Twitter Used To Control Botnet Machines
DikSeaCup writes "Arbor Network's Jose Nazario, an expert on botnets, discovered what looks to be the first reported case of hackers using Twitter to control botnets. 'Hackers have long used IRC chat rooms to control botnets, and have continually used clever technologies, such as peer-to-peer strategies, to counter efforts to track, disrupt and sometimes decapitate the bots. Perhaps what's surprising then is that it's taken so long for hackers to take Twitter to the dark side.' The next step, of course, is to code the tweets in such a way that they aren't so suspicious."
Sure Twitter is just a large botnet, but is anyone really in control?
Who knew Twitter had a use?!?!
ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
Twitter isn't as reliable as IRC.
This is a boring sig
That's actually an interesting thought... it was sending obfuscated URLs to code that the zombie bots would download and execute.
Wouldn't it make sense, rather than having Twitter simply kill the account, to allow the "good" guys to craft some sort of zombie-self-destruct and tweet its URL over the account? Imagine, all the bots automatically downloading and executing a specially designed tool that removes the malicious trojan...
Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
"Twitter Used To Control Botnet Machines"
It used to, but it doesn't anymore, right?
Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
Jose and those guys at Arbor are doing really concrete things to curb botnets and malware contagion. They have their gear in a great number of peering points around the world, and are correlating huge amounts of data into discrete patterns. I've seen Jose speak a couple of times, and I am impressed by the manner in which they are finding the ghosts who think they can't be found.
Anything that can be pinged and return any sort of tcp/ip packets could be a control center if the contents of the packets can actually
be translatable and have been mapped accordingly.
ie- ftp server has certain verbose return that may be configured based on what is being done, so the botnet program calls home to an ftp server...looking like a plain jane communication to any one looking. It tries a few different commands to which the ftp server can reply (with error messages) it can not proceed, however inside the ftp server error message is a text string that contains certain
key phrases.
This scenario is similar to steganography, of hiding in plain sight, inside an image, the contents of data....
I think it's cool to be able to pass off information that is hidden to regular onlookers, but is a lot of coding for nothing if you ask me.
Set up a twitter account where a particular page has the commands for all your bots to follow, and....wait a minute....
No onE would Think of uSing slashdoT As we aRen'T nearly as oBviOus as someThiNg likE Twitter. // Especially with all our talk about supporting Linux and such.
Sure they tried using Twitter to control their botnet but after sending out one set of instructions they got bored and went back to playing MafiaWars on Facebook.
Hmm... so you're saying I should take out this cron entry...
... that I added per the instructions in some stranger's .sig?
Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
The next step, of course, is to code the tweets in such a way that they aren't so suspicious
And people said that perl obfuscation, poetry, and golf tournaments didn't have any practical application. Ha!
Motorcycles, Robots, Space Gossip and More!
From the looks of it it's all base64 encoded shortened URLs.
aHR0cDovL2 is http:///
aHR0cDovL2JpdC5seS is http://bit.ly/
The first one is clipped.
The rest go to a pastebinish sites which have gbpm.exe encoded as Base64. It also appears the base64 is different but the exe has the same name (I'm guessing it's changed 'output'?)
http://rifers.org/paste/content/paste/9507/body?key=upd4t3
http://rifers.org/paste/content/paste/9508/body?key=upd4t3
http://rifers.org/paste/content/paste/9509/body?key=upd4t3
They also use Pastebin (http://pastebin.com/pastebin.php?dl=m49f3b4c2) and Debian.net (http://paste.debian.net/44059/download/44059) but both of those file have been deleted.
There's already a botnet like that, but it runs on poorly-secured human brains rather than computers.
I am TheRaven on Soylent News