427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet270/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   266   267   268   269   270   271   272   273   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
330
Chapter 9 • Advanced Ourmon Techniques
Continued
427_Botnet_09.qxd 1/8/07 4:45 PM Page 330


way. For example, the botnet software might be spyware, recording
keystrokes and sending them out on some channel you don’t know
about. Or the host might sit there today and join a DDoS attack
tomorrow. 
The 
ngrep
tool is a nice custom sniffer that can be used to pick ASCII
strings out of packet data payloads. It can be used for watching for messages
from a known C&C botnet IP address. It can also be used with pattern
matching since it has 
grep
regular expressions (really, Perl Compatible Regular
Expressions, or PCRE; see www.pcre.org) built into it. It can also read and
write tcpdump format files. Here we will just give a few syntax examples,
explain them, and then look at one example of 
ngrep
in combat.
The overall syntax for 
ngrep
has the form:
# ngrep –flags "pattern" tcpdump-expression
Here are three examples. First:
ngrep –q host 10.0.0.1
We use 
–q
to make 
ngrep
quiet, so it only prints out strings.The 
host
10.0.0.1
part is a tcpdump expression to tell it to print strings for any packets
to and from that particular host.This expression format is the same for other
sniffers, too, including tcpdump and WireShark (and Snort and ourmon, for
that matter). Our goal is to watch traffic to and from the suspicious host in
question.This might be IRC traffic or HTTP traffic or something else
entirely.
Second:
ngrep –q "PRIVMSG|JOIN" host 10.0.0.1 or host 10.0.0.2
In this case we want any packet with 
PRIVMSG
or 
JOIN
in it from two
possible hosts.These both might be botnet servers. We are trying to use pat-
tern matching to look at interesting IRC messages, and this pattern would
rule out any PING or PONG messages or other types of IRC messages.
Third:
# script
serverip.log
# ngrep –q host 10.0.0.1
# Cntrl-D

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   266   267   268   269   270   271   272   273   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish