Magazine Subscribe Events Careers Backblog About Us Press Releases Media Kit Supplements Book Review
How to blog with Backbone
Current Issue

Directories &
Industry Blogs

Canadian Technology Associations

Data Warehousing

eHealth

ICT Hardware and Infrastructure

IT Staffing Solutions

Online Education and MBAs

Outsourcing

Professional Services

Security

Social Networking

Software Companies

VOIP

Web Developers

Wireless Solution Providers

To post a directory listing contact Backbone

Multimedia

sponsored by


Podcasts

Mobility Podcast
Productivity Podcast
IT Metrics Podcast


Webcasts
Dual Core Laptop Computing
Staying connected on the go
Wireless Business Podcast
SMB Success



How-to Guides
Find Ideas to inspire your digital life


Small Business
Case Studies

Action International 
Float point
Ghadban Accounting
Grant Stream
Promation 
Vertical Brokers 


Guide for Small Business
Freedom to succeed in business


Don't get botnetted April 25, 2008 

"Botnet" is not a verb, but it should be. As a noun, it refers to a group of computers (called zombies) that have been compromised by worms, Trojan horses or some other type of backdoor software and are secretly being used by a controller, called a bot herder or a botmaster. 

An article by Danny Bradbury in Backbone's March/April issue illustrates how vulnerable computers are: "Computers can be joined to a botnet simply by visiting a Web site, and staying away from sites offering porn and pirated software won't help. Last summer, thousands of mainstream Web sites were hacked and made to surreptitiously point to a server hosting a malware kit called MPACK. Machines visiting the legitimate sites consequently touched the MPACK software, which scanned for vulnerabilities and infected them, dragging them down into the botnet.

"Thousands of visitors are still blissfully unaware that their PCs are listening for instructions from the botmaster — the person responsible for remotely controlling hundreds of thousands of computers. The botmaster can instruct infected PCs to do almost anything, including sending back a log of all the user's keystrokes, hosting illegal porn and sending out more spam using lists of e-mail addresses sent by the botmaster. When criminals began realizing how profitable botnets could be, they were quick to exploit them. Spammers pay botmasters to send e-mails by the millions through these illicit networks. They have also been used for distributed denial of service (DDoS) attacks, in which tens of thousands of infected PCs are told to send packets of data to a particular Internet address, flooding Web servers with traffic and shutting them down."

And then the situation got even worse in early 2007 when the Storm worm appeared: "Instead of using an IRC server, it employed the same peer-to-peer tactics used by file sharing software such as the old Napster. Instead of taking commands from a central server, PCs infected with the Storm worm relayed instructions to each other, creating a global matrix of infected machines with no single "head" to decapitate. It also obfuscated its activities using encryption, which makes it theoretically impossible for researchers and law enforcement to understand what the botnet is doing."

So clearly botnets are so active that the term should also have a verb form: to be botnetted. But it doesn't have to be this way; in fact, according to three security software vendors, if your computer has been botnetted it's entirely your fault.

Now it has to be said up-front that security vendors have an incentive to say their software protects computers, but even so their responses were definite: as long as both Windows and the security software are kept up to date, there is no chance a PC can become infected.

Lynn Hargrove, director of consumer solutions at Symantec (Canada), said the company's Norton 360 or Norton Internet Security along with its news Norton AntiBot "provides the most effective security solution available against known and unknown forms of malware—including botnets." McAfee's Avert Labs' Security Research and Communications manager Dave Marcus also said users of its software would be protected. For both the message is simple: install software, keep it updated and you're safe. And if a PC is already infected, both products claim they can clean out the botnet code.

The message is slightly different from Websense, which makes content filtering and data leakage prevention software, in that the company does not provide firewall or anti-virus technology and cannot clean infected systems. Instead, Websense works with products like those from McAfee or Symantec and adds an extra layer of protection that prevents users from accessing dangerous sites in the first place. Fiaaz Walji, Websense country manager for Canada, said a clean PC with WebSense, anti-virus and firewall software installed and up-to-date is absolutely safe from botnet infection.

So the message is clear: if your PC is infected by a botnet, and if therefore your banking information and passwords are stolen and your computer slows to a crawl, it's your fault.

Go out and get some good protection.

Peter Wolchak

Posted April 25, 2008
Categories: Security

Comments

Add Your Comment
Name
Email
Comments
   
Backblog Archives

May 2008

April 2008

March 2008

February 2008

January 2008

December 2007

November 2007

October 2007

September 2007

August 2007

July 2007

June 2007

May 2007

April 2007

March 2007

February 2007

January 2007

Top 300 Issue
 
Gadget of the Week (Canadian)



Small. Really small
Creative Zen Stone Plus with Speaker

This MP3 player has a lot of features: 500-song capacity, 20-hour battery, an alarm clock, FM radio, voice recorder, stopwatch and—rare in an MP3 player—a built-in speaker. And it packs all that in a tiny space: check out the paperclip in the photo.

more>>
Special Supplements

 

Green Technology - The rise of green technology.
Data Management - information sharing and data lifecycles.
eHealth  - New technology is changing the face of healthcare in Canada.
Outsourcing  - Read about how outsourcing can enhance your company's bottom line.
eLearning  - Canada’s smartest businesses are applying new technologies to employee training.
eTravel - Learn how new technologies are helping hotels provide service.
Fast Cities  - Technology is changing urban environments with updated options from voting to paying for parking.
Security  - Converged security takes a holistic approach to safeguarding your company. 
Technology  - at the 2010 Winter Olympic Games.
UK Trade & Investment  - helps businesses prosper in the UK market.
Unified Communications - VoIP, human communication, converged networks, and more.
VoIP  - Discover how Canadian companies are harnessing the power of VoIP.

Backblog RSS feed
Click to subscribe
© 2006-2007 Backbone Magazine. All Rights Reserved. Privacy Policy | Terms of Use.