What a Botnet Looks Like
Esther Schindler writes "CSO has an annotated, zoomable map of real botnet topologies showing the interconnections between the compromised computers and the command-and-control systems that direct them. The map is based on work by security researcher David Voreland; it has interactive controls so you can zoom in and explore botnets' inner workings. Hackers use botnets for spamming, DDoS attacks and identity theft. One recent example is the Storm botnet, which may have comprised 1 million or more zombie systems at its peak. As with any networking challenge, there are good (resilient) designs and some not-so-good ones. In some cases the topology may be indicative of a particular botnet's purpose, or of a herder on the run."
To get a good look at a botnet they say, "You need to upgrade your Flash Player". How true!
No calls now, I'm
here's a photo of a botnet. Ok, it's a small botnet but if the botnet was a semi you wouldn't see the computers, now would you?
mcgrew's razor: Never attribute to stupidity that which can be explained by greedy self-interest
all of the IP addresses. Can I get that in a text format? I want to add them to my hosts file.
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
http://www.artsci.washington.edu/news/Autumn05/largermap_sexualnetworks.htm
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
It would be nice to be able to search my static IP or a range of IPs to see if they are on the map.
There are lots of well constructed stars, where a handful of master nodes control several slaves. Each slave knows two or three masters for redundancy. That's good design, and I expected it.
But what's hilarious is that there are some ip addresses that are slaves to four or five different botnets. I wonder what the owners of those machines think?
"Man, the internet sure is slow today!"
"I need a new computer, this one's all slow."
"Sweet! Five botnets and counting! I'm part of something! I belong!"
Use the Firehose to mod down Second Life stories!
Who modded this "offtopic"? The site requires the latest and greatest flash player to look at a freaking image when everyone knows that Flash has big fat holes in it. They might as well made it IE only.
...would like to see more. Was there actually an article there, or was that just a picture? How about something about the methodologies used, a description of the organization of the network, maybe even some metrics like centrality. Something other than a picture, ferchrissakes.
Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
No, it sucks. I zoomed in to close and saw my IP!
There are fields, Neo. Endless fields where bot beings are no longer born. Are grown. For the longest time I wouldn't believe it and then I saw the fields with my own eyes...
One of the nodes backendportal.info is registered to Horatio Nelson!
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
If you zoom in, you'll see a lot of the concentration of spiderwebs are around sites like honeynet.cz.
Was it just me, or did anyone else imagine parent as speaking in the voice of max headroom?
"Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
Wait, 127.0.0.1 is in there. That is my IP address!
allow people to register with information like:
Registrant Contact:
elnopic
elnopic elnopic (elnopic@elnopic.com)
+1.2435543
Fax: +1.5555555555
123 sdhdsa g
asdf, AD 34215
US
Do they not even try to verify this information?
One of our competitors trademarked the term "hypothesis". From now on, we will call them "boneheaded ideas".
There must be too many bots - I can't even get it to render! All I get is a white page with no nodes and no links :\
;) )
Either that or they've rendered the botnet on a white background in apple white with light grey lines.
(i.e. it seems to be Slashdotted
And why's this so much news?
Any self-respecting revolutionary knows that you have a distributed network, so that even if a cell goes down, you can still pass messages.
Hell... I wish IRC could learn from this, I've had enough of netsplits. By rights only the server that goes offline should be affected if it goes down, it shouldn't split the network into 2 massive sections.
Yeah the image looks nice, and is all "ooohhhh ahhhh" and lends itself to "Hey... that's me", but really "News"? I think not
Call me when they have an article as to how they got this information
-1 "Cynical Bastard"
I will not give in to the terrorists. I will not become fearful.
That looks alot like the map of our network where I am emplo... oh crap...
Seriously, is it supposed to look like that?