Digital Identity Management
Scott C. Lemon, Exploring Identity in the Internet Age





Blogroll










My other blogs ...




Subscribe to "Digital Identity Management" in Radio UserLand.

Subscribe To This Site (RSS)
RSS Feed


Click here to send an email to the editor of this weblog.

 

 

Friday, November 18, 2005
 

Few people seem to understand what all of these viruses and malware are really about.  Yes, there is a certain amount of spam that you get that is designed to then barrage you with pop-up ads ... as though you would say "Wow, what a great ad!  I'm glad I get these pop-ups ... I'll have to go and spend money with these folks!"

One of the real business models behind all of this - the real people doing business in this space - are the ones that use large numbers of compromised computers at business and homes to launch DDOS (Distributed Denial Of Service) Attacks.  These attacks are used for good ol' conventional extortion.  It becomes a very simple case of "Pay me, or your Internet presence will be shut down!"  The person who controls the compromised machines can easily "task" them to attack various web sites, at various times, and for various amounts of time.  Reading this article, you can begin to get the idea that large scale "Internet vandelism" can quickly grow into a profitable - yet illegal - business.  I recently read another article where a California 20-year-old had over 400,000 machines under his control as a massively distributed "botnet" that he could divide up and control as a virtual military force.  Yes ... 400,000 machines!

A while back I had one of my Linux boxes compromised through a hole in a Open Source PHP application.  The attackers were able to install and execute a small script that pulled down and ran a larger script.  That one actually attached to an IRC server and waited for additional commands.  I found that they then sent a command to download a DDOS script, and would then begin to run it from time to time attacking various sites.  I discovered this whole scenario when I noticed that my DSL line would get swamped from time to time and isolated the traffic to that Linux box.  I actually had some fun before cleaning everything up.  I did patch the hole, but I modified the DDOS script to simply log information about the command and the target, but not actually generate the traffic.  It was fun to review the log and see that my box was being controlled by a compromised machine in South America, and that I was being to used - at one point - to attack an on-line gambling site.

This got me thinking a lot about what we don't know that we don't know about the whole world of the Internet, spam, viruses, and malware.  In addition, it reinforces the levels of indirection that can easily be created to hide the identity of the controller.  But not forever!

Hackers Admit to Wave of Attacks. With their ringleader on the run, two cybervandals own up to using an army of compromised PCs to take down sites for commercial gain. By Kevin Poulsen. [Wired News]
[tags: ]
1:58:51 PM     

I know that this type of identity theft is why so many people are working on identity solutions.  I believe that these types of incidents are going to be on the raise for a while.  What is interesting to me is that I am not sure that this can prevented except through the use of harsh penalties.

What we have is a company who specializes in outsourcing various work, and number of companies who have entrusted their customers - and their identity data - to this outsourcing entity.  Within the outsourcing entity, there are employees - or this one employee - who saw the opportunity to compromise the system from the inside!

While I was working at Novell, we often saw the hacker/security breach reports that floated around, and in almost all of the cases that I could remember the biggest breaches were from the inside!  We can do everything that we want to protect the identities of others, however when we have someone within our company - within our community or context - that is committed to exploiting our identity for their own purposes, there is little we can do.  This becomes a fundamental breakdown within that community ... and for significant violations in the past there were severe punishments.  This truly gets at the roots of the meaning of being fired!

Indian call center worker arrested. In a new case of alleged data theft, Indian police have arrested a call center employee in the outsourcing hub of Gurgaon. [CNET News.com]
[tags: ]
1:15:00 PM     


Click here to visit the Radio UserLand website. © Copyright 2005 Scott C. Lemon.
Last update: 12/4/2005; 7:21:05 AM.
This theme is based on the SoundWaves (blue) Manila theme.
November 2005
Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30      
Oct   Dec