The InformationWeek -- Blogs
Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Is It Time For Security To Go On The Offense?


Posted by George Hulme, Apr 15, 2008 03:53 PM

Security researcher Joel Eriksson recently demonstrated how security vulnerabilities within hacker attack tools can be used to turn the tide on online criminals.


According to a Wired blog post, Eriksson, a security researcher with Swedish security form Bitsec, demonstrated how he has successfully reverse engineered attack software, such as Trojan horses, so that he can upload his own exploits on the attacking systems.

It seems Eriksson is finding vulnerabilities in a number of "remote administration" tools, including Bifrost and PCShare.

"If there is a vulnerability, it is still game over for the hacker," Eriksson is quoted as saying.

It's truly turning the tables on attackers: Once a vulnerability is found in a Trojan, it's then possible to crash, or even infect, the attacking system with the software of your choosing.

I'm all for nailing the bad guys, and while this is interesting, there’s the obvious question: are you legally justified toasting the machine that is attacking you? And what about the innocent bystander, albeit infected, systems potentially caught in the crossfire?

This research sort of reminds me of a story I wrote one week short of five years ago, about the digital tar pit, LaBrea, developed by Tom Liston. LaBrea would entrap hackers and worms -- but it froze their machine and forced the hacker to break off the attack. That story is available here, and goes into how LaBrea might go afoul of the Digital Millennium Copyright Act of 1998.

Both Eriksson's and Liston's works are laudable, in my opinion. And maybe, one day, there will be a legal mechanism, akin to digital self-defense, that would let us all safely and legally temporarily brick -- or at least reboot -- an offending system.

« TechWeb's Digital Library Gets Facebook Facelift | Main | AOL Brings Mobile Search To The iPhone »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Sequential Programming: Like Eating Peas with a Straw.
  2. Biomolecular device using self-assembled DNA nanostructures?
  3. Coreinfo v2.0: A Simple Utility to Understand the Manycore Complexity in Windows


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Verizon: $350 ETF Is A Go
  4. Motorola Explains Why Droid Doesn't Have Multi-Touch


  1. Florida Hospital Dials Up iPhones For Nurses
  2. Full Nelson: A Web Presence Needs Sizzle, My Nizzle
  3. Is Antivirus Software Dead?
  4. Practical Analysis: The Fastest-Growing Security Threat
  5. InformationWeek Analytics Research: Federated Search
  6. Securing The Cyber Supply Chain

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007