Skip to main content
  1. Home
  2. Computing
  3. News

The source code for a potent DDoS tool has now been made public

Add as a preferred source on Google

In September, cybersecurity journalist Brian Krebs was targeted by a massive DDoS attack that took his website offline. Now, Krebs is reporting that the source code that powered the attack has been publicly distributed on the internet.

Mirai is a piece of malware that preys on Internet of Things devices, specifically those that are being protected by factory default settings, or hard-coded authentication credentials. It continually scans for targets, seeding those that are vulnerable and turning them into bots that can be used to facilitate a DDoS attack.

Recommended Videos

The Mirai source code was released via a malware message board known as Hackforums, according to a report from Krebs on Security. The user responsible for the post states a desire to move on from staging attacks on IoT hardware, but Krebs believes that the real motivation behind this release is less altruistic.

The high-profile nature of the attack on Krebs’ site has likely prompted a new wave of investigations into Mirai and its authors. Krebs argues that the culprit is likely to be circulating the source code to make it more difficult for law enforcement to trace this particular strain of malware back to its origin.

The good news is that IoT devices infected by Mirai can be recovered via a simple reboot — the bad news is that scanning for new targets is thought to be so prevalent, that the hardware could be infected once again in a matter of minutes. As such, the advice is to change the default password, putting the device outside of Mirai’s reach.

Referencing a Gartner forecast that predicts that 6.4 billion IoT devices will be in use worldwide this year, Krebs warns of a “dawning IoT nightmare” if security standards aren’t tightened. Given the amount of hardware out in the wild, and the fact that Mirai is now freely available, it’s easy to see where his concerns are coming from.

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
The old internet built a museum for dying tech sounds, and it’s somehow still alive
The wonderfully dated site has outlasted many of the noisy gadgets it was created to preserve
Camera, Electronics, Art

Before our gadgets became silent glass rectangles, they complained constantly. Dial-up modems screeched through every connection, while dot-matrix printers sounded like they were slowly chewing through the desk.

The Museum of Endangered Sounds keeps that irritating soundtrack alive. It first appeared in 2012, but the site is still online 14 years later, inviting visitors to hear technology that has mostly disappeared from everyday life.

Read more
This Mac app can turn every window into a CRT fever dream or a nostalgic Game Boy
Apple doesn't let offer wacky customization on Macs, but Glaze has got you covered.
Glaze 1.9

If you're tired of only being able to customize your wallpaper, accent colors, and other basic aspects of your MacBook, an indie called Glaze could be something you might want to try out. The latest release, Glaze 1.9, can transform your Mac's entire live display using more than 50 GPU-powered visual effects. Those include convincing recreations of CRT monitors, Game Boy screens, worn VHS tapes, comic books, oil paintings, old film, vintage paper, and even Sony's Trinitron displays.

Your Mac can finally cosplay as a CRT

Read more
Microsoft wants to stop screenshot leaks, one Edge tab at a time
Sensitive PDFs are getting screenshot protection, exclusively in Microsoft Edge
Microsoft Edge on a phone

Microsoft is looking to improve the privacy protection of your sensitive PDFs by closing one of the more obvious loopholes in its document protection system. It is also giving businesses another reason to keep Microsoft Edge firmly installed.

Starting next month, OneDrive and SharePoint will block screen captures when users open certain sensitivity-labeled PDFs through their web viewers in Microsoft Edge. The restriction applies to enterprise organizations using Microsoft Purview Information Protection rather than ordinary personal OneDrive accounts.

Read more