary
  #9  
Old December 19th, 2011, 10:47 PM
MessageBoxA MessageBoxA is offline
Regular Poster
 
Join Date: Jun 2011
Posts: 52
Default Re: Duqu hackers scrub evidence from command servers, shut down spying op

Quote:
Originally Posted by Baserk
Anyone 'In-the-know' who can shed some light on this?

Pure speculation of course, but I'll add a comment; I have heard rumors of some information disclosure vulnerabilities that leak a single next-bit at a time. Most system administrators will lock down the CentOS servers with an iptables rule to slow down brute-force against the SSH daemon. Such as:


Quote:
/sbin/iptables -A INPUT -i eth0 -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 8 --rttl --name SSH -j DROP

If we were able to obtain a single bit at a time... and we know there are 8 bits to the byte... we could get 1 character of the password per minute.

Server "B" in Germany was brute forced in 8 minutes and would imply an 8-character password in our little fantasy scenario.

Best Wishes,
-MessageBoxA
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:33 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums