[Project] W32.Asclepius.Worm
[Project] W32.Asclepius.Worm
I'm at this very moment sitting in my bed with my lappy in the dark, because I can't sleep. And this thought just hit me....
There are a lot of old worms out there still circling around the net because of old un-updated computers, like blaster and such.
What if one was to create a sort of "white blood cell" or simply a friendly worm that would scan the net for old vulnerabilities, and on finding a hole, it would spread just like the "malicious" worm does, but instead of causing havoc, it would remove the worm in question from the infected computer, patch the vulnerability, and warn the user.
And, hell, why stop there? SQL worms are pretty common these days, might as well make it take care of that as well =)
The friendly little worm that I now have created in my head, has a pretty good name imo. "Asclepius", which (afaik) is a healing God in Greek mythology.
I mean, at the moment people are mostly defending themselves against malicious code. It will never stop if no changes are done, so I say we need to fight fire with fire! ^^
There are a lot of old worms out there still circling around the net because of old un-updated computers, like blaster and such.
What if one was to create a sort of "white blood cell" or simply a friendly worm that would scan the net for old vulnerabilities, and on finding a hole, it would spread just like the "malicious" worm does, but instead of causing havoc, it would remove the worm in question from the infected computer, patch the vulnerability, and warn the user.
And, hell, why stop there? SQL worms are pretty common these days, might as well make it take care of that as well =)
The friendly little worm that I now have created in my head, has a pretty good name imo. "Asclepius", which (afaik) is a healing God in Greek mythology.
I mean, at the moment people are mostly defending themselves against malicious code. It will never stop if no changes are done, so I say we need to fight fire with fire! ^^
Last edited by ayu on 25 Feb 2009, 15:11, edited 1 time in total.
"The best place to hide a tree, is in a forest"
- computathug
- Administrator
- Posts: 2693
- Joined: 29 Mar 2007, 16:00
- 17
- Location: UK
- Contact:
outside the box
Now i definitely like the sound of this. The question is would the AV companies leave the signatures and leave it UD as it wouldn't be malicious and how long before someone attaches on to the idea and adds malicious content to the source.
I wonder if this worked if it would still be classed as an intrusion. I can see the headlines now 'developer gets 6 years for the introduction of the super W32.Asclepius.Worm' even though it has just patched 1 million computers worldwide from a known vulnerability.
Maybe this would work if you gave it rights to ask the user for permission first before patching but then most would deny it the privilege as it would be then more than likely be called 'spam'. There again its unbelievable how many computers i go to repair that don't have any protection at all, so this wouldn't be a problem to them.
Nice thought though
I wonder if this worked if it would still be classed as an intrusion. I can see the headlines now 'developer gets 6 years for the introduction of the super W32.Asclepius.Worm' even though it has just patched 1 million computers worldwide from a known vulnerability.
Maybe this would work if you gave it rights to ask the user for permission first before patching but then most would deny it the privilege as it would be then more than likely be called 'spam'. There again its unbelievable how many computers i go to repair that don't have any protection at all, so this wouldn't be a problem to them.
Nice thought though
- Shimo
- Fame ! Where are the chicks?!
- Posts: 197
- Joined: 17 May 2008, 16:00
- 15
- Location: Canada
- Contact:
I some how think AV companies would not be very happy.... I mean its taking away from there buissness. Most companies would treat it as a major threat.. Although the newslines would be very comical.... I vote you get to work.
[img]http://i133.photobucket.com/albums/q49/xblric9000000/ShimoSignature.jpg[/img]
- Big-E
- Administrator
- Posts: 1332
- Joined: 16 May 2007, 16:00
- 16
- Location: IN UR ____ , ____ING UR _____ .
- Contact:
I've actually been on more professional forums where this exact thing has been pondered and it always comes up to one thing, as thuggy mentioned - ethics. Why is it right for a non-malice user to intrude when it`s not okay for a malice user to intrude. We can use DNR's old analogy with scanning, as an example. Think of it like this - a burglar enters your home when you are away, you think "WTF and GTFO" whereas the cops enter your house when you are not around and you still think "WTF and GTFO". Truth be told, no one should be entering your house without your authorization.
My opinion, behind every good deed is trouble waiting to happen. Again, back to exactly what thuggy has mentioned - when will this good worm be turned into something bad?
My opinion, behind every good deed is trouble waiting to happen. Again, back to exactly what thuggy has mentioned - when will this good worm be turned into something bad?
is it raining?
1. Still illegal to unauthorized access to a computer or network, in USA, and UK. Your app will be doing just that. Corporations will accuse you of damage and seek monetary compensation. Law Enforcement will want to bill you for their time to figure things out. Even Jail while the dumbasses try to understand why someone would do something nice anyways.
2. Heuristic behavior of your software will get it flagged quick by hostbased firewalls and network IDS as malware. You'll be stopped right at the starting gate.
Nice idea, but don't. Consider someone could rewrite bits of your code to make it hostile too.
Sorry to piss on your parade!
DNR
2. Heuristic behavior of your software will get it flagged quick by hostbased firewalls and network IDS as malware. You'll be stopped right at the starting gate.
Nice idea, but don't. Consider someone could rewrite bits of your code to make it hostile too.
Sorry to piss on your parade!
DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.
- Big-E
- Administrator
- Posts: 1332
- Joined: 16 May 2007, 16:00
- 16
- Location: IN UR ____ , ____ING UR _____ .
- Contact:
Re: is it raining?
DNR wrote:.....
2. Heuristic behavior of your software will get it flagged quick by hostbased firewalls and network IDS as malware. You'll be stopped right at the starting gate.
Nice idea, but don't. Consider someone could rewrite bits of your code to make it hostile too.
Sorry to piss on your parade!
....
DNR
No, I say do it. I already had this discussion with someone today; there is ALWAYS risk associated with innovation. There is going to be 'bad' uses for everything; I thought about it, I say go for it.
If cats can develop a decentralized patch for various security vulnerabilities, and provide a unique method of doing so whilst defeating all current barriers, I say make the attempt.
Cats, you may be interested in this link:
http://www.people.frisk-software.com/~bontchev/
Attempts at creating 'good' worms have failed, many times because the writers did not adopt the safeguards outlined in the Bontchev paper. In 1982, prior to Bontchev's work, two Xerox Palo Alto Research Center (PARC) researchers John Shoch and Jon Hupp coined the term 'worm' for a program that spread around their 100-computer network updating drivers. A flipped bit in the program caused the resulting worm to spread uncontrollably and clog the network.
Source:http://www.securityfocus.com/news/11506
-
- On the way to fame!
- Posts: 28
- Joined: 23 Jul 2008, 16:00
- 15
While this is a cool project, I'm still stuck on.....Why?
If people are to lazy and/or incompetent to be able to complete the necessary steps in securing whatever they are using, they lose. It seems like now a days everyone relies on someone else to do shit for them. With the increase in the use of technology basic security and how to implement it shouldn't be something you do when you have spare time...
Ignorance is bliss does NOT carry over into computing all that well and it never should. = /
Meh, it's 4 am and I've run out of brain cells : (
If people are to lazy and/or incompetent to be able to complete the necessary steps in securing whatever they are using, they lose. It seems like now a days everyone relies on someone else to do shit for them. With the increase in the use of technology basic security and how to implement it shouldn't be something you do when you have spare time...
Ignorance is bliss does NOT carry over into computing all that well and it never should. = /
Meh, it's 4 am and I've run out of brain cells : (
moar doritos plox <3
Well of course it's illegal, but I would never make it so that they could track it here anyway ^^
And the reason I'm doing it is to learn, and to force people to stay safe, since they refuse to do it because of ignorance and idiocy. You might think "yeah, why should I care about them?", well, for every idiot who doesn't give a fuck about their computer getting infected with shit, the more load there is on the internet, and more ways for malware to spread, therefore I want to fight it with the malware producers own methods.
And, don't worry DNR, I have thought about that as well, the worm will go through a lot of testing before it's "released", and also, there are loads of worms like this that have a malicious purpose, one more wouldn't change much.
Thanks for the material E ^^
The show must go on!
And the reason I'm doing it is to learn, and to force people to stay safe, since they refuse to do it because of ignorance and idiocy. You might think "yeah, why should I care about them?", well, for every idiot who doesn't give a fuck about their computer getting infected with shit, the more load there is on the internet, and more ways for malware to spread, therefore I want to fight it with the malware producers own methods.
And, don't worry DNR, I have thought about that as well, the worm will go through a lot of testing before it's "released", and also, there are loads of worms like this that have a malicious purpose, one more wouldn't change much.
Thanks for the material E ^^
The show must go on!
"The best place to hide a tree, is in a forest"
- computathug
- Administrator
- Posts: 2693
- Joined: 29 Mar 2007, 16:00
- 17
- Location: UK
- Contact:
what if: all the different platforms, apps, drivers - you better hope it doesn't crash something, good intentions or not.
A good deed never goes unpunished...
DNR
A good deed never goes unpunished...
DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.
- str33tl0rd
- Fame ! Where are the chicks?!
- Posts: 241
- Joined: 04 Jul 2008, 16:00
- 15
- Location: somewhere
good idea, but not always you fight fire with fire...couz then there is always a more bigger one that will take over...and this is one of those cases...i doubt you will suceed not meanin' you shouldn't try...but give it your best...i hope to see your worm do something that other worms don't do. =]
A fools mind is at the mercy of his tongue and a wise mans tongue is under the control of his mind.~ Imam Ali (A.S)