427 Botnet fm qxd


Common Botnets • Chapter 4



Download 6,98 Mb.
Pdf ko'rish
bet93/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   89   90   91   92   93   94   95   96   ...   387
Bog'liq
Botnets - The killer web applications

Common Botnets • Chapter 4
107
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 107


Propagation
The primary means of propagation for the RBot family is through Windows
network shares. RBot scans on ports 139 and 445 looking for open connec-
tions. If a target is found, RBot then attempts to connect to the IPC$ admin-
istrative share on that system.
If RBot is successful at connecting with the target system, it will try to
obtain a list of the usernames on the target machine that it can use to gain
access. If RBot cannot get the list of usernames from the target system, some
variants will simply try a default list of usernames (like those listed in Table
4.4), which are preconfigured into the malware.
Table 4.4
Usernames That Some RBot Variants Will Attempt to Use to
Connect With Network Resources
administrator
student
administrador
teacher
administrateur
wwwadmin
administrat
guest
admins
default
admin
database
staff
dba
root
oracle
computer
db2
owner
Source: CA (www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39437)
For each username that RBot finds on the target system or the usernames it
is preconfigured with, RBot attempts to authenticate using a list of commonly
used weak passwords.The list of passwords varies from one version of RBot to
the next, but it commonly includes passwords like those found in Table 4.5.
Table 4.5 
Weak Passwords Commonly Found in RBot Variants
*
007
chris
intranet
pwd
1
cisco
jen
qaz
12
compaq
joe
qwe
www.syngress.com
108
Chapter 4 • Common Botnets
Continued
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 108



Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   89   90   91   92   93   94   95   96   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish