Re: [botnets] mocbot spam analysis

2006-08-17 Thread J. Oquendo
up. =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ J. Oquendo http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0x1383A743 sil infiltrated . net http://www.infiltrated.net How a man plays the game shows something of his character - how he loses shows all - Mr. Luckey

[botnets] Increased SSH activity

2007-01-29 Thread J. Oquendo
(servidor.energiasanjuan.com.ar) 65.111.170.42 (42-170-111-65.serverpronto.com) 220.130.193.125 (220-130-193-125.HINET-IP.hinet.net) 200.31.6.148 (sc-core2.impsat.net.ec) -- J. Oquendo http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0x1383A743 sil

Re: [botnets] Tor CC? (Was: Re: Alternative Botnet CCs - free chapter from Botnets:The Killer Web App)

2007-07-26 Thread J. Oquendo
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- Marco Gruss wrote: To report a botnet PRIVATELY please email: [EMAIL PROTECTED] -- While we're on the subject of alternative CCs, a thought just crossed my mind: Suppose a bot herder started packaging Tor with his

[botnets] Why ISP's and NSP's Love Botnets

2007-09-21 Thread J. Oquendo
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --http://www.infiltrated.net/?p=29 Biased... In all honesty I don't believe so -- J. Oquendo Excusatio non petita, accusatio manifesta http://pgp.mit.edu:11371/pks/lookup

Re: [botnets] Why ISP's and NSP's Love Botnets

2007-09-21 Thread J. Oquendo
:27 PM, J. Oquendo wrote: The ATLAS Initiative wrote: Dear Jesus, Thank you for expressing interest in ATLAS. Today, only select ATLAS partners and customers can access the private portal. Tomorrow, however, Arbor will be making available a web services-based ATLAS subscription service that can

Re: [botnets] Why ISP's and NSP's Love Botnets

2007-09-21 Thread J. Oquendo
on the schooling I'm getting. J. Oquendo Excusatio non petita, accusatio manifesta http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xF684C42E sil . infiltrated @ net http://www.infiltrated.net smime.p7s Description: S/MIME Cryptographic Signature

Re: [botnets] Botmasters Take Heed – You Are Being Put On Notice

2007-10-02 Thread J. Oquendo
. pty Its called Joe Job(bing) -- J. Oquendo Excusatio non petita, accusatio manifesta http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xF684C42E sil . infiltrated @ net http://www.infiltrated.net smime.p7s Description: S/MIME Cryptographic

Re: [botnets] blog spammer

2007-10-03 Thread J. Oquendo
-- J. Oquendo Excusatio non petita, accusatio manifesta http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xF684C42E sil . infiltrated @ net http://www.infiltrated.net smime.p7s Description: S/MIME Cryptographic Signature

Re: [botnets] corrected Google information

2007-10-03 Thread J. Oquendo
] # ARIN WHOIS database, last updated 2007-10-02 19:10 # Enter ? for additional hints on searching ARIN's WHOIS database. -- J. Oquendo Excusatio non petita, accusatio manifesta http://pgp.mit.edu:11371/pks/lookup?op=getsearch=0xF684C42E sil

Re: [botnets] mech config captured today

2007-11-16 Thread J. Oquendo
of these compromised businesses need to start giving idiot admins the boot. Sorry if its off-topic, harsh, etc., but man experience, training, common sense sure go a long way. J. Oquendo SGFA (FW+VPN v4.1) SGFE (FW+VPN v4.1) I hear much of people's calling out

[botnets] LEO on list

2007-11-20 Thread J. Oquendo
To report a botnet PRIVATELY please email: [EMAIL PROTECTED] --Any LEO within NY/NJ/CT please shoot me an email offlist or someone onlist with a trustworthy contact please get in touch. TIA J. Oquendo SGFA #579 (FW+VPN v4.1) SGFE #574

[botnets] Botnets using super hi tech encryption

2007-12-10 Thread J. Oquendo
edge. By the way this message has been encrypted with rot13 twice. Contact me for the key. -- J. Oquendo SGFA #579 (FW+VPN v4.1) SGFE #574 (FW+VPN v4.1) I hear much of people's calling out to punish the guilty, but very few are concerned

[botnets] SQL Injection bot?

2008-08-27 Thread J. Oquendo
-0500 From: J. Oquendo [EMAIL PROTECTED] To: botnets@whitestar.linuxbox.org Subject: New SQL Bot? Message-ID: [EMAIL PROTECTED] Content-Type: text/plain; charset=us-ascii Starting yesterday I began seeing a few attempts at an XSS attack. Posting perhaps someone else knows something about it, or has