427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet243/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   239   240   241   242   243   244   245   246   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
300
Chapter 8 • IRC and Botnets
427_Botnet_08.qxd 1/8/07 4:10 PM Page 300


Table 8.5
Channel Hobo Hosts
Ip_src
Tmsgs Tprivmsgs
Maxworm Server?
Sport/dport
192.168.6.66
199
22
95
H
4929/504
192.168.7.77
159
0
40
H
1028/219557
10.38.4.27
756
7
50
S
25394/2777
When we go and look at our TCP port report summarization, we dis-
cover that 192.168.6.66 has indeed been scanning on ports 139 and port 445.
Those are classic ports for Microsoft-based exploits. If we aren’t convinced,
we might resort to other measures. For example, if your acceptable-use policy
lets you peek at data payloads, you might now use ngrep to look at host
192.168.6.66 or host 10.38.4.27 (because PRIVMSGS exist and at least one
host appears to be in contact with the server). A command like this could
reveal something interesting:
# ngrep host 192.168.6.66 or host 10.38.4.27
T
IP
If you are suspicious, watch traffic associated with the server’s IP
address. As a result you might see traffic with other infected hosts
that you did not yet suspect. If you find a suspicious server IP in the
IRC report, search all the way through that report. Note all the
channel names where the server’s IP address appears. As a result we
could learn that channels 
hobo 
and .
i-exp
have the same server.
As a result of watching the server, you might see an IRC payload like this:
PRIVMSG #.i-exp :[S]CAN WKSSVCE445: Exploiting IP: 192.1.2.4
Oops! You just caught the bad guys in the act. Apparently results for about
445 port scans are being reported, and a new IP on your net might have just
been infected.
Using honeypot technologies, we eventually determined that this partic-
ular bot is known as 
toxbot
. Symantec calls this one 
W32.Toxbot.AL
. See
Symantec’s web page for more information on this bug

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   239   240   241   242   243   244   245   246   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish