427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet86/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   82   83   84   85   86   87   88   89   ...   387
Bog'liq
Botnets - The killer web applications

N
OTE
The bots covered in this chapter are the most common, but this list is
by no means comprehensive. Because they are common, they also
have many variants. Some have hundreds of variations. Understand
that the information covered in this chapter is generic to some degree
and that you might have to do research to find details of the specific
variant that has compromised your system.
SDBot
The SDBot family of bots has been around for almost five years and has
grown to include hundreds of variants and offshoots. One of the elements
www.syngress.com
98
Chapter 4 • Common Botnets
427_Bot_ch04.qxt 1/9/07 3:03 PM Page 98


that has added to the longevity of the SDBot family is that the original devel-
oper essentially made it into an open-source malware program.The original
SDBot author released the source code for the bot and included his contact
information, providing a means of public collaboration and evolution to con-
tinue developing and improving the code.
The other key to the success of SDBot is poor security on the compro-
mised systems. SDBot relies on spreading itself primarily via network shares
using blank or common passwords. Systems with solid security and more
complex passwords will not be compromised by SDBot.
With so many variants, a comprehensive description of each would
require a book of its own.The following are the general details of how
SDBot works and propagates and how you can recognize common signs that
could indicate that your computer has been compromised by SDBot.
Aliases
Antivirus and security vendors rarely agree on naming conventions, so the
same threat can have multiple names, depending on which vendor is sup-
plying the information. Here are some aliases for SDBot from the top
antivirus vendors:

McAfee: IRC-SDBot

Symantec: Backdoor.Sdbot

Trend Micro: BKDR_SDBOT

Sophos:Troj/Sdbot

Kaspersky: Backdoor.IRC.Sdbot

CA: Win32.SDBot
Infection
The method of infection varies from one variant to the next, but SDBot tra-
ditionally takes advantage of insecure network shares or uses known vulnera-
bility exploits to compromise systems. Once SDBot is able to connect to a
vulnerable system, it will execute a script that will download and execute
SDBot to infect the system.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   82   83   84   85   86   87   88   89   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish