Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Storm worm strikes back at security pros

Researcher says those discovered trying to defeat worm suffer DDoS attacks
By Tim Greene , Network World , 10/24/2007
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

The Storm worm is fighting back against security researchers that seek to destroy it and has them running scared, Interop New York show attendees heard Tuesday.

The worm can figure out which users are trying to probe its command-and-control servers, and it retaliates by launching DDoS attacks against them, shutting down their Internet access for days, says Josh Corman, host-protection architect for IBM/ISS, who led a session on network threats.

“As you try to investigate [Storm], it knows, and it punishes,” he says. “It fights back.”

As a result, researchers who have managed to glean facts about the worm are reluctant to publish their findings. “They’re afraid. I’ve never seen this before,” Corman says. “They find these things but never say anything about them.”

And not without good reason, he says. Some who have managed to reverse engineer Storm in an effort to figure out how to thwart it have suffered DDoS attacks that have knocked them off the Internet for days, he says.

As researchers test their versions of Storm by connecting to Storm command-and-control servers, the servers seem to recognize these attempts as threatening. Then either the worm itself or the people behind it seem to knock them off the Internet by flooding them with traffic from Storm’s botnet, Corman says.

A recently discovered capability of Storm is its ability to interrupt applications as they boot up and either shut them down or allow them to appear to boot, but disable them. Users will see that, say, antivirus is turned on, but it isn’t scan for viruses, or as Corman puts it, it is brain-dead. "It’s running, but it’s not doing anything. You can brain-dead anything," he says.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (23)
Login
Forgot your account info?

Re: Think this might bee a...By Anonymous on October 30, 2007, 3:11 pm...clearly you are not serious?

Reply | Read entire comment

You sir, are a twit and IBy Anonymous on October 29, 2007, 4:46 pmYou sir, are a twit and I must request that you refrain from commenting on this article for the duration.

Reply | Read entire comment

Think this might bee aBy Anonymous on October 27, 2007, 7:11 amThink this might bee a punishment to the west world, from fundamentalists in the islamic community for the wrong doing against their profet. This might bee the first...

Reply | Read entire comment

Re:Re: Antigen and HypeBy Anonymous on October 25, 2007, 4:36 pm...so, as a "real professional" what would you suggest?

Reply | Read entire comment

Re: Old newsBy Anonymous on October 25, 2007, 4:31 pmOK...so, has anyone researching this noted the range of the "spoofed" IP Adresses? I think that could be a good starting point, trigger the ddos to see what happens,...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed