<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft Disrupts &#8216;Nitol&#8217; Botnet in Piracy Sweep</title>
	<atom:link href="http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Tue, 21 May 2013 03:20:52 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Suresh Ramasubramanian</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-110719</link>
		<dc:creator>Suresh Ramasubramanian</dc:creator>
		<pubDate>Tue, 18 Sep 2012 10:22:08 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-110719</guid>
		<description><![CDATA[&quot;Unnamed&quot;?  The people complaining so far do have a rather long track record in security, and certainly aren&#039;t anonymous.

Action needed to be taken.  Whether siezing the domain through a court order and proxying dns requests for it was, or was not a bad idea .. well, this could have been handled a lot better.

http://www.circleid.com/posts/20120917_microsoft_takedown_of_3322_org_a_gigantic_self_goal/]]></description>
		<content:encoded><![CDATA[<p>&#8220;Unnamed&#8221;?  The people complaining so far do have a rather long track record in security, and certainly aren&#8217;t anonymous.</p>
<p>Action needed to be taken.  Whether siezing the domain through a court order and proxying dns requests for it was, or was not a bad idea .. well, this could have been handled a lot better.</p>
<p><a href="http://www.circleid.com/posts/20120917_microsoft_takedown_of_3322_org_a_gigantic_self_goal/" rel="nofollow">http://www.circleid.com/posts/20120917_microsoft_takedown_of_3322_org_a_gigantic_self_goal/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gonosenno kata</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-110478</link>
		<dc:creator>gonosenno kata</dc:creator>
		<pubDate>Tue, 18 Sep 2012 02:15:17 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-110478</guid>
		<description><![CDATA[Great article Brian.  The Nitol &quot;takedown&quot; is much much bigger than ridding the Internet of some run of the mill botnet.  This is counter-cyberespionage gold.]]></description>
		<content:encoded><![CDATA[<p>Great article Brian.  The Nitol &#8220;takedown&#8221; is much much bigger than ridding the Internet of some run of the mill botnet.  This is counter-cyberespionage gold.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AlphaCentauri</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-108450</link>
		<dc:creator>AlphaCentauri</dc:creator>
		<pubDate>Sat, 15 Sep 2012 03:55:40 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-108450</guid>
		<description><![CDATA[The effect of this court order may not be that significant. But if no one takes any action against organizations that tolerate criminal activity on their networks, you end up with the situation we&#039;ve got now where criminals operate so openly that they can amass huge botnets that constitute a threat to normal internet operations. 

A court order that affects one company may cause a dozen others to give a little more thought to how they conduct their business. Even if the criminal activity were just driven a little farther underground, maybe the rest of us wouldn&#039;t have 90% of the unfiltered email in our inboxes coming from criminals instead of people we know. Criminals ought to at least feel a need to be stealthy.]]></description>
		<content:encoded><![CDATA[<p>The effect of this court order may not be that significant. But if no one takes any action against organizations that tolerate criminal activity on their networks, you end up with the situation we&#8217;ve got now where criminals operate so openly that they can amass huge botnets that constitute a threat to normal internet operations. </p>
<p>A court order that affects one company may cause a dozen others to give a little more thought to how they conduct their business. Even if the criminal activity were just driven a little farther underground, maybe the rest of us wouldn&#8217;t have 90% of the unfiltered email in our inboxes coming from criminals instead of people we know. Criminals ought to at least feel a need to be stealthy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SeymourB</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-108168</link>
		<dc:creator>SeymourB</dc:creator>
		<pubDate>Fri, 14 Sep 2012 18:15:20 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-108168</guid>
		<description><![CDATA[I was unaware that posting comments on this site required prior experience shuttering large-scale botnets. I assume that you have the necessary experience? If so, why are you posting here when Nitol is still in the wild? Go, man, go, for the good of the internets!

Like clubbing one baby seal doesn&#039;t kill all baby seals, shuttering one domain isn&#039;t going to have any kind of long-term affect on malware that&#039;s coded to use multiple DDNS providers.

Just because you don&#039;t like the ugly reality of the situation we&#039;re all in doesn&#039;t change reality.]]></description>
		<content:encoded><![CDATA[<p>I was unaware that posting comments on this site required prior experience shuttering large-scale botnets. I assume that you have the necessary experience? If so, why are you posting here when Nitol is still in the wild? Go, man, go, for the good of the internets!</p>
<p>Like clubbing one baby seal doesn&#8217;t kill all baby seals, shuttering one domain isn&#8217;t going to have any kind of long-term affect on malware that&#8217;s coded to use multiple DDNS providers.</p>
<p>Just because you don&#8217;t like the ugly reality of the situation we&#8217;re all in doesn&#8217;t change reality.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nic</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-108128</link>
		<dc:creator>Nic</dc:creator>
		<pubDate>Fri, 14 Sep 2012 17:05:11 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-108128</guid>
		<description><![CDATA[&quot;While it is nice that they took action, it would have been better if they had done a more thorough investigation of how the botnet operates when 3322 is shut down, then investigate what happens when the next DDNS site is shut down, and so on, then perform a takedown of all sites.&quot;

Is this what you have done wrt other botnets?  If so I would love to read about it.

Or do you know security researchers who have done this wrt other botnets?  If so, I would love to read about it.

As far as I know, abuse.ch (one of the best in the biz) is about the only security researcher actually doing the kind of work you describe.  He also never complains (AFAIK) when Microsoft shuts down a botnet.  My hunch is that the unnamed security researchers who complain about botnets getting shut down only do so because they have a financial incentive to keep botnets around: their investigations are worth a pretty penny to multinational corporations with more money than they know what to do with, and shutting down botnets shuts down the gravy train.]]></description>
		<content:encoded><![CDATA[<p>&#8220;While it is nice that they took action, it would have been better if they had done a more thorough investigation of how the botnet operates when 3322 is shut down, then investigate what happens when the next DDNS site is shut down, and so on, then perform a takedown of all sites.&#8221;</p>
<p>Is this what you have done wrt other botnets?  If so I would love to read about it.</p>
<p>Or do you know security researchers who have done this wrt other botnets?  If so, I would love to read about it.</p>
<p>As far as I know, abuse.ch (one of the best in the biz) is about the only security researcher actually doing the kind of work you describe.  He also never complains (AFAIK) when Microsoft shuts down a botnet.  My hunch is that the unnamed security researchers who complain about botnets getting shut down only do so because they have a financial incentive to keep botnets around: their investigations are worth a pretty penny to multinational corporations with more money than they know what to do with, and shutting down botnets shuts down the gravy train.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wiredog</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-107958</link>
		<dc:creator>wiredog</dc:creator>
		<pubDate>Fri, 14 Sep 2012 11:27:04 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-107958</guid>
		<description><![CDATA[You probably caught this on the news this morning:
http://www.nbcwashington.com/news/local/ATM-Skimmer-169624676.html]]></description>
		<content:encoded><![CDATA[<p>You probably caught this on the news this morning:<br />
<a href="http://www.nbcwashington.com/news/local/ATM-Skimmer-169624676.html" rel="nofollow">http://www.nbcwashington.com/news/local/ATM-Skimmer-169624676.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SeymourB</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-107820</link>
		<dc:creator>SeymourB</dc:creator>
		<pubDate>Fri, 14 Sep 2012 06:51:40 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-107820</guid>
		<description><![CDATA[While it is nice that they took action, it would have been better if they had done a more thorough investigation of how the botnet operates when 3322 is shut down, then investigate what happens when the next DDNS site is shut down, and so on, then perform a takedown of all sites.

As it is, botnets and malware will route around the single domain seizure and, over time, little will come of this. In other words, while there is a current hit in traffic, it will pick up as malware fails to contact its masters and moves on to backup C&amp;C systems on other domains.

On the other hand, who knows, maybe Microsoft is planning on asking the judge to grant it control of the other domains next.]]></description>
		<content:encoded><![CDATA[<p>While it is nice that they took action, it would have been better if they had done a more thorough investigation of how the botnet operates when 3322 is shut down, then investigate what happens when the next DDNS site is shut down, and so on, then perform a takedown of all sites.</p>
<p>As it is, botnets and malware will route around the single domain seizure and, over time, little will come of this. In other words, while there is a current hit in traffic, it will pick up as malware fails to contact its masters and moves on to backup C&amp;C systems on other domains.</p>
<p>On the other hand, who knows, maybe Microsoft is planning on asking the judge to grant it control of the other domains next.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott S</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-107634</link>
		<dc:creator>Scott S</dc:creator>
		<pubDate>Fri, 14 Sep 2012 00:12:47 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-107634</guid>
		<description><![CDATA[Now that&#039;s an interesting article IMO, and it will be interesting to see what MicroSoft does in regards to ridding the world of counterfeit versions of it&#039;s Windows.]]></description>
		<content:encoded><![CDATA[<p>Now that&#8217;s an interesting article IMO, and it will be interesting to see what MicroSoft does in regards to ridding the world of counterfeit versions of it&#8217;s Windows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dan</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-107505</link>
		<dc:creator>dan</dc:creator>
		<pubDate>Thu, 13 Sep 2012 20:00:50 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-107505</guid>
		<description><![CDATA[waldec and kelihs are the same botnet
they only took down the public version of rustock
none of the zeus campaigns were P2P]]></description>
		<content:encoded><![CDATA[<p>waldec and kelihs are the same botnet<br />
they only took down the public version of rustock<br />
none of the zeus campaigns were P2P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PC.Tech</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-disrupts-nitol-botnet-in-piracy-sweep/comment-page-1/#comment-107480</link>
		<dc:creator>PC.Tech</dc:creator>
		<pubDate>Thu, 13 Sep 2012 19:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16797#comment-107480</guid>
		<description><![CDATA[- https://blog.damballa.com/archives/1806
Sep 13, 2012 - &quot;... Nitol... employs multiple domains from several free dynamic DNS providers, including -other- four-digit .ORG domain services such as
6600 .org, 7766 .org, 2288 .org and 8866 .org...&quot;

(Highly recommend blocking those addresses also, if you haven&#039;t already.)
.]]></description>
		<content:encoded><![CDATA[<p>- <a href="https://blog.damballa.com/archives/1806" rel="nofollow">https://blog.damballa.com/archives/1806</a><br />
Sep 13, 2012 &#8211; &#8220;&#8230; Nitol&#8230; employs multiple domains from several free dynamic DNS providers, including -other- four-digit .ORG domain services such as<br />
6600 .org, 7766 .org, 2288 .org and 8866 .org&#8230;&#8221;</p>
<p>(Highly recommend blocking those addresses also, if you haven&#8217;t already.)<br />
.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 16/17 queries in 0.002 seconds using memcached
Object Caching 386/392 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-21 00:27:29 by W3 Total Cache -->