In millions of Windows, the perfect Storm is gathering

Did any of you get an email with the subject: '230 dead as storm batters Europe'?

I hope not.

A spectre is haunting the net but, outside of techie circles, nobody seems to be talking about it. The threat it represents to our security and wellbeing may be less dramatic than anything posed by global terrorism, but it has the potential to wreak much more havoc. And so far, nobody has come up with a good idea on how to counter it.

It's called the Storm worm. It first appeared at the beginning of the year, hidden in email attachments with the subject line: '230 dead as storm batters Europe'. The PC of anyone who opened the attachment became infected and was secretly enrolled in an ever-growing network of compromised machines called a 'botnet'. The term 'bot' is a derivation of 'software robot', which is another way of saying that an infected machine effectively becomes the obedient slave of its - illicit - owner. If your PC is compromised in this way then, while you may own the machine, someone else controls it. And they can use it to send spam, to participate in distributed denial-of-service attacks on banks, e-commerce or government websites, or for other even more sinister purposes.

Storm has been spreading steadily since last January, gradually constructing a huge botnet. It affects only computers running Microsoft Windows, but that means that more than 90 per cent of the world's PCs are vulnerable. Nobody knows how big the Storm botnet has become, but reputable security professionals cite estimates of between one million and 50 million computers worldwide. To date, the botnet has been used only intermittently, which is disquieting: what it means is that someone, somewhere, is quietly building a doomsday machine that can be rented out to the highest bidder, or used for purposes that we cannot yet predict.

Of course, computer worms are an old story, which may explain why the mainstream media has paid relatively little attention to what's been happening. Old-style worms - the ones with names like Sasser and Slammer - were written by vandals or hackers and designed to spread as quickly as possible. Slammer, for example, infected 75,000 computers in 10 minutes, and therefore attracted a lot of attention. The vigour of the onslaught made it easier for anti-virus firms to detect the attack and come up with countermeasures. In that sense, old-style worms were like measles - an infectious disease that shows immediate symptoms.

Storm is different. It spreads quietly, without drawing attention to itself. Symptoms don't appear immediately, and an infected computer can lie dormant for a long time. 'If it were a disease,' says one expert, Bruce Schneier, 'it would be more like syphilis, whose symptoms may be mild or disappear altogether, but which will come back years later and eat your brain.'

Schneier thinks Storm represents 'the future of malware' because of the technical virtuosity of its design. For example, it works rather like an ant colony, with separation of duties. Only a small fraction of infected hosts spread the worm. A much smaller fraction are command-and-control servers; the rest stand by to receive orders. By only allowing a small number of hosts to propagate the virus and act as command-and-control servers, Storm is resilient against attack because even if those hosts shut down, the network remains largely intact and other hosts can take over their duties.

More fiendishly, Storm doesn't have any noticeable performance impact on its hosts. Like a parasite, it needs the host to be intact and healthy for its own survival. This makes it harder to detect, because users and network administrators won't notice any abnormal behaviour most of the time.

And instead of having all hosts communicate with a central server or set of servers, Storm uses a peer-to-peer networking protocol for its command-and-control servers. This makes the botnet much harder to disable because there's no centralised control point to be identified and shut down.

It gets worse. Storm's delivery mechanism changes regularly. It began as PDF spam, then morphed into e-cards and YouTube invites. It then started posting blog-comment spam, again trying to trick viewers into clicking infected links. Similarly, the Storm email changes all the time, with new, topical subject lines and text. And last month Storm began attacking anti-spam sites focused on identifying it. It has also attacked the personal website of a malware expert who published an analysis of how it worked.

At the moment, nobody knows who's behind this. Is it a Russian mafia operation? An al-Qaeda scheme? The really creepy thing is that, to date, the controllers of Storm have used it for such relatively trivial purposes. The suspicion has to be that they are biding their time, waiting for the moment when, say, 100 million naive Windows users have clicked on an infected link and unwittingly added their machines to the botnet.

Only then will we know what a perfect storm in cyberspace is like.

john.naughton@observer.co.uk

I bet you anything our zionuts are involved.

Posted in Submitted by qrswave on Mon, 2007-10-22 05:01.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

The article is excellent, but this part is BULLSHIT:

"At the moment, nobody knows who's behind this. Is it a Russian mafia operation? An al-Qaeda scheme? "

The ONLY "Russian Mafia" that has major operations is the "Jewish Russian Mafia".

Secondly, Al-queda was an Israeli-Khazar-UK-US invention. The SCATTERED (unaffiliated) resistance fighters ADOPTED that name AFTER such and such events (e.g. Jewish 911 False Flag).

______________________________

BUT EVEN MORE IMPORTANT:

There are some very common technologies, each slightly different from each other.

HOWEVER, there is ONE that stands out, ONE that is insecure, ONE that was designed as a spyware/malware ---- this ONE was designed to give ROOT (aka 'Administrator') ACCESS.

Of all the popular web technologies, from Perl to Python to Ruby.....

........ PHP ..........

........ PHP stands out as malware ............

It was PURPOSELY DESIGNED that way!
______________________________

Guess who "owns/controls" the "development" of PHP???!!!!

A little company called Zend based in Israel.

GNU/Linux and FS (aka FLOSS - Free Libre Open Source Software) places a lot of effort and emphasis on: 1) Freedom, 2) Quality code, and 3) Secure software.

But, in every version, in every 'update', in every revision, from PHP 4 to PHP 5, Zend has largely ignored the MAJOR security issues, and KNOWN BACK-DOORS (i.e. these allow intruders through php to gain root access quite easily).

>>>>>>>>>>>>>>> Now, why is that???!!!

The Great Revealer | Mon, 2007-10-22 07:29

There are quite a few articles about this storm worm out there. It is both shocking and amazing how this worm has been designed, very well planned and using state of the art methods.

Switch to Linux and you won't have to worry about spy ware or viruses, worms or trojans.

I switched about a year ago and haven't looked back since.

p.s. I don't know how accurate the claims are against PHP, I also think a lot of you people are obsessed with finding a conspiracy behind everything, but what do you think this site runs on? It uses Drupal and PHP.

Reader | Mon, 2007-10-22 14:31

Rootkits aren't detected by anti-virus or anti-spyware. I strongly recommend everyone install the AVG series - Rootkit detector, anti-spyware, and anti virus. It's great software and it's free, although I ask you to support them by purchasing a license so they can continue their good work.

Get AVG products here

Claymoremind | Tue, 2007-10-23 01:10

I feel very silly but I have to ask... what is PHP?? It is obvious that I was expected to know... but I don't think I do? Can someone please help?

Cherifa Sirry | Tue, 2007-10-23 07:20

Its built in, to all of them, even Linux. The difference is, that with windows, they can have the subcontractors do it. With a real computer, they have to use the official door and do it themselves.

Anybody who thinks theyre being sneaky is deluded. You can be tracked 6 ways from Sunday and your computer isnt closed if they dont want it to be.

But they dont care anyway. We are all being trained to feel helpless and hopeless. Thats why we know all this other awful shit. A daily barrage of reinforcing evidence to create that reality. Thats all it is.

Of course.. you joo-bashers...you might want to stay away from windows, because I betchya most of those subcontractors are them.

Other than that though, they give not a shit about what you know, post, link to, or hold an opinion about. They want you to lose faith. Not only that, you do their work for them by spreading the 'news' even further. Thats the whole point of it all.

Even their supposed screwups aid their goal. It really is a thing of hideous genius.

But really.. if you are lying awake because you think they might be on to you?.. dont. They dont care.

geeez | Tue, 2007-10-23 07:56

Why bash a Jew
Lie cash sway you?

In the alternative
When a wall trauma sieve

Why bash a Jew
Die trash say you?
_______________
"As often as Herman had witnessed the slaughter of animals and fish, he always had the same thought: in their behavior toward creatures, most of mankind are Nazis"
--Isaac Bashevis

Stern Gang | Tue, 2007-10-23 08:36

I feel very silly but I have to ask... what is PHP??

PHP is a programming language used to create database-driven, dynamic websites like this one. Any site where the end user can create and store content - like blogs for instance, will have a database behind the scenes and a programming language like PHP to store and fetch data from the database and to present retrieved data in a form capable of being displayed in a web browser.

Sullivan | Wed, 2007-10-31 14:45

unclesam wakeup

Meet The Greatest President


...we never had

US Gross National Debt

Just Foreign Policy Iraqi Death Estimator