To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
----------
sandalwood wrote:
> To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
> ----------
> Hello botnets,
> 
>   first post? nice.
> 
>   well my question is, what do these kids all have down syndrome??
>   why are they so stupid as to use the ancient "recommended" port 6667
>   for c&c, when they should know that probably HALF of all major isps
>   automatically block outbound traffic to that port?
> 
>   obvious alternate ports would be common services 80, 21, 53..

First off, who says they don't use alternate ports OR services as C&C 
channels?

Second, getting any ISP to block any port is very problematic, and for 
many good reasons.

It is obvious that by only hunting botnets the only thing we accomplish 
is to educate the Bad Guys and push them into continuing evolution, 
however, informing the responsible party and taking the C&C's off-line 
makes their lives more difficult at this point.

As that is already done and this information is valuable to the public, 
not to mention can take the whack-a-mole part of the war to the next 
level, we decided to open this mailing list as a proof of concept and 
measure how it may help the fight.

        Gadi.

-- 
http://blogs.securiteam.com/

"Out of the box is where I live".
        -- Cara "Starbuck" Thrace, Battlestar Galactica.
_______________________________________________
botnets mailing list
To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
http://www.whitestar.linuxbox.org/mailman/listinfo/botnets

Reply via email to