427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet87/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   83   84   85   86   87   88   89   90   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
Common Botnets • Chapter 4
99
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 99


SDBot typically includes some sort of backdoor that allows an attacker to
gain complete access to compromised systems.The Remote Access Trojan
(RAT) component of SDBot connects to an IRC server and lies silently
waiting for instructions from a botherder.
Using the RAT, a botherder can collect information about the compro-
mised system, such as the operating system version, computer name, IP
address, or the currently logged-in username. A botherder can also run IRC
commands directing the compromised computer to join an IRC channel,
download and execute files, or connect to a specific server or Web site to ini-
tiate a distributed denial-of-service (DDoS) attack.
Signs of Compromise
If you believe that your computer might be infected with SDBot, there are a
few clues you can look for to verify your suspicions.
System Folder
Upon execution, SDBot will place a copy of itself in the System folder.
Typically, this folder is C:\Windows\System32, but SDBot uses the
%System% variable to find out where it is and then places a copy of itself in
that folder.The filename used can vary, but Table 4.1 contains a list of known
filenames.
Table 4.1
Known Filenames Used by Backdoor
*
Aim95.exe
service.exe
CMagesta.exe
sock32.exe
Cmd32.exe
spooler.exe
Cnfgldr.exe
Svchosts.exe
cthelp.exe
svhost.exe
Explorer.exe
Sys32.exe
FB_PNU.EXE
Sys3f2.exe
IEXPL0RE.EXE
Syscfg32.exe
iexplore.exe
Sysmon16.exe
ipcl32.exe
syswin32.exe
www.syngress.com
100
Chapter 4 • Common Botnets
Continued
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 100



Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   83   84   85   86   87   88   89   90   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish