On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

March 12th, 2009

BBC team buys a botnet, DDoSes security company Prevx

Posted by Dancho Danchev @ 6:46 am

Categories: Anti Virus, Botnets, Browsers, Denial of Service (DoS), Hackers, Malware, Passwords, Phishing, Rootkits, Spam and Phishing, Spyware and Adware, Viruses and Worms

Tags: Security, Cybercrime, DDoS, Distributed Denial of Service Attack, BBC, Prevx, Dancho Danchev

Update: BBC Click’s tweet states that they took legal advice following comments on the potential violation of U.K’s Computer Misuse Act.

There’s a slight chance that you may have unknowingly participated in a recent experiment conducted by the BBC.

In a bit of an awkward and highly unnecessary move, a team at the BBC’s technology program Click has purchased a botnet consisting of 22,000 malware infected PCs, self-spammed themselves on a Gmail account, and later on DDoS-ed a a backup site owned by security company Prevx (with prior agreement), all for the sake of proving that botnets in general do what they’re supposed to - facilitate cybercrime.

A video of the experiment is already available. Here are more details :

Upon finishing the experiment, they claim to have shut down the botnet, and interestingly notified the affected users. Exposing cybercrime or exposing the obvious, the experiment raises a lot of ethical issues. For instance, how did they manage to contact the owners of the  infected hosts given that according to the team they didn’t access any personal information on them?

It appears that they modified the desktop wallpapers of all the infected hosts to include a link notifying them that they’ve been part of the experiment. Thanks, but no thanks.

Let’s talk money, and how much did they pay to get access to the botnet. Despite the fact that they’re not mentioning the exact amount, a quote within their article once again puts the spotlight on the dynamics of cybercrime economy :

“Computers from the US and the UK go for about $350 to $400 (£254-£290) for 1,000 because they’ve got much more financial details, like online banking passwords and credit cards details,” he said.”

I beg to differ. From my perspective based on the active monitoring of on the growing “botnet for hire” business during the last couple of years, it appears that the BBC got scammed on their way to expose the scammers by overpaying them. In a dynamic underground marketplace where transparency of the sellers and buyers doesn’t exist for the sake everyone’s anonymity, you are unable to say whether you’ve made a good or bad deal, since you’re unaware of all the propositions. Namely, the botnet you’ve just purchased is available at a cheaper price from a vendor of whose existence you’re not even aware of.

Take a peek at the screenshot from a similar service that’s been active for several years, with hosting services provided by “our dear friends” at Layered Technologies, and how cheaper their services are. See, I told you, but I didn’t and wouldn’t demonstrate you the obvious effectiveness of botnets in general. Take that for granted.

In an interview which I took from German malware researchers earlier this year, their primary concern for using a methodoly that could issue potential disinfection commands to Storm Worm infected hosts was the legal, and also, ethical side of the practice. Just like the way it should be, since their approach is among the many other the community is taking advantage of on its way to fighting cybercrime.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 45 Talkback(s)
Quite
You're right, it's an impossibility. (Read the rest)
Posted by: d.s.williams Posted on: 04/14/09 You are currently: a Guest | | Terms of Use
Did the BBC break the law?  gcluley | 03/12/09
With all due respect: stop already.  ejhonda | 03/12/09
Bad analogy...  techboy_z | 03/12/09
So what you are saying is that were actually using a stolen gun.  Been_Done_Before | 03/12/09
Who said that?  ejhonda | 03/12/09
Excellent point!  MGP2 | 03/12/09
Ecxactly. And after this the allready EXISTING botnet  hkommedal | 03/13/09
Doiesn't matter what anyone said  mdsock@... | 03/13/09
Nothing wrong  croberts | 03/12/09
No, it sounds like they did indeed infect the machines  GuidingLight | 03/12/09
I believe "the programme"...  MGP2 | 03/12/09
Nothing wrong?  d.s.williams | 03/13/09
Well done, BBC.  johnhaverysamuel | 03/12/09
True investigative journalism?  d.s.williams | 03/13/09
Heisenberg  reziol | 03/13/09
Quite  d.s.williams | 04/14/09
Rule one...  amunar@... | 03/13/09
RE: BBC team buys a botnet, DDoSes security company Prevx  jtwaldo | 03/12/09
Good stuff... ethical or not, botnets exist and are trouble.. but...  Been_Done_Before | 03/12/09
By buying a botnet they have helped hackers make money  malcarada | 03/12/09
The authorities do it all the time...  MGP2 | 03/12/09
The authorities do it all the time...  gazzerjay@... | 03/13/09
Except  mdsock@... | 03/13/09
It's not unusual  d.s.williams | 03/13/09
On a side note, ISPs could shut them all down.  TripleII | 03/12/09
Some have the will......  middle of nowhere | 03/12/09
Awesome!  TripleII | 03/12/09
I agree with TripleII  davagain | 03/18/09
RE: BBC team buys a botnet, DDoSes security company Prevx  catmedia | 03/13/09
Fw: 000webhost.com  catmedia | 03/13/09
Interestingly  therealbigb | 03/13/09
Couple of points  wkeneipp@... | 03/13/09
Phished into reading this story...  M.W.H. | 03/13/09
Prostitution  Quigs | 03/13/09
RE: BBC team buys a botnet, DDoSes security company Prevx  hoxco94@... | 03/13/09
RE: BBC team buys a botnet, DDoSes security company Prevx  Bill F. | 03/13/09
RE: BBC team buys a botnet, DDoSes security company Prevx  DurbanDon | 03/13/09
How has the BBC done the PC owners a favour?  gazzerjay@... | 03/13/09
If it helps get the message across  tony@... | 03/13/09
A "Technical Transgression" is still "Breaking the LAW!"  gazzerjay@... | 03/13/09
All laws are't equal and nor is their application  pvandck | 03/16/09
RE: BBC team buys a botnet, DDoSes security company Prevx  Mike Bear | 03/13/09
Great Idea, fine tune it  T Mike | 03/14/09
RE: BBC team buys a botnet, DDoSes security company Prevx  pvandck | 03/16/09
Good Work BBC. Sorry for articles trying to make a buck off of it -  softwareFlunky | 03/16/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline