Feeds

FBI refuses to open source for Linux DDOS detector

But wants to make it widely available...

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

The FBI has released updated Distributed Denial of Service detection tools for Linux and Solaris, and is urging people to use them - but the Feds are declining to make the source available. This is obviously a bit of a no-no for the open source audience you'd expect for Linux tools, and the stance looks even odder when you learn that the FBI's developer, Dave Dittrich of the University of Washington, has released his own software, with source. The FBI is making the tools, designed to detect TRINOO and Tribal Flood Network (TFN) attacks, available via the National Infrastructure Protection Center (NIPC). It does however seem to be refusing to release source as a matter of policy. Contacted by a Register reader the NIPC responded (corporately, apparently, as no spokesperson name was attached): "The NIPC has determined that it is important not to release the source code publicly. We do, however, have measures in place to help ensure that the executable on our website is not compromised. Thank you for contacting us." Our informant had pointed out that: "Many internet sites will *not* install binaries provided by the US government, and specifically the FBI, lacking source. I would strongly recommend that you provide source for these tools, preferably under an OSI compliant license (GPL, BSD, MozPL, etc.), at the very least simply publishing source whether or not you allow modifications of it, though copyright in government works is not, AFAIK, applicable in this case." This seems to be a mindset too far for the NIPC. But never mind, although the FBI version isn't likely to be that popular, Dittrich's version comes with source. We're told that the FBI version runs on the target systems and searches files for traces of the DDOS tools, whereas version with source attempts to remotely identify the DDOS tools by eliciting certain responses to network probes. According to our informant (thanks, reader): "This method is much less reliable as it typically relies on the tools having the original passwords. However, running programs on the target systems is much harder to automate." So there you go. Pays your money (not exactly), takes your choice. ® Your DDOS downloads tonight: FBI version Dittrich implementation

Remote control for virtualized desktops

More from The Register

next story
Facebook pays INFINITELY MORE UK corp tax than in 2012
Thanks for the £3k, Zuck. Doh! you're IN CREDIT. Guess not
Big Content outs piracy hotbeds: São Paulo, Beijing ... TORONTO?
MPAA calls Canadians a bunch of bootlegging movie thieves
Google Glassholes are UNDATEABLE – HP exec
You need an emotional connection, says touchy-feely MD... We can do that
YARR! Pirates walk the plank: DMCA magnets sink in Google results
Spaffing copyrighted stuff over the web? No search ranking for you
UK.gov pushes for SWIFT ACTION against nuisance calls, threatens £500k fines
DCMS seeks lowering of legal threshold to fight rogue firms
Just don't blame Bono! Apple iTunes music sales PLUMMET
Cupertino revenue hit by cheapo downloads, says report
Hungary's internet tax cannot be allowed to set a precedent, says EC
More protests planned against giga-tariff for Tuesday evening
US court SHUTS DOWN 'scammers posing as Microsoft, Facebook support staff'
Netizens allegedly duped into paying for bogus tech advice
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
How to simplify SSL certificate management
Simple steps to take control of SSL certificates across the enterprise, and recommendations centralizing certificate management throughout their lifecycle.