427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet94/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   90   91   92   93   94   95   96   97   ...   387
Bog'liq
Botnets - The killer web applications

Table 4.5 continued 
Weak Passwords Commonly Found in RBot Variants 
123
control
john
qwerty
1234
data
kate
root
12345
database
katie
sa
123456
databasepass
lan
sam
1234567
databasepassword
lee
server
12345678
db1
linux
sex
123456789
db1234
login
siemens
1234567890
db2
loginpass
slut
2000
dbpass
luke
sql
2001
dbpassword
mail
sqlpass
2002
default
main
staff
2003
dell
mary
student
2004
demo
mike
sue
access
domain
neil
susan
accounting
domainpass
nokia
system
accounts
domainpassword
none
teacher
adm
eric
null
technical
admin
exchange
oainstall
test
administrador
fred
oem
unix
administrat
fuck
oeminstall
user
administrateur
george
oemuser
web
administrator
god
office
win2000
admins
guest
oracle
win2k
asd
hell
orainstall
win98
backup
hello
outlook
windows
bill
home
pass
winnt
bitch
homeuser
pass1234
winpass
blank
hp
passwd
winxp
bob
ian
password
www
bob
ibm
password1
xp
brian
internet
peter
zxc
changeme
internet
peter
Source: CA (www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39437)
www.syngress.com
Common Botnets • Chapter 4
109
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 109


If it authenticates successfully with the target machine, RBot then
attempts to copy itself to the following locations and schedules a remote job
to execute the RBot software and infect the target machine:

\Admin$\system32

\c$\winnt\system32

\c$\windows\system32

\c

\d
Using Known Vulnerability Exploits
Another method RBot uses to propagate itself is to use exploits of known
vulnerabilities. RBot variants may attempt to exploit one or more of the vul-
nerabilities listed in Table 4.6. If a vulnerable target is found, RBot executes a
small program instructing the target machine to connect to a remote server to
download the complete RBot code.The connections back to the RBot
source may use alternate port assignments but are typically made via HTTP
(port 81) or TFTP (port 69).
Table 4.6 
Known Vulnerabilities Commonly Exploited by RBot Variants 
Microsoft Windows LSASS buffer overflow vulnerability (TCP port 445)
Microsoft Windows ntdll.dll buffer overflow vulnerability (Webdav vulner-
ability) (TCP port 80)
Microsoft Windows RPC malformed message buffer overflow vulnerability
(TCP ports 135, 445, 1025)
Microsoft Windows RPCSS malformed DCOM message buffer overflow vul-
nerabilities (TCP port 135)
Exploiting weak passwords on MS SQL servers, including Microsoft SQL
Server Desktop Engine blank sa password vulnerability (TCP port 1433)
Microsoft Universal Plug and Play (UPnP) NOTIFY directive buffer overflow
and DoS vulnerabilities (TCP port 5000)
DameWare Mini Remote Control buffer overflow (TCP port 6129)
Microsoft Windows Workstation service malformed message buffer over-
flow vulnerability (TCP port 445)

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   90   91   92   93   94   95   96   97   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish