427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet231/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   227   228   229   230   231   232   233   234   ...   387
Bog'liq
Botnets - The killer web applications

T
IP
See http://en.wikipedia.org/wiki/Internet_Relay_Chat for a good dis-
cussion of both IRC and its history, although it doesn’t say much about
IRC’s dark side.
Our goal here is to not explain all the IRC protocol. Ourmon only cares
about a very small restricted set of IRC, and as a result that IRC subset is all
we intend to explain here. Also please note that we are talking about the low-
level IETF IRC protocol; we are not talking about IRC commands used in
any particular IRC client program.The four kinds of IRC protocol messages
ourmon understands are as follows:

JOINS
JOINS are used by an IRC client to log into a channel on a
server.The channel name and password are part of the JOIN message.

PINGS
PINGS are sent from a server to a client to discover if the
client is still interested in the channel and has not for example
crashed or gone away otherwise.Typically PINGS are sent in a peri-
odic fashion at some multiple of 30 seconds.

PONGS
See PINGS above. PONGS are returned from the client to
the server to show that it does not want to be logged out and still
exists.

PRIVMSG
A PRIVMSG contains both the channel name and data
sent to the channel name.The basic idea here is that the message (“hi
mom” or “scan using port 445”) should be sent to all the hosts in the
logical IRC channel.
JOINS and PRIVMSG messages contain the channel names, and ourmon
uses those messages along with the IP addresses in the IP header to construct
a list of channels with associated IP hosts (as IP addresses). Ourmon does not
look at the data part of the PRIVMSG. because our goal is only to construct
a network mesh, not look at user data. It also keeps track of PING and
PONG messages because they indicate basic IRC mesh connectivity. It is
possible for a client to send a JOIN message and not do PINGs and PONGS.
So in some cases a client could simply send a JOIN over and over again. In

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   227   228   229   230   231   232   233   234   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish