4 ms·
Using the botnet to run security patches is what fascinates me. > But it soon found it was getting competition from a malicious botnet dubbed Aidra and the res
by anonfunction 14y ago
Using the botnet to run security patches is what fascinates me.
> But it soon found it was getting competition from a malicious botnet dubbed Aidra and the researcher adapted the binary to block this competitor where possible[...]
- marshray 14y agoMy understanding is that it's actually not that uncommon for botnet malware to patch the exploit that it came in on. I too wonder if this is some deep principle at work or just something obvious.
- eitland 14y agoMy take is it's obvious: they are already in and don't need to use that exploit again. This makes sure no one else gets access as well. (On a related note: I think I remember HP demonstrate a remote mitigation tool in '07 that would use exploits to pop messages to logged in users or even shut down the machine.)
- andypants 14y agoYou don't want other malware running on your botnet. They take up resources and may make the owner realise that their computer is infected. If you patch their biggest security holes, their computer keeps on running smoothly and nobody suspects a thing.