Observing Botnets with Honeynets
Susan Saradon writes "The Honeynet Project has released a new paper which deals with the observation of botnets. "Know Your Enemy: Tracking Botnets" discusses what Botnets are, who is using them, how, and why. It als introduces the tools "mwcollect" and "drone" which can be used for collecting an tracking Botnet activity. Nice to read and looking forward to the release of these tools."
logging into the IRC channels of botnets, and trying to introduce myself, and asking "a/s/l" and getting all huffy that nobody's answering. Or talking like a robot.
-Jesse
Nothing says "unprofessional job" like wrinkles in your duct tape.
I'd love to use bot nets to spot, stop or even patch new/unknown machines on my network.
Conformity is the jailer of freedom and enemy of growth. -JFK
In one case, bot software detected whether the game "Diablo II" was installed on the host PC. If the game was present, the program would steal items from the player's characters and drop them at preplanned places in the online game world. The bot net's controller would then collect the items and sell them on auction site eBay, Holz said.
What the... ? Stealing identities and installing viruses is one thing; but to actually go and steal stuff from Diablo-II?? Have these guys no shame???
I'm an op in a large channel on the Undernet and spam is definately a growing problem. I see lots of spambots join/part our channel and an unusually high percentage of them come from Romania.
You would think that the Undernet admins could simply force users to login to X, thus dramatically reducing the problem. However they are not willing to do that. As a sysadmin myself, never in a million years would I turn a blind eye one of my services being used completely inapporpriately and I would take the steps necessary to prevent it.
J.
You're only jealous cos the little penguins are talking to me.
There's no explanation for such a botnet other than a professional full-time organization specifically created for profit.
That... or the network has attained self-awareness and is trying to recruit all our PCs to conquer the world!
THROW YOUR PC OUT OF THE WINDOW. IT'S THE ONLY WAY TO BE SURE.
When the bots become self aware, then it is time to worry.
-- my sig got