Re: [botnets] new one

2006-04-05 Thread PinkFreud
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Upstream is Level3. Not that I'm holding my breath, but perhaps it's time to start notifying them of Iqarus' abuses? On Fri, Mar 31, 2006 at 09:10:04AM +0200, Raymond Dijkxhoorn babbled thus: > Hi! > > > Here's another one

[botnets] C&C Communication

2006-04-05 Thread Mary Henthorn
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- I'm a senior technology analyst and a graduate computer science student. I'm particularly interested in finding ways to discover botnets that are using anything other than IRC as a C&C protocol by observing the enterprise net

[botnets] possible botnet? channel #asn2 at dynamic1084.amdwebhost.com:6667

2006-04-05 Thread Jamie Riden
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- I'm not an IRC guy, but I imagine this is not a good thing? cheers, Jamie nepenthes-721e2a9c2fa4efd12f80672a87fb977b-asn2.exe : [SANDBOX] contains a security risk - W32/Spybot.gen3 (Signature: W32/Spybot.AHRJ) [ General inf

Re: [botnets] botnets Digest, Vol 2, Issue 1

2006-04-05 Thread Deborah Gage
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- >From: [EMAIL PROTECTED] >Reply-To: botnets@whitestar.linuxbox.org >To: botnets@whitestar.linuxbox.org >Subject: botnets Digest, Vol 2, Issue 1 >Date: Sun, 02 Apr 2006 04:24:38 -0500 > >Send botnets mailing list submissions

[botnets] Botnets book

2006-04-05 Thread Richard (Rick) Wanner
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Jess Kitchen reference a botnets book in the email below, the details were a little off. It is actually... Internet Denial of Service: Attack and Defense Mechanisms By Jelena Mirkovic, Sven Dietrich, David Dittrich, Peter Rei

[botnets] Botnets

2006-04-05 Thread Jeremy Linden
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --Server: irc.rizon.net Channel: #warezfr (warez bot network) Server: irc.webchat.org Channels: #jabalalnaser, #amlhmshesreere, # Server: a.k.reipmav.net Channels: #barb1can Server: l0n3ly.reipmav.net Channels: #t3rr0r, #ti

Re: [botnets] C&C Communication

2006-04-05 Thread Georg Wicherski
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Hi Mary, one of the key protocols to observe here is DNS, I would say. All C&C protocols except for P2P protocols usually rely on DNS to resolve the address of the C&C server(s). Additionally, you should observe anomalities i

Re: [botnets] Botnets book

2006-04-05 Thread Scott Brenner
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Another great book is Defense and Detection Strategies against Internet Worms by Jose Nazario of Arbor Networks. Artech House, Hardcover, Published November 2003, ISBN 1580535372

Re: [botnets] C&C Communication

2006-04-05 Thread Daniel Elessedil Kjeserud
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On 03.04.2006 04:25 wrote Mary Henthorn: > -- > I'm a senior technology analyst and a graduate computer science student. I'm > particularly interested in finding ways to discover botnets that are using > anything othe

[botnets] another irc client

2006-04-05 Thread brack
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- I just don;t have time to look at it right now, so here is the link to another botnet irc client: http://210.3.4.193/cmd.txt <<-- defacer 70.168.74.193/strange <<-- downloader 207.90.211.54/arts <<-- actual client http://7

Re: [botnets] C&C Communication

2006-04-05 Thread Paul Cordes
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- I suppose one possibility, assuming that your sysadmin doesn't mind it, would be random port scans of the network. I've found tons of remote-control trojans on our network that way. It wouldn't catch everything, but it cou

Re: [botnets] C&C Communication

2006-04-05 Thread Jose Nazario
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Wed, 5 Apr 2006, Georg Wicherski wrote: > one of the key protocols to observe here is DNS, I would say. All C&C > protocols except for P2P protocols usually rely on DNS to resolve the > address of the C&C server(s). so, in

Re: [botnets] C&C Communication

2006-04-05 Thread Gadi Evron
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Jose Nazario wrote: > To report a botnet PRIVATELY please email: [EMAIL PROTECTED] > -- > On Wed, 5 Apr 2006, Georg Wicherski wrote: > > >>one of the key protocols to observe here is DNS, I would say. All C&C >>protoc

Re: [botnets] another irc client

2006-04-05 Thread PinkFreud
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- On Wed, Apr 05, 2006 at 06:55:33AM -0500, [EMAIL PROTECTED] babbled thus: > I just don;t have time to look at it right now, so here is the link to > another botnet irc client: > > http://210.3.4.193/cmd.txt <<-- defacer Ind

[botnets] Web-Based Bots

2006-04-05 Thread Ken Dunham
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Hi, I'm going to do a little research on web-based bots to date. Does anyone have any examples of web-based bots, where they are controlled, where stats are provide, etc, to an HTTP solution rather than an IRC solution? Thank