427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet157/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   153   154   155   156   157   158   159   160   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
184
Chapter 5 • Botnet Detection: Tools and Techniques
427_Botnet_05.qxd 1/9/07 9:59 AM Page 184


about the login types listed in the event log at
http://technet2.microsoft.com/WindowsServer/en/library/e104c96f-e243-
41c5-aaea-d046555a079d1033.msp, or search Microsoft for 
audit logon events.
In addition, we looked for instances of logon type 3 in which the origi-
nating workstation name differed from the victim’s computer and where the
domain name is the name of the attacking computer. In most environments,
this should be a rare occurrence.The victim’s computer would have to be
actively sharing files and adding local accounts from the other computer as
users on the victim’s computer.
Figure 5.4
Failed Login Record
To clinch the deal, password-guessing attacks occur much more rapidly
than any human can type.This won’t be the case every time.The password-
guessing tools we have captured can throttle down the attack frequency (
x
attacks over 
y
hours), so it might not be so obvious (see Figure 5.5).
www.syngress.com
Botnet Detection: Tools and Techniques • Chapter 5
185
427_Botnet_05.qxd 1/9/07 9:59 AM Page 185


Figure 5.5
A Password-Guessing Attack
Both Phatbot and Rbot provide other clues that a password-guessing
attack is real. Earlier in the book we listed the default userids they both can
use.You might not see this in every attack, but if the bot hasn’t gathered any
userids locally yet, or if the gathered userids haven’t gotten in, the bot might
try userids from the default list.They almost always try Administrator, so if
you have renamed this account, its appearance in a failed login attempt raises
the probability that this is an attack. If you see attempts using userids of
Administrador, then administrateur as the login ID, you can be sure that this is
password-guessing attack and that a bot (likely Phatbot, Rbot, or another
related bot family) is attacking the victim’s computer. If the attempts happen
to take place during times that no one is supposed to be working in that
department, you can be even more certain.
So, what’s the point of analyzing this data? You are examining this com-
puter because someone already said it was virus infected or because one of
your intelligence sources spotted it talking to a known C&C server. Here’s
the value of this analysis:The computers listed in the workstation field of the
failed login records type 3 login, where the workstation field differs from the
victim’s computer name, are all infected computers. Using this technique
during the analysis phase, we have found over 200 infected computers that
were part of one botnet.This is despite the fact that we actively scan for bot

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   153   154   155   156   157   158   159   160   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish