Advertisement
  • About the Author
  • About this Blog

  • MalCon: A Call for ‘Ethical Malcoding’

    I was pretty bummed this year when I found out that a previous engagement would prevent me from traveling to Las Vegas for the annual back-to-back Black Hat and Defcon security conventions. But I must say I am downright cranky that I will be missing MalCon, a conference being held in Mumbai later this year that is centered around people in the “malcoder community.”

    According to the conference Web site, MalCon is “the worlds [sic] first platform bringing together Malware and Information Security Researchers from across the globe to share key research insights into building the next generation malwares. Spread across the world, malcoders now have a common platform to demonstrate expertise, get a new insight and be a part of the global MALCODER community. This conference features keynotes, technical presentations, workshops as well as the EMERGING CHALLENGES of creating undetectable stealthy malware.”

    The call for papers shows that this security conference is encouraging malware writers of all shapes, ages and sizes to bring and share their creations. “We are looking for new techniques, tool releases,unique research and about anything that’s breath-taking, related to Malwares. If your presentation, when given with all its valid techno-Jargon can give our moderators a head-ache, you are right up there. The papers and research work could be under any of the broad categories mentioned below. You can submit working malwares as well.”

    Among the “malwares” encouraged are novel phishing kits, botnets and mobile phone-based malware, malware creation tools, cross-platform malware infection techniques, and new malware self-defense mechanisms, such as anti-virus exploitation techniques.

    At first, I didn’t know what to make of this conference, which was initially brought to my attention by a clueful source in the botnet underground. My hoaxmeter went positively bonkers after I pinged both of the e-mail addresses listed on the site and each e-mail bounced.

    But then I caught up with Rajshekhar Murthy, the coordinator for the conference. Murthy said MalCon will be hosted on Dec. 3 in Mumbai, and then again on Dec. 5 at the Clubhack 2010 conference in Pune, India, which has apparently attracted oft-quoted security expert Bruce Schneier as a leading speaker.

    Murthy confirmed that the idea behind the conference was indeed to attract malware writers.

    “You are right, the major goal of the conference is to encourage and foster the creation of malcode. But it is done for all the good reasons,” Murthy wrote in an e-mail to KrebsOnSecurity.com. “There are only a handful companies that dominate and sell Anti-malware / Anti-virus programs, compared to a huge number of malcoders who release a million new malwares every year. The approach to the problem is always ‘Reactive’ and is done if the malcode is detected in time.”

    Murthy continued: “While a conference can be done by inviting the best / well known security experts who can share statistics, slides and ‘analysis’ of malwares, it is not of any benefit to the community today except that of awareness. The need of MalCon conference is bridge that ignored gap between security companies and malcoders. They have to get on a common platform and talk to each other. Just like the concept of  ‘ethical hacking’ has helped organizations to see that hackers are not all that bad, it is time to accept that ‘ethical malcoding’ is required to research, identify and mitigate newer malwares in a ‘proactive’ way.”

    For his part, Schneier said he does not agree with the idea that better malware is needed to fine-tune computer security tools.

    “The bad guys produce more than enough malware to stimulate research,” Schneier wrote in an e-mail.

    At any rate, it’s time to get working on your malwares already, people! Final papers are due Nov. 10. Oh, and if anyone decides to go and can snag me a T-shirt from the con, I’m an extra large.

    Bookmark and Share

    Related posts:

    1. Call Centers for Computer Criminals

    Tags: , , , , , ,

    32 comments

    1. I did a quick WHOIS check for malcon.org and it seems to be run by some group called “OrchidSeven”. They seem to offer a multitude of somewhat dubious hacking bootcamps and security certifications. Under their “News and Events” tab at the bottom of the page I noticed a link to labeled “India’s Youngest Hacker from Orchidseven!”. Apparently the group made the newspapers in Mumbai a few years back for offering a 12-year-old kid a research fellowship. The “whiz hacker” reportedly passed his MCSE exam at age 7. As cute as he is, this hefty heavyweight hacker can pwn your box faster than you can say Little Debbie’s Snack Cakes. I wonder if he attending the conference?

      Well-loved. Like or Dislike: Thumb up 18 Thumb down 0
      • Yes, the boy too was present there and surprisingly was also in the panel members for replying in the discussions. However, the interesting part was whenever he spoke it felt to me like another Indian Government official is saying something. By the way, his name is SHANTANU.

        Like or Dislike: Thumb up 3 Thumb down 0
    2. OrchidSeven offers security certifications and university courses (!) … have a look at the curriculum:
      - Using SMS and Chat for effectively gaining trust
      - How SMS has taken over our lives…

      I believe the target audience is l33t haxors with deep pockets. So .. I’m out.

      Like or Dislike: Thumb up 3 Thumb down 0
    3. Could be I’m missing something in my reading. I’m reading a group of malware authors is sponsored by an organization supporting malware is coming together with a gaggle of computer geeks for the common good of computer security? Pretty well supports my suspicions that malware detection vendors and malware authors are under the same umbrella. While so many malware authors are gathered, how bout haul them off to jail?

