Create an Account
username: password:
 
  MemeStreams Logo

Kaminsky Analysis of Sony Rootkit traffic

search

Elonka
Picture of Elonka
Elonka's Pics
My Blog
My Profile
My Audience
My Sources
Send Me a Message

sponsored links

Elonka's topics
Arts
  Sci-Fi/Fantasy Literature
  Movies
   Movie Genres
    Sci-Fi/Fantasy Films
  Folk
  TV Game Shows
  SciFi TV
Business
Games
  Role Playing Games
  Trading Card Games
  Video Games
   PC Video Games
   Console Video Games
   Multiplayer Online Games
Health and Wellness
Home and Garden
  Genealogy
Miscellaneous
  Humor
  MemeStreams
   Using MemeStreams
Current Events
  War on Terrorism
  Elections
Recreation
  Travel
   Asian Travel
   North American Travel
Local Information
  Missouri
   St. Louis
    St. Louis Events
Science
  Astronomy
  Biology
  History
  Medicine
Society
  Futurism
  History
  Politics and Law
   Civil Liberties
    Internet Civil Liberties
    Surveillance
  Media
   Blogging
  Philosophy
  Relationships
  Religion
Sports
Technology
  Computers
   Computer Security
    Cryptography
   Cyber-Culture
   Human Computer Interaction
   Web Design
  High Tech Developments

support us

Get MemeStreams Stuff!


 
Kaminsky Analysis of Sony Rootkit traffic
Topic: Computer Security 1:17 pm EST, Nov 15, 2005

Sony.

Sony has a rootkit.

The rootkit phones home.

Phoning home requires a DNS query.

DNS queries are cached.

Caches are externally testable (great paper, Luis!), provided you have a list of all the name servers out there.

It just so happens I have such a list, from the audits I've been running from http://deluvian.doxpara.com .

So what did I find?

Much, much more than I expected.

It now appears that at least 568,200 nameservers have witnessed DNS queries related to the rootkit. How many hosts does this correspond to? Only Sony (and First4Internet) knows...unsurprisingly, they are not particularly communicative. But at that scale, it doesn't take much to make this a multi-million host, worm-scale Incident. The process of discovering this has led to some significant advances in the art of cache snooping. Here are some of the factors I've dealt with . . .

Interesting data, courtesy of Dan Kaminsky.

Kaminsky Analysis of Sony Rootkit traffic



 
 
Powered By Industrial Memetics
RSS2.0