ThreatFire Research Blog Home
 
 
« What’s in a name? — Adclicker agent spambots
Here come the mounties »

cDc Hacktivist Tool Release

The Cult of the Dead Cow is a group that has been around for over a decade, presented by its members as an underground hacker/do-it-yourself media group. Every now and then, they release another “tool” as a result of their research. They are known mostly for their Back Orifice tool release in the late 1990’s. Unfortunately, it was only a taste of what was to come from the world of “RAT” development, or so-called remote administration tools. These sorts of tools were often used to maintain botnets and control over compromised systems for malicious purposes.

This new tool, the Goolag Scanner, is a stab at using Google’s technologies for security research (open to definitions of white, grey, or black hat), and a part of the cDc hacktivist response “to Google’s decision to comply with China’s Internet censorship policy and censor search results in the mainland-Chinese version of its search engine.” Its interface is similar to the popular Nessus vulnerability scanner. While use of the scanner most likely violates every contractual licensing agreement in the Google’s terms of service, it provides an automated method of evaluating web sites for vulnerabilities using “Google Hacks”, or “Dorks” that were popularized by “Johnny Hack” and his “Google Hacking Database“.

In line with their generally dark humor, this version of the scanner is being released as the “Stanley Kowalski” version, most likely in reference to an awful character from Tennessee Williams’ “Streetcar Named Desire”, along with a tough love usage statement:
“If this software does something bad to your computer or network or provides information that you have no legal right to see, then that’s your problem. In some countries this software might be illegal. Don’t be stupid, and don’t come whining to us if you get into trouble. You’ve been warned.”

Discussions on various security mailing lists wager on how long the site will remain up. It seems that the cDc presents the site as a parody of the google site itself:
“It isn’t even a particularly good parody. As such, it is protected by the First Amendment.” It most likely will be up for a while:

Web admins should be sure to attend to the security needs of their servers.

This entry was posted on Thursday, February 21st, 2008 at 10:00 am and is filed under Exploit, RAT. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • FBI IC3 2009 Report
    • FakeAv Antivirus XP 2010
    • Troyak-AS De-peered for Good?
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • A.M. Infosec
    • AV-Comparatives
    • iAntivirus
    • Mind Streams of Information Security Knowledge
    • Symantec Security Response
    • Tech Thoughts
    • ThreatExpert
  • Links

    • AMTSO
    • AV-Test
    • ICSA Labs
    • PC Tools
    • PC Tools is on Facebook
    • Reconstructer
    • ThreatExpert
    • ThreatFire
    • Uninformed
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).