      Well-loved. Like or Dislike: Thumb up 22 Thumb down 5
      • I had that same thought…or feed them all eggs from Dutch Farms…

        Hot debate. What do you think? Thumb up 5 Thumb down 8
      • I appreciate malware writers & anti-malware people. Collectively they cause improved security in *nix operating systems & software. The world benefits. They also keep me from using, paying for & slaving to repair Windiz systems. Without them I would still be using Windiz.
        Thanks guys!

        Like or Dislike: Thumb up 2 Thumb down 4
      • Unfortunately, very few malware authors were present. The maximum attendance was of the Govt. Servants of India and few independent Cyber Security Researchers. I found that only nulcon hackers were present and were supposedly supported by the conference organizers.

        Like or Dislike: Thumb up 2 Thumb down 0
    4. I heard it was being held in a huge tent. The MalCon tent.

      Well-loved. Like or Dislike: Thumb up 60 Thumb down 1
    5. If a bunch of drug lords decided to host a large conference where everyone could come and share their best techniques on making meth, smuggling drugs, and killing cops; would we stand by and let them do it?

      Maybe I am not comparing apples to apples, but even the activities at DefCon are bad enough for me to question whether such conferences really ought to be held.

      I guess if I’m a good enough hacker/malware developer, I can quit my day job and become a “security researcher” and just spend all day trying to find new ways to exploit the software we use every day. (I’m NOT saying there aren’t legitimate security researchers out there.)

      Hot debate. What do you think? Thumb up 13 Thumb down 11
      • Hidden due to low comment rating. Click here to see.

        Poorly-rated. Like or Dislike: Thumb up 2 Thumb down 34
      • I detest the malware enterprise. It takes some of the fun out of the internet for me, and ruins the finances of the unwary and unfortunate. But it you’ve ever seen what becomes of the ‘lives’ of hard drug users @ the end of their addiction, you’d know that aside fr/ murder, sexual predation, or large scale environmental pillage (give me my life back!) no crime compares to dealing in hard drugs

        Hot debate. What do you think? Thumb up 5 Thumb down 10
    6. They should arrest as many malware authors as possible, then transport them to the deepest part of the ocean, tie infected computers to their ankles, and drop them overboard. Seriously. I spend a LOT of time at work fixing computers that have been infested with their garbage. I say it’s time to take out the trash–the malware author trash. They don’t fear fines or imprisonment–they should fear death when they’re caught.

      chicopanther

      Well-loved. Like or Dislike: Thumb up 31 Thumb down 7
      • so, these guys are responsible for a lot of your income, and you’re upset about them?

        I’m delighted by the existence of Bill Gates and malware authors. They’ve crafted an ecosystem together which permits a group of folks to make a living.

        Hot debate. What do you think? Thumb up 7 Thumb down 9
        • You know I’m totally for malware. I deal with it to “every day” too and the solution I give my customers is a simple one STOP USING WINDOWS~! I haven’t lost a single customer yet either. I do it full time and make my living off it. It’s really that simple. Those customers who choose not to go free end up with a OS reload. Almost nobody gets a “virus removal” because virus removals are priced accordingly and should be frowned upon. If you’re removing malware the hard way it’s probably because you’ve chosen to do so and totally your fault as a techy person. Stop telling people malware can be removed. It can’t. It’s not that simple. You backup peoples data, wipe, and reload. It’s the only way you’ll know it’s totally gone. If they want a system free of viruses, spyware, and other malware then you sell them a Penguin like I do (which are the only systems / products designed for GNU/Linux not dependent on non-free drivers or firmware and made for non-techy users) or put together some other GNU/Linux system for them. And before anybody says GNU/Linux is too hard it’s isn’t. You just have to SELL people support and provide them a place to purchase REAL GNU/Linux hardware & services/accessories. MS Windows hardware doesn’t work so stop making it out as if it’s a GNU/Linux problem!

          Hot debate. What do you think? Thumb up 7 Thumb down 7
    7. While I can fully understand people being upset that a gathering like this can take place – if it’s being used in a good way, what’s wrong with it? I think it falls in the “it takes one to know one” type category – how are you going to catch them or protect against them if you don’t think like them?

      Jonathon compares them to drug lords – but what if they’re the undercover cop within that whole string? Is that person just as bad as the rest since he’s trying to help end it but first has to get involved to do so?

      If these people understand security experts are going to be there too – I’d compare them more to the undercover cop than to the drug lords… I would think they’d know the combination of the two was to help security as a whole (but perhaps I give too much credit). Could it be questionable – yes, could there be some people there in hopes of bettering their malware – yes… but could there be a positve to come out of it too – yes. If we can learn to think more like them we can better prepare for future attacks. And if they’re willing to help us – why not?

      Hot debate. What do you think? Thumb up 9 Thumb down 10
      • Hidden due to low comment rating. Click here to see.

        Poorly-rated. Like or Dislike: Thumb up 2 Thumb down 8
    8. Hidden due to low comment rating. Click here to see.

      Poorly-rated. Like or Dislike: Thumb up 4 Thumb down 13
    9. Although I shouldn’t be, I’m amazed. As someone already mentioned, it’s a sure bet that there will be law enforcement there. Even if they can’t be arrested for just talking and sharing technology and practices, isn’t just being visible there a gamble on their parts?

      Well-loved. Like or Dislike: Thumb up 13 Thumb down 2
      • You are right. In the MALCON, not only the law enforcement agencies were present but the people from Intelligence Agencies, Defence Intelligence Agencies were also present. The interesting part was that when I recognized one of them in the conference, he was in a shock and said instead that he is just an unemployed one and was here to look for an employment opportunity. Wow! What a lie…

        Instead I had observed that the people from Intelligence Agencies were monitoring those people specifically who were attending their workshops esp. the one on Exploit writing.

        Like or Dislike: Thumb up 2 Thumb down 0
    10. Most commercial malware comes fr/ the former Soviet Bloc. I assume that the governments of these various states, esp Russia and Ukraine, tolerate the malefactors who write and ‘administer’ the malware–for various reasons.

      To hazard a guess, not many of the pros fr/ the former Soviet sphere will attend, especially if their local secret services have any input on the subject. The lower their profile the better. They MAY send talent scouts to watch the proceedings fr/ the periphery.

      Well-loved. Like or Dislike: Thumb up 8 Thumb down 4
    11. My assumption is the malcoders will be deceptive and try to lay traps. The idea from this perspective is for the conference to become a part and parcel of the deception that is the creation of malware. But there certainly would be some that “turn to the good.” Perhaps someone who knows a lot about game theory could calculate all of this and tell us whether or not he/she sees an overall plus or a minus.

      Like or Dislike: Thumb up 3 Thumb down 2
    12. I think opening a MalCon tent is a good thing. The exchange of information is valuable. The vulnerabilities are out there discovered or not, public or not. At least some of the undiscovered vulnerabilities out there are in use by “for profit” MalContents as well as governments. Getting the discussion in public helps security folks discover what they don’t know. As for acting against the people that are at the conferences, the information gathered would be mostly intelligence for future actions against these people where specific hard evidence has been gathered. As for the educational aspects for the MalContents, I think it’s mainly a ego trip for them rather than learning the trade/hobby….no actor goes to the Emmys to learn how to act. I guess it stimulates them to some degree but I think there are plenty of methods for this exchange of information.

      Like or Dislike: Thumb up 4 Thumb down 2
    13. don’t worry we only build malware to use on bad people this makes it ok

      Hot debate. What do you think? Thumb up 2 Thumb down 7
    14. What does it take to get shut down in this country? Maybe someone in the media should do a little investigative reporting, because there seems to be a bigger problem here than a few isolated incidents. Aren’t these factory farms repeat offenders?

      Like or Dislike: Thumb up 2 Thumb down 1
    15. Hopefully there will be a few black vans outside with the words Free Beer Inside written on the side.

      Like or Dislike: Thumb up 4 Thumb down 1
    16. Even as arch enemies Indian and Pakistani Governments are at each others throats, powerful hackers groups in both countries have met and signed a deal to avoid hacking into each other’s sites.

      Perhaps this Malcon conference is also in the same spirit of working together

      http://www.techgoss.com/Story/401S12-PCA–We-did-not-hack-Vijay-Mal.aspx

      Like or Dislike: Thumb up 0 Thumb down 2
    17. Well I checked orchidseven.com and apparently its quite interesting. They helped me get some things cleared out. I informed that my pockets aint deep and boy am i glad they are quite easy with that. the course is a lot cheaper in cost compared to what others are offering as per the topics.
      I hope i make it to Malcon.

      Like or Dislike: Thumb up 1 Thumb down 2
    18. To me, attending the MalCon seems more like a marketing gimmick than a serious talks / discussions. Orchid Seven was more interested in launching their initiative called as “National Security Database (NSD)” and to showcase it, in my opinion, the conference was termed as an International. Nothing was there as such International. Only one person from France was present. Is being present from another country gives the sense and meaning of an International Conference? I don’t think so.

      Additionally, I met many independent cyber security researchers present there in the conference and surprisingly, no one was interested to be a part of NSD. NSD was supposed to create a database of those people who will be a part of crusaders’ team and will be checked by Orchid Seven. The key issue which was a major concern of the independent cyber security researchers was the clauses of NSD. One can’t submit their research papers in any conference, and the members of NSD had to work anonymously (&, as a volunteer…. no paid service!).

      I just wasted my time and money, I think so, by being a part of MalCon. Except meeting few old & new friends, I didn’t received much knowledge (which I had supposed to receive being in such conferences).

      So, in my opinion, its’ a strict No-No if someone is planning to be a part of 2nd MalCon in future, if any.

      Like or Dislike: Thumb up 4 Thumb down 2
      • I think for the fact that its a first kind of attempt, its obvious you wont find too many malware authors walking right into it happily. I was there at the conference too and it did not feel like they were interested to launch this NSD – it was more of a response to a query to an audience?

        At least there exists one good hacker convention in India. You seem to have more of a personal take on this.

        Like or Dislike: Thumb up 3 Thumb down 1