427 Botnet fm qxd


Cloning A clone is any connection to an IRC server over and above the first connection. www.syngress.com



Download 6,98 Mb.
Pdf ko'rish
bet23/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   19   20   21   22   23   24   25   26   ...   387
Bog'liq
Botnets - The killer web applications

Cloning
A clone is any connection to an IRC server over and
above the first connection.
www.syngress.com
8
Chapter 1 • Botnets: A Call to Action
427_Bot_01.qxd 1/8/07 11:53 AM Page 8



BNC (Bounce)
A method for anonymizing Bot client access to a
server.
Today, all variations of bot technology that are based on mIRC are said to
be members of the GT Bot family.These bot clients did not include a mecha-
nism for spreading itself directly. Instead, they would use variations on social
engineering ploys. A common ploy used to infect systems was an e-mail that
claimed to be from a security vendor. If the user clicked on the embedded
link they were taken to a Web site that delivered the client to the victim.
These early botnet clients were not modular, but rather were all contained in
a single package.
SDBot
Early in 2002, SDBot appeared. It was written by a Russian programmer
known as sd. SDBot is a major step up the evolutionary chain for bots. It was
written in C++. More important to the evolution of botnet technology, the
author released the source code, published a Web page, and provided e-mail
and ICQ contact information.This made it accessible to many hackers. It was
also easy to modify and maintain. As a result, many subsequent bot clients
include code or concepts from SDBot. SDBot produced a small single binary
file that contained only 40KB of code.
A major characteristic of the SDBot family is the inclusion and use of
remote control backdoors.
SDBot family worms spread by a variety of methods, including:

NetBios (port 139)

NTPass (port 445)

DCom (ports 135, 1025)

DCom2 (port 135)

MS RPC service and Windows Messenger port (TCP 1025)

ASN.1 vulnerability, affects Kerberos (UDP 88), LSASS.exe, and
Crypt32.dll (TCP ports 135, 139, 445), and IIS Server using SSL

UPNP (port 5000)

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   19   20   21   22   23   24   25   26   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish