Message boards :
Number crunching :
Do we have a Boinc virus?
Message board moderation
Previous · 1 · 2 · 3 · 4 · 5 . . . 27 · Next
Author | Message |
---|---|
Fred G Send message Joined: 17 May 99 Posts: 185 Credit: 24,109,481 RAC: 0 |
I definitely agree. I imagine with the account deleted the exploited computers will run out of WU's and continue trying to contact SETI.Very interesting ... quite an exploit ... :( http://www.teamstarfire.org/ |
Jack Gulley Send message Joined: 4 Mar 03 Posts: 423 Credit: 526,566 RAC: 0 |
I imagine with the account deleted the exploited computers will run out of WU's and continue trying to contact SETI. Based on the way Seti@home Classic was shut down, and with BOINC having the ability to "update" installed science applications, I imagine the Berkeley staff would have a way to pop a message up on each of those hacked systems and to cause the program to self destruct in some way. |
Michael Send message Joined: 21 Aug 99 Posts: 4608 Credit: 7,427,891 RAC: 18 |
I definitely agree. I imagine with the account deleted the exploited computers will run out of WU's and continue trying to contact SETI.Very interesting ... quite an exploit ... :( I smell foul play. Someone has made BOINC the payload of a trojan. |
Crunch3r Send message Joined: 15 Apr 99 Posts: 1546 Credit: 3,438,823 RAC: 0 |
I definitely agree. I imagine with the account deleted the exploited computers will run out of WU's and continue trying to contact SETI.Very interesting ... quite an exploit ... :( And the account belongs to a company ---> www.esc-consult.de. I'm curious if this was done by an employee and the comany gets bad credit for that one now. Would be interesting if someone could/would contact them the hear what they have to say about this. Join BOINC United now! |
Fuzzy Hollynoodles Send message Joined: 3 Apr 99 Posts: 9659 Credit: 251,998 RAC: 0 |
http://www.esc-consult.de/kontakt.htm "I'm trying to maintain a shred of dignity in this world." - Me |
trux Send message Joined: 6 Feb 01 Posts: 344 Credit: 1,127,051 RAC: 0 |
Hmm, very interesting and very dangerous for the project and for the community!!! Can someone of the people here having direct wire to Rom or others at Berkeley assure that they are aware of it, and taking the necessary steps to avoid banning BOINC by antimalware, antivirus and firewall software and before it makes news in some IT magazines? I know the user ID quite well - I noticed him when he, as the leader of SETI Germany with increible RAC of ~70k (now it is even more) left the team and created his own one just few weeks ago. I found it very strange, but since there were others leaving the team shortly after (including some well known forum members), I thought there were some internal conflicts behind it (we just seem to have one at CNT too). I find it very important that some officials make the necessary steps to avoid more damage. I hate to tell it, but this is a criminal activity, and the author of the act desires to be investigated by the police. I hope for him that he is innocent and it was just some stupid friend of the victim who installed it manually (though it definitely does not look like). trux BOINC software Freediving Team Czech Republic |
MikeSW17 Send message Joined: 3 Apr 99 Posts: 1603 Credit: 2,700,523 RAC: 0 |
Hmm, very interesting and very dangerous for the project and for the community!!! Can someone of the people here having direct wire to Rom or others at Berkeley assure that they are aware of it, and taking the necessary steps to avoid banning BOINC by antimalware, antivirus and firewall software and before it makes news in some IT magazines? While this situation does need watching, I don't believe that anything yet needs to be done. As others have pointed out, Classic SETI was also installed 'unofficially' on many machines by various dubious means - The sky didn't fall in. IMO, the more that's said about this, the greater the (uninformed) awareness of the issue. As often happens, the discussiuon/fear/reaction of/to 'security issues' generally wastes more time/creates more upheaval than the threat ever created or posed. |
Lee Carre Send message Joined: 21 Apr 00 Posts: 1459 Credit: 58,485 RAC: 0 |
As often happens, the discussiuon/fear/reaction of/to 'security issues' generally wastes more time/creates more upheaval than the threat ever created or posed.that applies to almost all "security" situations. Read Bruce Schneier's blog, he's a security expert who knows what he's talking about, and knows what real security is, he thinks and talks about security in a very rational way, discussing real-world security issues, most security responces are completely pointless, or unnecessary, some of the things he suggests aren't what you'd expect at all, but what what he suggests is true |
MikeSW17 Send message Joined: 3 Apr 99 Posts: 1603 Credit: 2,700,523 RAC: 0 |
As often happens, the discussiuon/fear/reaction of/to 'security issues' generally wastes more time/creates more upheaval than the threat ever created or posed.that applies to almost all "security" situations. Exactly, therefore no one at Berkeley or anywhere else needs to take any special action, beyond the standard AV and safe computing practices. |
Lee Carre Send message Joined: 21 Apr 00 Posts: 1459 Credit: 58,485 RAC: 0 |
As often happens, the discussiuon/fear/reaction of/to 'security issues' generally wastes more time/creates more upheaval than the threat ever created or posed.that applies to almost all "security" situations. precisely, this isn't a boinc problem it's the same as with guns, guns don't kill people, people kill people boint doesn't just install itself without permission on it's own, someone instructs it to do so, the problem is the person, not the tool |
MikeSW17 Send message Joined: 3 Apr 99 Posts: 1603 Credit: 2,700,523 RAC: 0 |
Right. My point is that putting the words 'BOINC' and 'Virus' in the same sentence is potentially more dangerous than a destructive BOINC Variant ever could be. As soon as the two words appear together all reason goes from the minds of millions of users and compuer professionals alike and a witch-hunt begins. |
trux Send message Joined: 6 Feb 01 Posts: 344 Credit: 1,127,051 RAC: 0 |
it's the same as with guns, guns don't kill people, people kill peopleExplain to the Gestapo it was not you who killed H. Heidrich even if it is apparent your gun was used. I mean I do not agree - some damage control needs to be done, and exemple must be shown to wanabe followers - account cancelled, credit removed from the team stats, and information about him posted on a Black Board (it seems it needs to be created) trux BOINC software Freediving Team Czech Republic |
trux Send message Joined: 6 Feb 01 Posts: 344 Credit: 1,127,051 RAC: 0 |
Right. My point is that putting the words 'BOINC' and 'Virus' in the same sentence is potentially more dangerous than a destructive BOINC Variant ever could be.Exactly! And as soon as people not having any relation to BOINC start reporting it to media or to antivirus/antimalware companies, you can be sure the impact will be big. Therefore, better make the damage control now! trux BOINC software Freediving Team Czech Republic |
trux Send message Joined: 6 Feb 01 Posts: 344 Credit: 1,127,051 RAC: 0 |
|
Michael Send message Joined: 21 Aug 99 Posts: 4608 Credit: 7,427,891 RAC: 18 |
Right. My point is that putting the words 'BOINC' and 'Virus' in the same sentence is potentially more dangerous than a destructive BOINC Variant ever could be.Exactly! And as soon as people not having any relation to BOINC start reporting it to media or to antivirus/antimalware companies, you can be sure the impact will be big. Therefore, better make the damage control now! Agree! |
john_morriss Send message Joined: 5 Nov 99 Posts: 72 Credit: 1,969,221 RAC: 48 |
As an aside: How do the results from this "team" look? If someone is going to do a secret install to get credits, will he/she necessarily use a valid app? Just a thought... |
Lee Carre Send message Joined: 21 Apr 00 Posts: 1459 Credit: 58,485 RAC: 0 |
it's the same as with guns, guns don't kill people, people kill peopleExplain to the Gestapo it was not you who killed H. Heidrich even if it is apparent your gun was used. different issue, my point was that the gun acting alone (if that's possible for an inanimate object) doesn't kill someone, it needs to be fired by a person what you're talking about is ownership, have you heard of zombie or bot networks, these are mostly computers of unaware users conducting a DDoS attack, just beacuse john doe owns one of these infected computers, doesn't mean he's responsible just beacuse my car might have been used in a robbery, doesn't mean i was there, it just means my car was, because it was probably stolen please take a look at an idiotic article on TMP in which the blatent problems with the implied "security" of the system is made apparent, the main quote from the original article being... In fact, with TPM, your bank wouldn’t even need to ask for your username and password -- it would know you simply by the identification on your machine. and the comment to that... Since when is "your computer" the same as "you"? i wouldn't try to explain, the Gestapo usually just did what they wanted, right or wrong, because they were power hungry and unreasonable, so if they wanted to kill me they would anyway however, (i'd hope) the officials in charge of security today (national security and the like) would be more reasonable, and if something controversial makes sense, then they'd at least listen |
trux Send message Joined: 6 Feb 01 Posts: 344 Credit: 1,127,051 RAC: 0 |
different issue, my point was that the gun acting alone (if that's possible for an inanimate object) doesn't kill someone, it needs to be fired by a personYou do not get the point. People will not study what is BOINC as soon as it is associated with malware and viruses in some IT magazine article, or when antimalware/antivirus/firewall software starts reporting BOINC as potential intruder. It is pointless to discuss whether it is the owner or the gun who killed, once the owner got bad reputation, the good conscience does not help him a lot to repair the damage. It may safe him from the punisment (and even that does not happen always), but it will ruin his life nevertheless. trux BOINC software Freediving Team Czech Republic |
Lee Carre Send message Joined: 21 Apr 00 Posts: 1459 Credit: 58,485 RAC: 0 |
different issue, my point was that the gun acting alone (if that's possible for an inanimate object) doesn't kill someone, it needs to be fired by a personYou do not get the point. People will not study what is BOINC as soon as it is associated with malware and viruses in some IT magazine article, or when antimalware/antivirus/firewall software starts reporting BOINC as potential intruder. It is pointless to discuss whether it is the owner or the gun who killed, once the owner got bad reputation, the good conscience does not help him a lot to repair the damage. It may safe him from the punisment (and even that does not happen always), but it will ruin his life nevertheless. true, and again, i'm not disputing that but, again, that's a different issue, but the fact still remains if i had to make a suggestion, i'd say inform all the right places about what boinc is, before they make their own assumptions, that would be a good path towards damage control |
trux Send message Joined: 6 Feb 01 Posts: 344 Credit: 1,127,051 RAC: 0 |
if i had to make a suggestion, i'd say inform all the right places about what boinc is, before they make their own assumptions, that would be a good path towards damage controlThat begins to sound better, but is still not sufficent. What we need is publicly showing and punishing such cheaters - having Black Boards on the official BOINC and project web sites, where such people will be displayed, accounts and credits removed, and their credits removed from all their present and former teams too. If such people are legally persecuted, it also needs to be shown there - so that it serves as a sufficinet deterrent for other potential followers. If people are fired because of illegally installing BOINC in their jobs, it should be shown there too. trux BOINC software Freediving Team Czech Republic |
©2024 University of California
SETI@home and Astropulse are funded by grants from the National Science Foundation, NASA, and donations from SETI@home volunteers. AstroPulse is funded in part by the NSF through grant AST-0307956.