Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Deloder worm has resurfaced. Watch your privacy!

0 views
Skip to first unread message

Kyle Lai

unread,
Mar 28, 2003, 12:07:08 PM3/28/03
to
DeLoder worm has resurfaced during the past several days. Here are
some info missed by many anti-virus analyses...

Deloder worm leaves a VNC (free remote control software) service
running on the infected systems, and it also set a VNC password, which
eventually allowed anyone with malicious intent (hackers) to get in
via VNC. There are tens of thousands of Windows 2000 & XP systems out
there that are infected with Deloder (according to CERT, possibly
140,000 on 3/17/2003).

The password that was set by Deloder was cracked by KLC Consulting
Security Team, and the information is available in the article below.
With this password in hand, anyone can detect (not too difficult) and
connect to infected systems and watch the computer screen, take over
the keyboard and mouse control, or just spy on every single keystroke
and mouse move by the infected users. Watch out, and protect your
privacy!

The article below also has methods of detection, fixes, and
recommendation for protections against future worm/Trojan attacks.

An updated Deloder worm analysis is available at URL is at
http://www.klcconsulting.net/deloder_worm.htm

Nick FitzGerald

unread,
Mar 28, 2003, 7:21:11 PM3/28/03
to
"Kyle Lai" <ky...@kylelai.com> wrote:

> DeLoder worm has resurfaced during the past several days. ...

"resurfaced" as in "we are seeing a rash of new infections of the
original" (which is what "resurfaced actually means) or as in "there
is a new variant of it which is getting some traction".

> ... Here are


> some info missed by many anti-virus analyses...

Not so much "missed by their analsyses" as "won't be detected by virus
scanners".

Now, you're a clever chap Kyle, so can you suggest any reason why an
antivirus developer might chose to _not_ detect a legitimeta remote
control application such as VNC??

> Deloder worm leaves a VNC (free remote control software) service
> running on the infected systems, and it also set a VNC password, which
> eventually allowed anyone with malicious intent (hackers) to get in
> via VNC. There are tens of thousands of Windows 2000 & XP systems out
> there that are infected with Deloder (according to CERT, possibly
> 140,000 on 3/17/2003).

Could you provide a reference for that CERT claim of 140,000 Deloder
infections? I recall CERT (and saw it in other reports whose sources I
cannot divulge) saying on 11 March that a 140,000+ GT-bot network had
been found:

http://www.cert.org/advisories/CA-2003-08.html

> The password that was set by Deloder was cracked by KLC Consulting

> Security Team, ...

...using a simple brute-force VNC password cracker...

> ... and the information is available in the article below.


> With this password in hand, anyone can detect (not too difficult) and
> connect to infected systems and watch the computer screen, take over
> the keyboard and mouse control, or just spy on every single keystroke
> and mouse move by the infected users. Watch out, and protect your
> privacy!

And without your article, very few people would have taken the time or
effort to crack the password. So, the upshot of your "work" is that
many more people can now easily take advantage of the existence of what
you claim (CERT claims) is a 140,000 strong network of machines
unknowingly running VNC with this configuration.

Why did you not include download and operating instructions for
obtaining and using a port scanner? Then even those readers who may be
too dense to know how to do that can join the ranks of the "hacker
wannabes" your analysis has just assisted.

I am interested in how you justify your membership of the ISSA in light
of its code of ethics:

http://www.issa.org/codeofethics.html

and your actions in publicly releasing the VNC password used by Deloder.
I see your actions as contrary to all but the last two of the items in
that code, specifically:

* Perform all professional activities and duties in accordance with
the law and the highest ethical principles;

As no formal list of "the highest ethical principles" is given, my
highest ethical principles must be considered as suitable as the basis
for comparison. As I would not have released that information because
doing so would violate my ethical principles, your releasing the
information puts you in beach of that point of the ISSA's code.

* Promote good information security concepts and practices;

As your actions are in breah of "good security concepts and practices"
(by being in breach of other items in the ISSA's ethical code) you are,
obviously, also in breach of this one because acting in the role as an
information security professional and publicly promoting yourself
through your unethical acts cannot be seen as promoting good practice.

* Maintain the confidentiality of all proprietary or otherwise
sensitive information encountered in the course of professional
activities;

The password to an illicitly installed system backdoor, present by your
own estimates or those of another professional or body whose opinion you
respect on 140,000+ machines on the public Internet is senstive
information. You clearly became aware of this in the course of your
professional activities.

* Discharge professional responsibilities with diligence and
honesty;

You seem to have posted this message, and put your analysis on your web
site with diligence and honesty, but as doing so _with the report of the
otherwise secret VNC password_ constituting a breach of ethics, your
preofessional responsibilities have not been discharged diligently (you
missed that your attempts at self-aggrandizement through publishing more
detail than anyone else was unethical).

* Refrain from any activities which might constitute a conflict of
interest or otherwise damage the reputation of employers, the
information security profession, or the Association;

Need I spell out why you are in berach of this one?

Of course, probably other professional organizations with similar ethical
codes to which you are affiliated -- I didn't bother to check.

I wonder if you have enough conviction to report yourself to the ISSA
(and any other organizations to which you affiliate yourself whose ethical
codes you will also likely have broken) and resign your membership?

Oh, and you'd better report yourself to (ISC)2 for an ethics review
panel hearing to consider revoking your CISSP:

https://www.isc2.org/cgi/content.cgi?category=12

> The article below also has methods of detection, fixes, and
> recommendation for protections against future worm/Trojan attacks.

It also recklessly exposes information better not made public.

There are good reasons why measured analyses of Deloder do not include
the password information. Further, there are compelling ethical
reasons for them to not include that information. The rest of your
analysis is a good and useful contribution, but it and your ethical
reputation are spolied by a couple of sentences.


--
Nick FitzGerald


John

unread,
Mar 28, 2003, 11:00:33 PM3/28/03
to
Nick FitzGerald, while drooling on their self, scribbled:

What a crock! S/he put it out, because if left up to "them" (those who are
supposed to fix the 'problem'), they'd never get off their asses until 6 months
from now! As a matter of fact, M$ has said themselves they won't be 'fixing'
some exploit/bug/security flaw in NT4, because it's just too much of a pain in
the butt (essentially).
These things need to be exposed, so that the company(s) who make these
apps/software, quit hiring sloppy/lazy/scriptkiddies, and get back to
*QUALITY*, not 'how fast can you guys turn this out so we can sell it?'. Funny
how the opensource community gets right on these kinds of things almost
instantly, meanwhile, M$ and its cronie companies sit on it to 'see if it's a
bad as it might be'. Pretty pathetic.

John
--

My penguin eats butterfly's.

Nick FitzGerald

unread,
Mar 29, 2003, 7:30:08 AM3/29/03
to
"John" <Yoch...@yahoo.com> wrote:

Note: "Followup-To: overruled and original posting list restored.

Note^2: A good sign to start with one is dealing with an arsehole and/or
plonker -- he wants everyone to see his opinion but wishes to "restrict"
the response of those he replies to.

<<snip entire quote of my post>>


> What a crock! S/he put it out, because if left up to "them" (those who are
> supposed to fix the 'problem'), they'd never get off their asses until 6 months
> from now! As a matter of fact, M$ has said themselves they won't be 'fixing'
> some exploit/bug/security flaw in NT4, because it's just too much of a pain in
> the butt (essentially).
> These things need to be exposed, so that the company(s) who make these
> apps/software, quit hiring sloppy/lazy/scriptkiddies, and get back to
> *QUALITY*, not 'how fast can you guys turn this out so we can sell it?'. Funny
> how the opensource community gets right on these kinds of things almost
> instantly, meanwhile, M$ and its cronie companies sit on it to 'see if it's a
> bad as it might be'. Pretty pathetic.

Excuse me, but what -- apart from displaying your complete lack of
intellect -- has that to do with what was being discussed?

A quick recap for the cranially challenged (John included)...

Kyle posted about a Windows 2000/XP-specific worm that spreads through
weakly passworded admin shares on machines running those OSes. It does
this by the trivially simple expedient of generating an IP address and
repeatedly attempting the rough programmatic equivalent of

net use * \\<ip>\IPC$ <pwd>

where <ip> is the randomly generated IP address and <pwd> is one of
approximately 80 in a hardcoded list in the worm's code including the null
string (representing a blank password). In short, it does not involve an
"exploit" in the sense of involving something the vendor can fix and is
solely an "exploit" of administrative or user laziness and/or stupidity.
Hell, Unix boxes are just as "vulnerable" to such flaws to the extent their
typical users are as stupid/lazy as to set null or otherwise laughably weak
passwords on critical network accessible resources.

Anyway...

WTF this might have to do with the quality of Microsoft's software (which
I agree is generally poor), the speed with which Microsoft (or any other
s/w developer) produces patches for its s/w once someone points out a
grievous flaw, or any of the other topics you vaguely touched on is a
mystery to me. You also entirely failed to comment one way or the other
on my critcisims of Kyle's lack of professional ethics in publishing the
"magic" password that allows anyone with that password and access to a
machine suspected of having been compromised by this worm full access to
it. In short, your post was entirely off-topic as a reply to mine.

Given you tried to restrict my, or any other, response to your message to
alt.comp.virus, one has to suspect that you are vying for the "a.c.v tosser
of the year" award. (Perhaps you know that Sooooog has left a.c.v and thus
see this as the big chance for your breakthrough year vis a vis the award?)


--
Nick FitzGerald


Kyle Lai

unread,
Mar 29, 2003, 12:08:51 PM3/29/03
to
"Nick FitzGerald" <ni...@virus-l.demon.co.uk> wrote in message news:<3e84...@clear.net.nz>...> There are good reasons why measured analyses of Deloder do not include

> the password information. Further, there are compelling ethical
> reasons for them to not include that information. The rest of your
> analysis is a good and useful contribution, but it and your ethical
> reputation are spolied by a couple of sentences.


I disagree. I think you missed the point. Plus, I don't think
anti-virus vendors looked at registry values other than the "start-up"
registry values.

If public did not get informed about the true problem and exploit, and
what the worm has done, how can they protect themselves from the
variants of this worm, which always happens? In addition, if people
don't get the information on what EXACTLY the worm did, how do you
know what proper actions to take to protect end-users?

CERT advisory, http://www.cert.org/advisories/CA-2003-08.html,
mentioend that 140,000 connections on an IRC network, which are the
systems infected with Deloder type of worms.

If you think the advisories and analysis are generated good awareness,
why are there still so tens of thousands of computers out there
infected with Deloder and other worms and Trojans, and why aren't they
doing anything about it?

That's why I published my article.

Regards,
/Kyle

Kyle Lai, CISSP, CISA
www.klcconsulting.net

John

unread,
Mar 29, 2003, 4:51:52 PM3/29/03
to
Nick FitzGerald, while drooling on their self, scribbled:

> "John" <Yoch...@yahoo.com> wrote:


>
> Note: "Followup-To: overruled and original posting list restored.
>
> Note^2: A good sign to start with one is dealing with an arsehole and/or
> plonker -- he wants everyone to see his opinion but wishes to "restrict"
> the response of those he replies to.

Get yourself a newsreader that actually works correctly. Anyone else who has
replied to a post by me whether new or in a thread has had no problems. You
sure do get pissed easy when it's pointed out how you may be wrong about
something don't you. I've not got any "restrictions" set on *any* post I put
up, you whiny baby.

>
> <<snip entire quote of my post>>
>> What a crock! S/he put it out, because if left up to "them" (those who are
>> supposed to fix the 'problem'), they'd never get off their asses until 6
>> months from now! As a matter of fact, M$ has said themselves they won't be
>> 'fixing' some exploit/bug/security flaw in NT4, because it's just too much of
>> a pain in the butt (essentially).
>> These things need to be exposed, so that the company(s) who make these
>> apps/software, quit hiring sloppy/lazy/scriptkiddies, and get back to
>> *QUALITY*, not 'how fast can you guys turn this out so we can sell it?'.
>> Funny how the opensource community gets right on these kinds of things almost
>> instantly, meanwhile, M$ and its cronie companies sit on it to 'see if it's a
>> bad as it might be'. Pretty pathetic.
>
> Excuse me, but what -- apart from displaying your complete lack of
> intellect -- has that to do with what was being discussed?

<snip 'let's try to baffle them with BS'>

My reply as a 'whole', you sub-moron, was just that. You're so full of
yourself you refuse to 'see' or 'hear' anything but what spews from your own
mouth or ass. If you can't figure out what my reply was about, perhaps the lack
of any intellect is on your part. Where did I refute any of the 'technical'
parts? If you were as smart as you think yourself to be, you should know
*exactly* to what I was replying to. Here, let me help you. This is part of
what you posted, and (the main) part of what I was replying to:

"I am interested in how you justify your membership of the ISSA in light
of its code of ethics:

http://www.issa.org/codeofethics.html

and your actions in publicly releasing the VNC password used by Deloder.
I see your actions as contrary to all but the last two of the items in
that code, specifically:

* Perform all professional activities and duties in accordance with
the law and the highest ethical principles;

As no formal list of "the highest ethical principles" is given, my
highest ethical principles must be considered as suitable as the basis
for comparison. As I would not have released that information because
doing so would violate my ethical principles, your releasing the
information puts you in beach of that point of the ISSA's code."

If you knew enough to deflate that over-sized ego of yours (wouldn't hurt your
head any either), the 'problem' was already made public. The OP put the url,
which by the way also contained any 'fixes'. You jumped on your ISSA white
horse so damned fast, you forgot your sword to smite the 'bad OP'. So instead
you try to tongue lash him with your 'I'm more ethical than you, you scumbag'
BS. Now that someone (me) responds to a portion of your post, you've got your
panties wadded so far up your ass, it's tearing you up!

>
> Given you tried to restrict my, or any other, response to your message to
> alt.comp.virus, one has to suspect that you are vying for the "a.c.v tosser
> of the year" award. (Perhaps you know that Sooooog has left a.c.v and thus
> see this as the big chance for your breakthrough year vis a vis the award?)

Given that you seem to not have the ability to understand how to use your POS
news reader, this coming from you doesn't seem to hold much water, it actually
sounds like you've got your hackles up thinking someone is trying to usurp the
'award' from *you*. Like I said, there's no 'restrictions' setup on *my*
reader, the problem is on your end bud. Also since this is cross-posted to 5
NG's, this will be the last reply from me you read. I've had plenty of
'battles' in NG's before, and I've *never* plonked anyone. Your irrational need
to do so to *anyone* after just one reply to a post from you, shows a *lack* of
intellect and/or wish to try to understand or view any points not your own, but
feel free to keep tossing out technical points in your posts though...it's the
hot air for that swollen head of yours.


> --
> Nick FitzGerald

Grow up and quitcherbellyaykin. You'll survive, VNC will survive, everything
will survive this diabolical plot by the OP and me.

Nick FitzGerald

unread,
Mar 29, 2003, 6:55:21 PM3/29/03
to
"Kyle Lai" <ky...@kylelai.com> to me:

> > There are good reasons why measured analyses of Deloder do not include
> > the password information. Further, there are compelling ethical
> > reasons for them to not include that information. The rest of your
> > analysis is a good and useful contribution, but it and your ethical
> > reputation are spolied by a couple of sentences.
>
> I disagree. I think you missed the point. Plus, I don't think
> anti-virus vendors looked at registry values other than the "start-up"
> registry values.

Why are you so obsessed with registry settings? And it is you that has
missed the point.

AV products in general do _not_ look at registry settings _AS A
DETECTION METHOD_. And there are very good reasons for that. No vendor
can afford the false positive and false negative rate "depending" on
such detection methods would produce. Such items are indeed useful in
manually handling incidents and knowledge of them is often necessary to
"fix" machines that have been "infected" (though with this kind of
compromise, it is generally best advice -- against the history of the
AV industry's approach -- to "burn and rebuild" as you can guarantee
that folk dumb enough to get hit by something like Deloder will not have
taken enough of the necessary preparatory steps to be able to assuredly
determine after the fact whether the rest of their box has not been
seriously compromised with other, as yet undetected backdoors, stealthing
rootkits, etc.

