Re: [botnets] re MAC trojan

2007-11-01 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Not sure this is necessariyl true, but that's beside the point as I'm sure we could have hundreds of witty replies all day long going both ways. The point is this requires user interaction to infect a machine. I am not

Re: [botnets] mac trojan in-the-wild

2007-11-04 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Sat, 3 Nov 2007 13:54:44 -0400, Mr. X [EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Dude, you gotta get over yourself. The fact that the mac os x operating system

Re: [botnets] mech config captured today

2007-11-16 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Just taking a wild stab in the dark, I'd bet on SSH brute force. A number of groups on Undernet (Romanian ones especially) are known to SSH brute force attack boxes and then install mech and put up a bunch of clones in an

Re: [botnets] New Storm variant

2008-01-07 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Adriel, The quick goal would be to get them (nic.ru) to suspend the 15 domains that are currently active: * familypostcards2008.com * freshcards2008.com * happy2008toyou.com * happycards2008.com *

Re: [botnets] New Storm variant

2008-01-07 Thread Steven Adair
[EMAIL PROTECTED] wrote: I add two domains to the list: ptowl.com yxbegan.com Best regards, Chato Flores On Mon, 07 Jan 2008 23:13:57 +0100 Steven Adair [EMAIL PROTECTED] wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Adriel, The quick goal

Re: [botnets] (broadband routers) PC World: Flash Attack Could TakeOver Your Router

2008-01-16 Thread Steven Adair
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- How are you defining network operators? Do you mean by the normal [in most cases home] user? Apparently flash is able to allow UPnP access per PDP's posting at www.gnucitizen.org. Apparently this is not a flaw and is a

Re: [botnets] reviving this list, allowing sharing

2008-08-27 Thread Steven Adair
I agree here. It'd be a bit much and cause people to unsubscribe if there's not some digest type format. The malware would still have to be sandboxed in some fashion to be overly relevant. Just having information from nepenthes will give you limited information. Also, unless there's a way to

Re: [botnets] [phishing] XP update phish/malware

2008-08-28 Thread Steven Adair
It seems Imageshack with malicious or at least abusive Flash files is getting more popular. We saw a similar attack, yet far less malicious, on Facebook last week. User's walls were spammed with a messae about someone having a crush on them with a link to an Imageshack flash file. The file

Re: [botnets] URL formats

2008-08-28 Thread Steven Adair
heh I think this is a discussion that's been had many times. A lot of people use and I am in favor of obfuscating http links with: hxxp://urlformat then for any URLs that have sensitive info that you want to still post use removed, example: