Everything2
Near Matches
Ignore Exact
Full Text
Everything2

Stupid things script kiddies do

created by dg

(idea) by dg (11.3 mon) (print)   ?   (I like it!) 1 C! Fri Sep 08 2000 at 3:04:16

Why are the programmers (if I may call them that) who write attack tools so incredibly, mind-numbingly, jaw-droppingly stupid? It must be some sort of inherent deficiency in the mental functioning of the sort of miscreants who feel compelled to create tools whose sole purpose is to attack other people's computers. I mean, if they are going to bother doing it at all, why the hell don't they do it right?

Here are three things that are utterly brain-dead about today's attack tools as used by today's script kiddies.

Too much logging
For some reason every time some script kiddie installs a packet sniffer on a box they've rooted they feel this need to have it log absolutely every packet that carries a username/password combo. They end up with a master list of usernames and passwords for the box they've cracked. Unfortunately for them, the sysadmin of the box also ends up with the master list of every account that the stupid script-kiddie has compromised. Now guess which accounts the sysadmin is going to change the password on?

A much better strategy for the clueless cracker would be to log only some of the compromised data. Maybe if they'd say this-

   if(!(++cracked_account_count % 5))
       mail_bad_guy_the_goods(user, passwd);
   else
       log_it_just_to_fuck_with_the_sysadmin(user, passwd);
      
they'd actually be able to do something interesting with the hijacked accounts.

Trojan Binaries
Ok, just who is the absolute Einstein who came up with this gem? Just about the first thing that any sysadmin does upon bringing up a new system is run Tripwire (or one of its many proprietary competitors). After that, Trojan attacks are not only not useful, they're actually detrimental to the luser's efforts. As soon as the modified binaries are detected, the box enters a period of intense scrutiny as the now pissed-off administrator goes filesystem spelunking looking for other signs of damage.

The better strategy here is to modify the .profile of most of the stolen logins to do something nefarious with some brand-new software (which won't trip most file integrity software) installed by the cracker. Don't worry though, the black hats appear to be too stupid to figure this out.

Resource hogs
Attention K-Mart crackers, repeat after me: "If my program hogs all of the disk space, if it gobbles all of the cpu time, if it overflows memory or swamps a network interface it will be noticed and removed. After it is removed, it will no longer run. Software that doesn't run, isn't useful."

Just think about how Mother Nature does it--the most successful parasites don't kill their hosts, they just make them a little less healthy.


(idea) by Neko (5.7 y) (print)   ?   (I like it!) Fri Sep 08 2000 at 3:28:01

From my understanding, this comes down one thing basically - most of the script kiddies arsenal starting life originally as something else. Most of the time as something that actually had a legitimate use as a defence or analysis tool eg Packet Sniffer.

And if it's not the original product that they're using then it has most likely hacked up by somebody who doesn't really have any idea what they're doing and consequently ends up screwing the nice piece of software that someone else spent a lot of time on.

On the other hand, do you really want script kiddies to have access to real software used for this purpose? Of course not! But what they've got makes them feel special, but keeps them from causing any real trouble.


printable version
chaos

Tripwire Right-click trap script kiddie I H4XX0RED E2!!
ext2 filesystem basics Urban spelunking Packet sniffer bad grammar is the halitosis of the internet
Microsoft Visual C++ If only the spaghetti westerns were half as good as their titles Black hat smurfing
Google hacking warez kiddies Messalina prepares to run An introduction to "The Move"
How to connect any cellular phone to a modem cluster filesystem luser Counter Strike
IPChains WINS versus DNS AIM script kiddies compromise
Y'know, if you log in, you can write something here, or contact authors directly on the site. Create a New User if you don't already have an account.
  Epicenter
Login
Password

password reminder
register

Everything2 Help

Cool Staff Picks
What you are reading:
The oppression of definition
Steve Jobs
Pica
Milkweed
Ten reasons to believe in God
The Island of Dr. Moreau
February 16, 2007
Arabic coffee
The Garden
Washing dishes
Jerusalem artichoke
philodendron
At the Mountains of Madness
New Writeups
dagnyswaggart
Dissolve like dreams.(personal)
XWiz
Trism(review)
artman2003
Briefcase Full of Souls - Part I(fiction)
Dreamvirus
Alan Ladd(person)
waverider37
Harold Holt(person)
The Debutante
Until death do us part(fiction)
Ysardo
a brother to a sister(personal)
antigravpussy
your warm whispers(personal)
Clarke
Multiculturalism(idea)
aneurin
Earl of Landaff(person)
Heitah
Pseudocide(idea)
XWiz
Google Knol(lede)
Mythi
July 24, 2008(personal)
locke baron
The fall of Earth(fiction)
BookReader
Fear the Cold(dream)
This page courtesy of The Everything Development Company