Message boards : Number crunching : Trojan boinc installation by rogue member
Author | Message |
---|---|
Saenger Send message Joined: 19 Sep 05 Posts: 271 Credit: 824,883 RAC: 0 |
I just found this post on the CPDN board: The person in question is Wate, who is crunching (and abusing others) here as well. Is there anything been done about hin(her? It recently came to the attention of boinc staff that a multi-project cruncher called Wate who occupied a very high position in the boinc and project stats had reached this exalted position by dishonest means. Grüße vom Sänger |
Paydirt Send message Joined: 10 Aug 06 Posts: 127 Credit: 960,607 RAC: 0 |
Thanks for the heads up! |
Michael.L Send message Joined: 12 Nov 06 Posts: 67 Credit: 31,295 RAC: 0 |
Very many thanks to Saenger! |
River~~ Send message Joined: 15 Dec 05 Posts: 761 Credit: 285,578 RAC: 0 |
... some compromised computers are still running and crashing climate models. Boinc and project staff have no means of contacting the owners of these computers. ... As I understand it, cpdn can abort a job at a trickle-up. On its own this would not be much use, as the client would simply download another client. I wonder how easy it would be to have a 'badlist' of banned users so that the scheduler would simply refuse to issue more work to them. This might prove useful in other situations as well. Just a thought. If anyone feels it is worth passing on, please repost on the BOINC forums. And I too would like to join in the thanks to Saenger for re-posting this. I have copied it across to LHC and LC. River~~ |
BennyRop Send message Joined: 17 Dec 05 Posts: 555 Credit: 140,800 RAC: 0 |
Since projects have the ip#s of the machines that are running the project under his name, they can contact the ISPs and ask the ISPs to forward a message to the owners of those ISP accounts being used. While they won't give out their email addresses to Boinc or the projects, they should be willing to pass on that information to those affected, getting them to remove the client, or sign themselves up and join a team of their own choosing. Seti was recently credited as being able to help track down a stolen laptop; so DC projects can be used to help identify systems being used on those projects. |
Saenger Send message Joined: 19 Sep 05 Posts: 271 Credit: 824,883 RAC: 0 |
Since projects have the ip#s of the machines that are running the project under his name, they can contact the ISPs and ask the ISPs to forward a message to the owners of those ISP accounts being used. While they won't give out their email addresses to Boinc or the projects, they should be willing to pass on that information to those affected, getting them to remove the client, or sign themselves up and join a team of their own choosing. Usually the IPs change quite often, some even daily, as most users are not on a permanent connection, quite a lot probably even on dial-in. To store all of them in some enormous data base would probably put a lot os stress to the data servers. The stolen puter was another matter. This was a single event with a single user, nothing to put a global drag net over every user. |
adrianxw Send message Joined: 18 Sep 05 Posts: 653 Credit: 11,840,739 RAC: 1 |
they can contact the ISPs and ask the ISPs to forward a message to the owners of those ISP accounts being used. I moderate a couple of forums. At times there have been abusers, and I have tried to remedy the problem via the perps ISP. Frankly, I have never found an ISP prepared to take action against one of their customers, unless of course, they stop paying their bills. Theoretically, from an IP address and an accurate date/time, server logs should be able to resolve a DHCP address to an end point. Wave upon wave of demented avengers march cheerfully out of obscurity into the dream. |
Feet1st Send message Joined: 30 Dec 05 Posts: 1755 Credit: 4,690,520 RAC: 0 |
Not through to an end-point... but through to a specific user's account. Yep. And the ISPs keep such logs and run other statistics over them. Timestamp, IP addr, account name, and perhaps duration... the files aren't unmanageably huge. Add this signature to your EMail: Running Microsoft's "System Idle Process" will never help cure cancer, AIDS nor Alzheimer's. But running Rosetta@home just might! https://boinc.bakerlab.org/rosetta/ |
Ensor Send message Joined: 7 Jan 07 Posts: 6 Credit: 27,111 RAC: 0 |
....Frankly, I have never found an ISP prepared to take action against one of their customers, unless of course, they stop paying their bills.... Never a truer word said.... A few years ago I was on the receiving end of a torrent of spam from a US based spammer, 300+ spam emails PER DAY!!!! His ISP point blank refused to do anything to stop him from doing this - they were/are well known for harbouring spammers and offered accounts which they guaranteed would never be suspended, for any reason.... His spam stopped abruptly when his email address database, ahem, "somehow" got poisoned with the email addresses of the CEO and other high-ups at his ISP <EVIL CACKLE>. TTFN - Pete. |
BennyRop Send message Joined: 17 Dec 05 Posts: 555 Credit: 140,800 RAC: 0 |
During the Nimda outbreak, most ISPs in the 24.x.x.x range seemed interested in Nimda infection reports so they could contact their clients and get the problem taken care of. And since I had someone in my area bring their machine in for cleaning that was told of their infection by our ISP, I got the impression that my communications with the security team bore fruit. With my experience, ISPs are willing to pass on information about infected machines to their clients. I wasn't after their email address, contact info, or trying to get them kicked off the ISP.. just get the machines cleaned up. |
Ensor Send message Joined: 7 Jan 07 Posts: 6 Credit: 27,111 RAC: 0 |
....trying to get them kicked off the ISP.. just get the machines cleaned up. All I was doing was asking the ISP concerned to enforce their own anti-spam policy, which they flatly refused to do.... :-( TTFN - Pete. |
River~~ Send message Joined: 15 Dec 05 Posts: 761 Credit: 285,578 RAC: 0 |
In all fairness Pete, the ISP you mentioned was one that made money out of harbouring people who are 'wittingly' abusing others, ie spammers. ISP's that make money out of offering customer service to folk who have been unwittingly have been caught in a scam will react differently. My response would have been to start a DOS attacl on the ISP, but the approach "someone" actually tried, effectively a DOS attack on their executive is rather neat. If you <ahem> happen to identify the "someone" give them my congratulations ;-) |
Misfit Send message Joined: 17 Sep 05 Posts: 79 Credit: 171 RAC: 0 |
Rosetta Admin should remove all of Wate's credits. That way when the stats update he loses everything. me@rescam.org |
Nightbird Send message Joined: 17 Sep 05 Posts: 70 Credit: 32,418 RAC: 0 |
Rosetta Admin should remove all of Wate's credits. That way when the stats update he loses everything. I wonder if any admin here reads this topic. ClimatPrediction : 3,631,651 credits -> zeroed Einstein@home : 2,463,297.43 credits -> zeroed PrimeGrid : + 930,000 credits -> zeroed Simap : 94,494 credits -> zeroed |
David E K Volunteer moderator Project administrator Project developer Project scientist Send message Joined: 1 Jul 05 Posts: 1480 Credit: 4,334,829 RAC: 0 |
did it. |
River~~ Send message Joined: 15 Dec 05 Posts: 761 Credit: 285,578 RAC: 0 |
did it. Thanks David |
Message boards :
Number crunching :
Trojan boinc installation by rogue member
©2025 University of Washington
https://www.bakerlab.org