What a Botnet Looks Like
Esther Schindler writes "CSO has an annotated, zoomable map of real botnet topologies showing the interconnections between the compromised computers and the command-and-control systems that direct them. The map is based on work by security researcher David Voreland; it has interactive controls so you can zoom in and explore botnets' inner workings. Hackers use botnets for spamming, DDoS attacks and identity theft. One recent example is the Storm botnet, which may have comprised 1 million or more zombie systems at its peak. As with any networking challenge, there are good (resilient) designs and some not-so-good ones. In some cases the topology may be indicative of a particular botnet's purpose, or of a herder on the run."
To get a good look at a botnet they say, "You need to upgrade your Flash Player". How true!
No calls now, I'm
that's just beautiful
here's a photo of a botnet. Ok, it's a small botnet but if the botnet was a semi you wouldn't see the computers, now would you?
mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
all of the IP addresses. Can I get that in a text format? I want to add them to my hosts file.
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
because I don't work in this area, but I think a simpler explanation for the crazy hodge-podge of IP's on the map is dynamic IP's being given to a few infected PC's.
How can one say with confidence that the design is purposeful?
http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
http://www.artsci.washington.edu/news/Autumn05/largermap_sexualnetworks.htm
If they know which ips/subnets are most prolific with botnets just nullroute them all and tell the isps/owners to get their act straight if they want back on the net!
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
It would be nice to be able to search my static IP or a range of IPs to see if they are on the map.
There are lots of well constructed stars, where a handful of master nodes control several slaves. Each slave knows two or three masters for redundancy. That's good design, and I expected it.
But what's hilarious is that there are some ip addresses that are slaves to four or five different botnets. I wonder what the owners of those machines think?
"Man, the internet sure is slow today!"
"I need a new computer, this one's all slow."
"Sweet! Five botnets and counting! I'm part of something! I belong!"
Use the Firehose to mod down Second Life stories!
Who modded this "offtopic"? The site requires the latest and greatest flash player to look at a freaking image when everyone knows that Flash has big fat holes in it. They might as well made it IE only.
...would like to see more. Was there actually an article there, or was that just a picture? How about something about the methodologies used, a description of the organization of the network, maybe even some metrics like centrality. Something other than a picture, ferchrissakes.
Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
There are fields, Neo. Endless fields where bot beings are no longer born. Are grown. For the longest time I wouldn't believe it and then I saw the fields with my own eyes...
Thanks for clearing that up.
One of the nodes backendportal.info is registered to Horatio Nelson!
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
The Tao of math: The numbers you can count are not the real numbers.
If you zoom in, you'll see a lot of the concentration of spiderwebs are around sites like honeynet.cz.
I can see my house from...oh wait..oh :/
Power corrupts. Absolute power...is even more fun.
was wondering what techniques could have been used to mask an ip address as 1.3.3.7
Was it just me, or did anyone else imagine parent as speaking in the voice of max headroom?
"Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
Wait, 127.0.0.1 is in there. That is my IP address!
Is perfect security possible? Serious question.
If the answer is yes, then there would be some point to your idea. It would probably not be practical to do what you're suggesting, and it may run counter to some people's ideas of personal freedom. Probably you would piss off a hell of a lot of people.
If the answer is no, then the same flaws apply as above, except that it would be ultimately pointless. There's an evolutionary principle called the Red Queen effect that you should be aware of. It's kind of a consequence of selective pressure in an environment. Basically, if you close off all the security holes you know about, this creates a strong pressure for someone to find another security hole.
So, should we use draconian methods to try to achieve a perfectly secure internet? It seems like the same argument as the anti-terrorism efforts. I do not think such efforts would be successful, or worth the cost.
Those who advocate genocide deserve every protection afforded by law, and none afforded by common human decency.
Any I the only one who thinks it is a bad idea it publish a list of infected IP address? I know you can get the from Anti-Spam site to set as black-hole on your gateway but still....
I can't find the big arrow that says "You are here" on the map. How am I supposed to use it without that?
allow people to register with information like:
Registrant Contact:
elnopic
elnopic elnopic (elnopic@elnopic.com)
+1.2435543
Fax: +1.5555555555
123 sdhdsa g
asdf, AD 34215
US
Do they not even try to verify this information?
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
And this, dear parents, is why you make an image of your kids computer and just put it back when the computer gets "slow".
It will save you that day of irritation and removing all the junk.
I guess that's worth a few bucks, isn't it?
Privacy is terrorism.
If it was this easy, then all of the crap you've installed would be blocking botnet activity - but it's not. Reality is that botnet activity is obfuscated and buried in normal transactions and behaviors. All the firewalls on the planet cannot stop bot activity no matter what vendor marketing slicks say.
There must be too many bots - I can't even get it to render! All I get is a white page with no nodes and no links :\
;) )
Either that or they've rendered the botnet on a white background in apple white with light grey lines.
(i.e. it seems to be Slashdotted
isn'that the point though? Close off all easy security holes(put some dead bolts on those doors, and poly films to prevent glass breakage) security holes will still exist but will both be harder to take advantage of(robbery at gun pint for keys, social engineering) Or brute forcing passwords.
*nix's aren't hacked very often in mass groups, yet you put a non patched windows system on the net and it will be pwned by the time you can download the security updates.
Lock the windows and force the crackers to find other flaws. let them be your Quality control team, and your consumers are used to being beta testers anyways.
i thought once I was found, but it was only a dream.
cool i can see my home IP from there!
And why's this so much news?
Any self-respecting revolutionary knows that you have a distributed network, so that even if a cell goes down, you can still pass messages.
Hell... I wish IRC could learn from this, I've had enough of netsplits. By rights only the server that goes offline should be affected if it goes down, it shouldn't split the network into 2 massive sections.
Yeah the image looks nice, and is all "ooohhhh ahhhh" and lends itself to "Hey... that's me", but really "News"? I think not
Call me when they have an article as to how they got this information
-1 "Cynical Bastard"
I will not give in to the terrorists. I will not become fearful.
You can practically see the same image here: http://images.google.com/images?um=1&hl=en&rls=en&q=my+computer+desk&btnG=Search+Images
they are wonderful tools. botnets keep the world running.
...And people say nobody uses IRC anymore.
Spelling mistakes, grammatical errors, and stupid comments are intentional.
Anyone knows if there's a tool to check an IP and see if it's part of a botnet?
y y y y y y y y y yes yyyyyyyyes es es yes
I'm not arguing against increased security efforts. I'm just arguing against draconian methods of doing so, on the basis that they may ultimately be ineffective, in the sense that they would not alter the eventual outcome.
Those who advocate genocide deserve every protection afforded by law, and none afforded by common human decency.
That looks alot like the map of our network where I am emplo... oh crap...
Seriously, is it supposed to look like that?
I zoomed in and saw "pimpin.opendns.be" attatched to 1.3.3.7 Has someone been messing with them or something? Anyone else seen any weird ones?
LOL.
I had a computer error. Swear i didn't write it like that.
haha.
I too, felt violated. It's like the CGI thing in movies. Just because you can, doesn't mean you have to. Useless.
The cost of that cleanup, of course, will be borne by taxpayers, not industry.
Wow, I can see my house's IP address from the zoom-out. It looks like a little ant from up here.
Table-ized A.I.
Looks like you can get the image right from the guy who collected the data.
check
http://www.honeynet.cz/img/big.jpg
and even http://www.honeynet.cz/img/small-circo.jpg (if you mostly just want to get an idea of what it all looks like)
you could hook it up to Google Earth. That would allow Google to do all the pan/joom heavy lifting.
Engineering is the art of compromise.
Man, that is certainly very old. I remember using IRC about 15 years ago (dammit I really am getting old) and netsplits happening. It was ever so much fun using them to boot OPs out and so on, but damn... I didn't know that an age old problem was still, an age old problem. I'd have thought that this far on, we'd have implemented (we have already learned) distributed systems. I bet it those guys on Usenet or Google groups that are scuppering distributed information of this kind. PS: I have viagra for sale.
hacker != blackhat /. we're smarter then this, we not supposed MSM misinformed terminology
... come on, this is
0.0.0.0 is faster than 127.0.0.1 in a CUSTOM BLOCKING (or, speeding up type HOSTS file), because:
1.) 0.0.0.0 is smaller than 127.0.0.1 (& thus, loads faster from disk)
2.) 0.0.0.0 occupies less RAM than 127.0.0.1 redirects, especially once it is loaded (into your local DNS cache)
That's the first set of benefits using 0.0.0.0 yields vs. 127.0.0.1 (savings in initial loads + RAM occupancy)...
(AND - that's actually pretty "elementary" to understand, just do the math)
Mainly/Simply because if your HOSTS file is like mine, with 55,000++ entries? You gain 110,000 bytes right off the bat, in my case, in reduced size (for faster loads from disk into RAM initially), + less RAM occupancy (once it is loaded) since 0. is tinier than 127. (on the first octet of BOTH IP addresses, compared side-to-side basically)).
----
Also, iirc? 0.0.0.0 takes less "CPU power" (etc.) to process redirect requests than using 127.0.0.1 (localhost) entry!
(This last point - I would like clarification on, because I recall that 0.0.0.0 is like a copy > NUL (copying to "insta-trash", vs. making your IP & Network stack have to actually look @ it & see if it can field said requests TO ITSELF (vs. the servers you block)).
APK
P.S.=> Blocking adbanners, even if NOT 'infested/infected' as many have been the past few years now (& many "famous" sites online, including Fortune 100/500 companies no less due to javascript &/or iFrame exploits in banners or just malicious code on website pages) speeds you up too!
Webmasters &/or Adbanner folks may not like this, but, I pay for my online linetime myself & I want ALL of the possible speed I pay for (even if it comes @ their expense) + SECURITY too (due to adbanner infection happening QUITE A LOT the past few years online) by blocking adbanners (HBO Internet/NO COMMERCIALS faster, & safer)!
First off, you gain by blocking banners in SPEED:
A.) Your system does not waste time calling out to & loading data across the web from adbanner servers you block (for security AND speed)
B.) Your system does not waste time resolving blocked sites via your DNS (especially if you use the registry file below as a Windows NT-based OS user)
(FOR POINT B SPECIFICALLY? Hey- HOSTS &/or LOCAL DNS CACHE = Faster! Even more than a more secure one like OpenDNS &/or ScrubIT DNS for example & simply because they are remote nonetheless, & that, takes time)
Mainly because local HDD's access that data (for speeding up your fav sites too, NOT just blocking adbanner servers OR known malicious ones by introducing their actual TRUE IP address = URL into your HOSTS file, & even if your DNS servers get poisoned OR go down? You STILL GET TO YOUR FAV. SITES TOO, just faster)
You can also CHANGE THE ORDER OF SEEK PREFERENCE, on remote DNS server, vs. HOSTS, vs. LocalDNS Cache too even, here in Windows 2000/XP/Server 2003 (possibly VISTA too):
----
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider]
"DnsPriority"=dword:00000007
"HostsPriority"=dword:00000006
"LocalPriority"=dword:00000005
"NetbtPriority"=dword:00000008
Lower #'s = GREATER PRIORITY
----
HOWEVER - Occasinally though, this need change/maintenance (IF you "hardcode" your own HOSTS file to resolve your fav sites... MAINLY, this has one small downside, but it's rare (since sites change hosting providers or network topology in server IP addresses too, etc. on occasion)!
Using a HOSTS file vs. dns servers? It's just far, FAR, F A R faster than roundtrip URL - to - IP Address resolutions from a DNS server.
Secondly, you gain MORE IN SPEED STILL, via:
Nor do you waste CPU time & electricity running any adbanner servers' script code + rendering images in your browser for adbanners, even NON-INFECTING ones (which is DEFINTELY potential
David is lead on the Czech Honeynet Project - http://www.honeynet.cz/?mmenu=home&smenu_int=0&lang=en&vmetr=1
"It doesn't cost enough, and it makes too much sense."
http://uk.gizmodo.com/win98%20logo.jpg
A little off topic, but my use of non-text tools is a bit limited. :) How would one go about mimicing the ability to make that Botnet map?
What those who want activist courts fear is rule by the people.
there hasn't been a *nx monoculture since the 1970's when it was first developed. Even in Linux you have 4-5 major distributions, with different libraries and software versions.
There is no monoculture in *nix. There never really was one.
i thought once I was found, but it was only a dream.
Actually the vast majority of botnet infections right spread by e-mail trojans and drive-by installs. These are not problems firewalls are meant to address. For the latter, you can sandbox your browser or at least keep your patches up to date. For the former, we expect people not to be idiots.
So, in reality, what you should say is that all the security advice on the planet cannot stop bot activity, no matter how smart people claim to be.
Wow, uhm...
... How much RAM do you have that the loading of the ASCII-encoded file is a serious difficulty?
0.0.0.0 is smaller in RAM than 127.0.0.1 because the numbers look smaller?