Authorities Seize Duqu's C&C Servers In Mumbai 53
wiredmikey writes "In Mumbai, Indian authorities seized components from servers in a data center after Symantec informed them that they were communicating with the command and control infrastructure used by Duqu, the Trojan that is touted as the precursor to the next Stuxnet. According to a report from Reuters, officials the Department of Information Technology in India seized hard drives and other components from a server hosted in a Mumbai data center. Security vendors and government labs are worried that malware such as Duqu and Stuxnet are the building blocks needed in order for attackers to target critical infrastructure. Based on the initial analysis of Duqu, many researchers warned that it was the second generation development of Stuxnet, but this is still the subject of much debate, with some experts now saying that the connection between the two malicious programs is questionable."
Re: (Score:1)
Fuckin' racist knuckle-dragger. Please stop fucking your mom, she's getting tired of it.
Racist? perhaps you'd like to explain the difference in race between Indians and Pakis to me, or are you to busy fucking your mom?
Re: (Score:2)
I'm not fucking my mom, I'm fucking your mom. That's how I know she's sick of your syphilitic sore covered dick. Which is why I only fuck her in the ass with 5 rubbers on. And stop pretending you don't know the term you used is racist, you dumb fuck.
I thought you'd not be able to answer the question. I'm not surprised you're fucking my mom, she's been dead for ten years.
Re: (Score:2)
Now now, everyone knows brothers shouldn't fight. Especially when it comes to fucking their mother in public restrooms.
Re: (Score:3)
The term you used is considered (extremely strong) racial abuse in the UK and some other parts of Europe - basically equal in strength to a certain word beginning with "n". I believe it lacks that association in the US and is used as a simple abbreviation - but given this is a site with an international readership, it's best avoided. It will get a powerful reaction, as you've seen.
Linguistic minefields like this exist in both directions - some terms considered mild in the UK would be fighting talk in the US
Re: (Score:2)
The weight attached to words depends heavily on history and context. In the UK, and a few other European nations with similar demographic histories, that word is one that has picked up a lot of baggage. It's associated with skinhead thugs smashing windows and other such unpleasantness.
Just as the "n" word I mentioned has unsavoury connotations in the US, particularly in the southern States, so too this is a word you should never use in polite company. I admit it's a bit odd... nobody has ever found... say..
Yet another win for the GDI over NOD and Kane (Score:2)
Honestly, unless I see it spelled out in the title or whatever... whenever I see "C&C" I simply think of the ol' Command & Conquer game.
Re: (Score:2)
I'd bet that at least 25 to 50% of slashdot readers think the same way.
Re: (Score:2)
Partly it's the subject: it sounds just like a Command & Conquer scenario. I can just see the commando shooting the exploding barrels to take out a tank, so the engineer can reach the data center.
Speaking of which, do you ever find yourself getting out of bed in the morning and saying, "I've got the codes"?
Re: (Score:2)
Re: (Score:2)
As an old usenetter, whenever I see C&C, I think of "coffee and cats warning" as in "put down the coffee and push the cat off your lap before you read this."
Authorities Seize Duqu's Coffee and Cats Servers In Mumbai
--
BMO
Re: (Score:2)
As an old usenetter, whenever I see C&C, I think of "coffee and cats warning" as in "put down the coffee and push the cat off your lap before you read this."
I'm an old Usenetter, and I've never seen that one. Thanks. The equivalent I saw was C|N>K ("Coke piped through nose to keyboard", or something. :-)
Re: (Score:2)
Surely you should know better with this headline. I don't think C&C ever had dedicated server support.
Unless you mean the tottering DRM-"disguising" atrocity that was the back-end for C&C4. But you can't have meant that. Because C&C4 didn't exist and wasn't the last nail in the coffin of a once proud series. And if anybody says otherwise I'm going to stick my fingers in my ears and go "NANANANANANANANANA" until they go away.
But yes, after too many hours of my student years wasted to playing that
Re: (Score:2)
There was never a C&C4. Ever.
Ever.
Re: (Score:2)
Honestly, unless I see it spelled out in the title or whatever... whenever I see "C&C" I simply think of the ol' Command & Conquer game.
I always think of the old school hippity hoppity band "C&C Music Factory".
Re: (Score:1)
Re: (Score:2)
Totally dude. The server was sharing ten year old pirated software, so they seized it...
Re: (Score:2)
Re: (Score:1)
Figures. (Score:4, Insightful)
Re: (Score:2)
I concur, this way they may make headlines immediately instead of patiently waiting and maybe triggering some alarm that the blackhat admins have set up, sure, but it's a poor replacement for getting the responsible people which will just rebuild something more carefully. Back to square one.
Heck, it could be seen as a form of cover up, or a way to keep oneself in business by throwing the fish back in the river.
Re: (Score:2, Funny)
"And ppl wonder why there are so many crackers out there."
Mostly because the keep having children...
Oh wait, are we talking about the same thing?
Correct (Score:3)
Re: (Score:2)
And ppl wonder why there are so many crackers out there.
Hey, didn't you see RogueyWon's post about name calling?
Servers? (Score:4, Interesting)
I'm kind of surprised that cutting edge malware depends on a central server for command and control. What about P2P? Or steganographic embedding of commands in forum posts or images? It seems like a robust and deniable control system would be one of the first things you implement in malware like this.
SHHHHHHHHH (Score:1)
Re: (Score:3)
Is this thing seriously not yet reverse engineered (Score:2)
If critical infrastructure wasn't online... (Score:5, Interesting)
... this wouldn't be an issue. And make sure workers can't plug in USB sticks or DVD/CD-ROMS. Really , I do wonder whether people running IT in critical industries have all had a collective lobotomy.
Re: (Score:2)
and what, run them only on custom microcontrollers and dos machines??
oh wait that would be perfect.
Re: (Score:2)
Maybe, who knows, Depends on the task. But thats besides the point, which is that even an unpatched Win95 machine is safe if its totally locked down and there's no way for any software or data to be loaded onto it either via a network connection or via the machine itself.
Re: (Score:1)
I've often wondered why there isn't a proper setup here.
I mean why are they connected?
if not
why can people access them directly?
I mean.. you can whitelist traffic instead of blacklisting.. you KNOW what is supposed to happen between the "critical side" and it's controller machine.. block anything that doesn't fit that mold.. done
as an override have a terminal that connects to the control box with a door that sets off every siren in the world when opened. basically saying, something went horribly wrong.
Looks like (Score:1)
*sunglasses*
YEEAHHH!!!