Anyway -- we can easily disagree about the desirability of using registry
values for programmatic malware detection and we can debate that till the
cows come home. However, you did not address my main point which is that
your publication of the VNC password used by Deloder is unethical and
therefore irresponsible and unprofessional. Your point that describing
the gory details of the registry settings is useful does not, in and of
itself justify your further compromising of security of the claimed
140,000+ machines that have been infected with Deloder. Were the VNC
password stored in clear text in the registry then a decision to publish
that registry value would be equally problematic given there are plenty of
other diagnostics people can use.

Surely you understand that as the VNC password is a purely arbitrary side-
effect of a malware writer's choice at some point in history, _AND_
knowing it adds precisely nothing to the end-users' ability either to
"protect" themselves or to remove Deloder should they have been infected
already (these are, you claim, your main motivations in releasing the
analysis) the specific value to your target audience of knowing that
password is _ZERO_. So your publication of it really only significantly
helps others than those you claim were the intended benefactors of your
work. Further, it is obviously highly likely that the only people who will
be greatly helped by your effort are those with intent to maliciously use
the machines of innocent people affected by Deloder. As that is such an
obvious conclusion, I restate my charge that it was recklessly unethical
and professionally irresponsible of you to publish the password information.

> If public did not get informed about the true problem and exploit, and
> what the worm has done, how can they protect themselves from the

> variants of this worm, which always happens? ...

They cannot.

But, if you think about it for a few seconds, they do not need to know
precisely what the worm does. In fact, it would be better if they had a
broader, more general appreciation of security issues than a temporary,
highly focussed view on this incident. Drawing such detailed focus to this
particular worm runs the risk of people deciding that because their
password is not in the list that Deloder uses, then they are "safe". This
is precisely the same sort of security-blind "knowledge enhancement" people
who suggest, hearing that a terrible virus payload is due to trigger on,
say 1 April, seriously suggest that a reasonable approach is to not use our
computers on that day "just to be sure".

And face it -- do you really think people with null and such obvious admin
passwords as those used by Deloder (and let's get honest here -- what
proportion of Deloder-hit machines have other than a null admin password?
Probably about 1% of them, yeah?) are either going to read your analysis or
even care that they are infected? Those that use antivirus or anti-Trojan
software who were hit before they got their update that detected it will
simply clean it and go on their way. Whether they have an unwanted VNC
installation left on their machine is actually something they don't care
about, because even if they did remove VNC, they will have left their admin
password blank and their Windows Network bound to their external Internet
interface for no good reason. These people will always exist and they will
always pose just this kind of risk to the rest of a public sewer-style
network such as the Internet. If you want to change that, you have to
design and implement a different Internet.

> ... In addition, if people


> don't get the information on what EXACTLY the worm did, how do you
> know what proper actions to take to protect end-users?

As I've already said, people do not need to know "exactly" what the worm
did. They need to know enough to determine if it is likely they have it or
have had it and, if it has been removed, whether any "collateral damage"
remains and if so what the best course of action is. And, in fact,
although you claim to have provided this "exact" information, I find your
analysis quite incomplete and only partial. Of course, few people would
want a sub-routine by sub-routine description of _exactly_ what the program
does, but you rightly understand that and provided a generally good
condensation of the important points to a reasonable level of detail for
most likely readers of your analysis.

However, that still does not justify the unethical release of the password,
as described in detail in my previous message and above...

> CERT advisory, http://www.cert.org/advisories/CA-2003-08.html,
> mentioend that 140,000 connections on an IRC network, which are the
> systems infected with Deloder type of worms.

How do you know that they are Deloder-ed systems? CERT claims that the
140,000+ network was a GT-bot network and as these IRC-controlled bot-nets
usually use a specific IRC channel (or group of channels) they presumably
made that claim because the channel(s) involved were configured in GT-bot
samples retrieved from some of the affected machines. As GT-bot is not
normally spread via open or weak-passworded Windows shares, I fail to see
how CERT's claim of a 140,000+ GT-bot network translates to 140,000+
possible Deloder infections.

> If you think the advisories and analysis are generated good awareness,
> why are there still so tens of thousands of computers out there
> infected with Deloder and other worms and Trojans, and why aren't they
> doing anything about it?

I've answered that above.

In short, most of the people running those machines simply don't care
enough...

> That's why I published my article.

...and it will fail to "help" any more than all those previous ones as the
people whose machines remain the problem are no more likely to see your
advisory or be swayed into caring enough as a result of seeing it than they
are to see any of the others.


--
Nick FitzGerald


Nick FitzGerald

unread,
Mar 29, 2003, 11:12:17 PM3/29/03
to
"John" <Yoch...@yahoo.com> wrote:

> Nick FitzGerald, while drooling on their self, scribbled:
>
> > "John" <Yoch...@yahoo.com> wrote:
> >
> > Note: "Followup-To: overruled and original posting list restored.
> >
> > Note^2: A good sign to start with one is dealing with an arsehole and/or
> > plonker -- he wants everyone to see his opinion but wishes to "restrict"
> > the response of those he replies to.
>

> Get yourself a newsreader that actually works correctly. ...

"Correctly" is so subjective, but it appears in this case that at least my
newsreader is working better than yours.

For starters, I've fixed your restrictive Followup-to: again. As you are
clearly too clueless to actually look at the headers of your own posts when
someone points out that they contain something you did not know was there,
I've included links to Google's archived copies of _both_ your messages in
this thread, in "Original Format" view (URLs will wrap -- yes, this is a
result of my crappy newsreader):

http://groups.google.com/groups?selm=BT8ha.562%24kK3.387872%40kent.svc.tds.net&oe=UTF-8&output=gplain

http://groups.google.com/groups?selm=Yzoha.668%24kK3.575010%40kent.svc.tds.net&oe=UTF-8&output=gplain

These show that both your messages have "Followup-To: alt.comp.virus" and I
was not just saying that in my previous response because I am a moron or
because my reputedly inferior newsreader was doing something wrong. So
John, who has the "POS" newsreader now?

As I am prepeared, from your tone, to accept that perhaps it wasnot _you_
that tried to limit the "followup" distribution, it seems we are left to
conclude that, at least when the issue is correctly forming the headers of
of a "reply to newsgroup" style response, my newsreader is less a POS than
yours. So let's see what yours is, eh?

> User-Agent: KNode/0.7.1

Oh dear, a piece of sofwtare so mature its author(s) haven't even given it
a post-beta version number. Might it not be only marginally stable?

I think we know where the real "POS newsreader" is now...

> ... Anyone else who has
> replied to a post by me whether new or in a thread has had no problems. ...

Or perhaps they were just as ignorant as you and thus didn't notice?

Maybe more of your penguin-praisin-at-all-price friends?

> ... You


> sure do get pissed easy when it's pointed out how you may be wrong about

> something don't you. ...

If the allegation is entirely wrong and the accuser as utterly stupid as to
not have done the slightest bit of thinking or checking of their own, I may
tend to the slightly incendiary end of the response spectrum. However, when
a grossly ignorant accuser, as we've already clearly seen you are, adopts an
air of superiority such as you did on top of all that ignorance, I treat such
puffery as it deserves.

> ... I've not got any "restrictions" set on *any* post I put
> up, ...

Well, _you_ may not have deliberately restricted them, but something has and
despite this being pointed out to you, you ignorantly failed to check and
then let your temper get the bette of you...

> ... you whiny baby.

Poor diddums -- not getting what you want?

> > <<snip entire quote of my post>>
> >> What a crock! S/he put it out, because if left up to "them" (those who are
> >> supposed to fix the 'problem'), they'd never get off their asses until 6
> >> months from now! As a matter of fact, M$ has said themselves they won't be
> >> 'fixing' some exploit/bug/security flaw in NT4, because it's just too much of
> >> a pain in the butt (essentially).
> >> These things need to be exposed, so that the company(s) who make these
> >> apps/software, quit hiring sloppy/lazy/scriptkiddies, and get back to
> >> *QUALITY*, not 'how fast can you guys turn this out so we can sell it?'.
> >> Funny how the opensource community gets right on these kinds of things almost

> >> instantly, ...

Yes, and ask them to fix your newsreader's "Followup-to when replying to
multiple group posts" bug while you're at it...

> >> ... meanwhile, M$ and its cronie companies sit on it to 'see if it's a


> >> bad as it might be'. Pretty pathetic.
> >
> > Excuse me, but what -- apart from displaying your complete lack of
> > intellect -- has that to do with what was being discussed?
>
> <snip 'let's try to baffle them with BS'>
>
> My reply as a 'whole', you sub-moron, was just that. You're so full of
> yourself you refuse to 'see' or 'hear' anything but what spews from your own
> mouth or ass. If you can't figure out what my reply was about, perhaps the lack
> of any intellect is on your part. Where did I refute any of the 'technical'
> parts? If you were as smart as you think yourself to be, you should know
> *exactly* to what I was replying to. Here, let me help you. This is part of
> what you posted, and (the main) part of what I was replying to:
>
> "I am interested in how you justify your membership of the ISSA in light
> of its code of ethics:
>
> http://www.issa.org/codeofethics.html
>
> and your actions in publicly releasing the VNC password used by Deloder.
> I see your actions as contrary to all but the last two of the items in
> that code, specifically:
>
> * Perform all professional activities and duties in accordance with
> the law and the highest ethical principles;
>
> As no formal list of "the highest ethical principles" is given, my
> highest ethical principles must be considered as suitable as the basis
> for comparison. As I would not have released that information because
> doing so would violate my ethical principles, your releasing the
> information puts you in beach of that point of the ISSA's code."

So your diatribe about speed of delivering updates, MS's refusal to patch
a recent NT 4.0 bug (FWIW, I agree that that sucks but at least it is now
available as public evidence that the original design was fundamentally
broken from the outset), your belief in the inherent quality of open-source
over proprietary s/w when it comes to such systems and so on was a relevant
reaction to my criticism of Kyle's ethics for choosing to unnecessarily
release the password Deloder uses for its VNC installation?

Wow -- greatly irrelvant still, but thanks for "clarifying" that...

> If you knew enough to deflate that over-sized ego of yours (wouldn't hurt your

> head any either), the 'problem' was already made public. ...

Your thoroughly discursive approach to "answering" things has me entirely
at a loss to understand what you mean by "the 'problem' was already made
public", so responding is difficult at best. Please explain what you mean
by that.

> ... The OP put the url,


> which by the way also contained any 'fixes'. You jumped on your ISSA white
> horse so damned fast, you forgot your sword to smite the 'bad OP'. So instead
> you try to tongue lash him with your 'I'm more ethical than you, you scumbag'
> BS. Now that someone (me) responds to a portion of your post, you've got your
> panties wadded so far up your ass, it's tearing you up!

Nope.

I have no "ISSA white horse". Kyle should though as he is a member and he
has clearly breached the association's ethical guidelines. I am not an ISSA
member and don't really care whether Kyle resigns for his breach (their
guidelines are quite clear about that), is booted out because someone else
dobs him in or neither. The point was that he has breached professional
ethics in choosing to publicize that password.

The rest of his analysis is fine (elsewhere I argue it is predictably very
unlikely to achieve a single goal Kyle states as his motivatin for producing
it, but it is often the case that we work in the knowledge that if a few are
helped it is worthwhile and the _hope_ that maybe, just maybe, this will be
the time a gretaer effect is achieved).

> > Given you tried to restrict my, or any other, response to your message to
> > alt.comp.virus, one has to suspect that you are vying for the "a.c.v tosser
> > of the year" award. (Perhaps you know that Sooooog has left a.c.v and thus
> > see this as the big chance for your breakthrough year vis a vis the award?)
>
> Given that you seem to not have the ability to understand how to use your POS

> news reader, this coming from you doesn't seem to hold much water, ...

Nah -- I just forgot the golden rule "never ascribe to malice that which is
adequately explained by incompetence". I apologize for suggesting you were
after the a.c.v tosser of the year award. Clearly you are just far too thick
to be allowed to use a newsreader that is not yet user-proofed enough to be
"safe" in the hands of sub-morons such as yourself.

> ... it actually


> sounds like you've got your hackles up thinking someone is trying to usurp the
> 'award' from *you*. Like I said, there's no 'restrictions' setup on *my*

> reader, ...

And like I said, there were and there are again. You are just too stupid to
work out how to check that I may be right and far too proud to admit that
you may be wrong. (You _would_ be a good replacement for Sooooog -- to go
one rung higher on the ladder of the Sooooogien-esque, you wouldn't happen
to be a twelth-rate coder who mainly writes programs by ripping other's
code then putting your own copyright notices on it??)

> ... the problem is on your end bud. ...

Nope -- as the world can see, you are entirely the "problem" here.

> ... Also since this is cross-posted to 5
> NG's, this will be the last reply from me you read. ...

Oh dear. Mummy's little boy running off to hide is he?

Well, in that case, as you have a Reply-To: header set, I'll CC this to your
Email address so you don't miss out out on seeing what a world-class plonker
the rest of the readers have seen you for...

> ... I've had plenty of
> 'battles' in NG's before, and I've *never* plonked anyone. ...

So?

Perhaps you need to look in a real dictionary to see what a "plonker" is...

> ... Your irrational need


> to do so to *anyone* after just one reply to a post from you, shows a *lack* of
> intellect and/or wish to try to understand or view any points not your own, but
> feel free to keep tossing out technical points in your posts though...it's the
> hot air for that swollen head of yours.

Huh???


--
Nick FitzGerald


Kyle Lai

unread,
Mar 30, 2003, 11:45:17 PM3/30/03
to
"Nick FitzGerald" <ni...@virus-l.demon.co.uk> wrote in message news:<3e86...@clear.net.nz>...

Hi Nick,

You missed the point again. Registry is not as important as what you
have point out: people should know that AV vendors do NOT check for
everything a virus/worm/Trojan infects. And the point is, if you
don't know the damage of a Trojan/worm, e.g. a Trojan set a encrypted
password in your system to allow anyone to get in, then you can't
think like a hacker, and you wouldn't know what they have done, and
you can't plan for the right move the next time...

Cheers,
/Kyle

KLC Consulting, Inc.
www.klcconsulting.net

Kyle Lai

unread,
Mar 31, 2003, 12:16:06 AM3/31/03
to
"Nick FitzGerald" <ni...@virus-l.demon.co.uk> wrote in message news:<3e86...@clear.net.nz>...

> "Kyle Lai" <ky...@kylelai.com> to me:
>
> > CERT advisory, http://www.cert.org/advisories/CA-2003-08.html,
> > mentioend that 140,000 connections on an IRC network, which are the
> > systems infected with Deloder type of worms.
>
> How do you know that they are Deloder-ed systems? CERT claims that the
> 140,000+ network was a GT-bot network and as these IRC-controlled bot-nets
> usually use a specific IRC channel (or group of channels) they presumably
> made that claim because the channel(s) involved were configured in GT-bot
> samples retrieved from some of the affected machines. As GT-bot is not
> normally spread via open or weak-passworded Windows shares, I fail to see
> how CERT's claim of a 140,000+ GT-bot network translates to 140,000+
> possible Deloder infections.
>
Just to clarify, Deloder is a variant of GT Bot. My other analysis
was on a variant of GT Bot as well, the taskmngr.exe/ocxdll.exe
(IRC.BOUNCER), which hit the world badly and caught MS off guard back
in 8/2002. (http://www.klcconsulting.net/mirc_virus_analysis.htm).

I won't say that 140,000 systems are all infected with Deloder, but
many of them are. I can say that the number of infected systems since
CERT advisory definitely went up. No hard umber here, but refer to
SANS Internet Storm Center (www.incident.org) and you will see there
are extremely high port 445 (Deloder's target port) activities in the
US and East Asia in the past few weeks. Over 60% of the traffic
reported from East Asia is port 445 traffic, and from my fw log, I
have more evidence that Deloder is resurfacing.

Cheers,
/Kyle

Kyle Lai, CISSP, CISA
http://www.klcconsulting.net

m...@tadyatam.invalid

unread,
Mar 31, 2003, 8:16:26 AM3/31/03
to

- snip crossposts -

BTW, the CERT advisory is dated 11-Mar-03.

Anecdotal evidence, FWIW:
My logs show about 37% _decrease_ in port 445 activity during
the 30 days from 1-Mar-03 to 30-Mar-03 vs. 28 days from 1-Feb to
28-Feb-03.

--J
Replies to: jNpolak(at)Ojuno(dot)Tcom

0 new messages