ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Virus writers use 'open source' methods

Tom Espiner ZDNet.co.uk

Published: 17 Jul 2006 12:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Malware writers are increasingly using open source methodologies when developing malicious code, according to antivirus vendor McAfee.

In its Global Threat Report for 2006, McAfee warned that more hackers are sharing source code and ideas freely. This includes distributing source code with documented explanations and annotations of how that code works, which helps programmers to adapt it.

McAfee said that this can be an extremely effective way of developing code, both legitimate and malicious.

"Like any powerful tool, open source can also be used for malicious purposes, particularly in security," McAfee said in its Global Threat Report for 2006.

"DoomJuice was a mass-mailer that distributed a copy of MyDoom. Maybe the author was proud of their skills being reused. It contained the documented source code of MyDoom, like a Lego kit with instructions," said McAfee UK security consultant Greg Day.

So-called script kiddies, who download easy-to-use malware from the Internet, have long been a reality. But McAfee's report claims that more virus writers, especially those involved in organised crime, are forming communities and typically share information over IRC networks.

However, these groups are much harder to join than open source software communities, as the malware writers are keen to avoid attention from the authorities.

McAfee said that malware now has a long-term development lifecycle, with code being developed, bugs being fixed, and betas then final versions being distributed amongst the malware community in a similar way to open source communities.

"You could say open source methodology allows them to build better quality attacks," Day told ZDNet UK. "Today's news is group development."

Hacker tools are also created and distributed freely on an open source model, according to McAfee. Versions of SDBot, a Trojan horse that opens a back door, included an add-in for the FU rootkit, a cloaking piece of software available on the Internet. McAfee claims it is possible to find documented copies of FU rootkit online "if you hunt around". It is also possible to find documented copies of Morphine, a tool used by hackers to circumvent antivirus protection.

Day said that few virus writers are devoting time to coding from scratch and resolving bugs. Hackers are also acting as paid consultants offering guidance once their source code has been opened — also known as "patronage" of their code.

"This is an effective methodology for ill-gotten gains," said Day. "If anything this shows that open source is an effective way of coding — a good idea being used for bad intent," Day added.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
76 out of 172 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Graduate Trainees Careers in Software Development and Advanced IT

The STFC e-Science Centre is charged with the exploitation of e-Science technologies throughout STFC's programmes -- see http://www.stfc.ac.uk/, the ...

Data Analyst* SAS* Basel II* Leading Financial Co* Docklands

An ideal opportunity has opened up within a leading financial company, for experienced SAS data analysts/report writers. Candidates must possess ...

Delphi Ver 5+ with C# & SQL Server COM, DCOM, COM+ & MTS

This is an amazing opportunity for the right candidate to join a cutting edge technical team working on complex and very large systems from ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation