HP sets ‘good worm’ loose
p2pnet.net News:- There’s a ‘good worm’ out there. And it belongs to HP.
The company says it’s moving its Active Counter Measures distributed scanning tool into beta and plans to release it in 2005.
“Active Counter Measures is software designed in HP Labs that uses techniques similar to those of network attackers to scan the network for machines that might be vulnerable to attack,” says an InfoWorld story here, but instead of loading a virus or malicious software, it installs a software patch to repair the vulnerability.”
“We’re fine tuning it now and making sure it’s good to go,” Tony Redmond, vp and cto with HP Services is quoted as saying. “This is a good worm. It’s turning the techniques (of the attackers) back on them.”
HP is still working out the details of how to market the product, which was first disclosed in February of this year, but it seems unlikely that it will be included as part of the company’s OpenView suite of management software, says Redmond in the report.
Redmond also boasts that HP’s network administrators haven’t been bitten by a worm or a virus since 2002, “in part because of the company’s deployment of Active Counter Measures”.
[In some circles, that'd be considered fighting talk - Ed]





August 19th, 2004 at 2:34 am
This is a good idea on the surface but…………
what if some unscrupulous individual were to develop a simular program or someone at HP decides to install some other programs in conjunction to monitor each individual for whatever reason. I like the idea as long as it’s approved by each individual computer user.
I don’t like the idea of someone installing something on my system without my knowledge reguardless of the benifits
August 19th, 2004 at 4:09 am
wasn’t a variation of this done last summer with blaster? I seem to recall microsoft did a similar stunt.
I think it’s unethical, I can’t see any “good” in having my system turned into server to carry out the work of the “good” worm.
August 19th, 2004 at 1:31 pm
They’re just going to add more congestion to the net through this scanning activity, this doesn’t sound adequately thought through or explained enough.
August 19th, 2004 at 6:07 pm
The sad reality of things is that people don’t patch their machines (even some IT departments are guilty of this.). Users unknowingly compromise their systems, and frequently, just don’t know any better. I often hear, “I didn’t know that you had to do that!” With that in mind, if you can’t depend on the user to secure their system, at least it gets done. And you effectively neuter any worm that exploits that vulnerability. I’d say, “make some more!” (Let’s neuter the virus writers while we’re at it.)
August 20th, 2004 at 1:24 am
I think everyone is missing the point, with the ‘good worm’ being an analogy for the method they are employing. Actually, they aren’t releasing this worm into the ‘wild’ like the Blaster and others have been deployed. This thing is supposed to stay at home and eat the lunch of the other ‘wild worms’ that are outside looking for a meal.
It stays inside your own servers and machines, and works in conjunction with the admins and automated tools to innoculate your system and patch holes automagically, and instead of exploiting any holes it finds it plugs them up BEFORE the ‘wild worms’ come along to do the nasty to your setup.
Sort of like an ‘always on’ update tool that just runs around to find all the problems and fix them before anyone else does. Of course, it can’t look for NEW exploits, but it should be pretty good at keeping the usual suspects out of the loop. Sounds like an interesting tool set, but I imagine the first few days of shaking out your network would be FUN, NOT!
As to a disgruntled employee adding ‘extras’ into the code, I am pretty sure the code shops should be able to look at the code and figure out any hacks someone might come up with. Isn’t that the point of all those CVS servers, and all those guys tirelessly auditing the code, looking for such things, or some similar process where ever you might be? Surely they wouldn’t release something that would compromise security by doing something unauthorized, would they?
August 20th, 2004 at 5:04 pm
> Redmond also boasts that HP’s network administrators haven’t been bitten by a worm or a virus since 2002, “in part because of the company’s deployment of Active Counter Measures”
That’s a pretty big boast, considering that MyDoom-M pretty much infected them worldwide. How do I know that? Because MyDoom-M travels with an encoded IP log up to 256 machines it has infected along the way. Every copy I received had mostly HP IP addresses in the log.
August 20th, 2004 at 11:01 pm
look Jass,
It will be just for those haters who went around telling people that I was using druggs knowing I was never the type to get high. I lost my appatite, and I can admitt that my own apatite was the source of my hunger pains, when it went away I got my focuss on my new music and you may think it aint the same and when you here my CD I want to here the words that you will choose on your own. LISTEN TO THAT MUSIC YOU ARE PLAYING, AND WHAT IS THE TEMPO SETTING ? OKAY, AND WHAT ? I MEAN I CAN DESCRIBE WHEN YOU,…. YOU-OOO–OOO,.. FEEL HEY–A-AAA-A CER-TAIN WAY HEY-OH- OO-OH,….. ABOUT,.. TO,.. LOOSE MY ( – EYES – background layer), mind oh-ver tha fact that she–ee–ee is my best,.. my-my-my very best frie-end,… always like ALWAYS WHO IS THE ONE WHO IS ALWAYS FUN TO BE A-ROUND,… AND WHEN-EV-ER IT SOUNDS LIKE MY,…… JASS IS SINGING,….. THE BLUES,…… JUST WAKES UP MY ATTI-T.U.D.E…….. MAKES ME WO,.. – WANT TO HOLD ON ! AND I GOT TO-OO-OO,… CHOOSE,.. TO,……. BE-EE-EE,… STRONG,… KNOW-ING,.. THAT,… LIFE,.. GOES,…. ON,… I COULD NEVER DO ANYTHING,… CONTIOSLY,… WRONG,… TO,… MY,… OWN,…… HOME,…. AND I BELEIVE,…. WE,…. AND I DO HAVE EQUIPTMENT TO FINISH THE SONG ON NOW,… AND NOBODY GAVE ME A PENNY OR EVER MADE A LOAN TO MY CAUSE 08 / 20 / 2004 ! I DIDNT ALLOW ANY CRIME NOWHERE IN MY PATH, AND STRUGLED, AND EVEN WENT WITHOUT AND I AM MAKING CD’S FOR EVERYBODIES CD PLAYERS,…. WITHOUT ANYTHING BUT ONE MIND MADE UP,…. AND I HAVE TO KEEP JASS (JANET) IN MY LIFE BEING THE RAPPER THAT I AM I LIKE HER R&B SONGS AND SHE IS JUST SIMPLY A HONEY BUNCH OF MIRACLES AND I HAVE TO RESPECT HER, AND I DONT FEEL THERE IS NO WAY I CANNOT HONOR THAT AS LONG AS I AM ALIVE AND SHE IS ALIVE THIS IS REGINALD STENNIS FETTY
August 22nd, 2004 at 1:20 pm
“…or someone at HP decides to install some other programs in conjunction to monitor each individual for whatever reason…”
That’s as dangerous as installing Microsoft’s patch don’t you think???
August 23rd, 2004 at 2:13 pm
whew…bet you’re glad you got that all out of your system…now put down the crack pipe and back away slowly please