Zeus Botnet Down But Not Out
harryjohnston writes "The Register points out that the takedown of a significant number of Zeus command-and-control servers, which we discussed earlier, was a short-lived victory, as about one-third of the affected servers were back on the net in less than 48 hours." Adds itwbennet: "Just hours after network connectivity to Troyak was severed the ISP peered with a new upstream Internet service provider named Ya. The next step will be to 'de-peer' Troyak from its new service provider, either an ISP named Nassist or its upstream provider, Hurricane Electric, said a researcher familiar with the matter. 'We have taken some of their territory, they are trying to out flank us,' the researcher said via IM. 'We are going to win this one — we have 'em boxed in.'"
n/t
So the Zeus is like a Toyota. You get a fix for it but it turns out they'll just keep going anyway.
How much are they charging per month for use of a command-and-control server? Can I host my e-commerce site on Zeus?
Do you have to share the command and control server with other users? Or do they have a "private command server" option?
(On a side note- will twittering help my business?)
This cat and mouse game that they are playing here reminds me of another cat and mouse......
were that reliable...
Aparently if your father had encased something else in rubber, we wouldn't have to listen to your drivel...
Science advances one funeral at a time- Max Planck
Ummmm... Isn't it true that if even one C&C is alive you really haven't killed the botnet? The more you kill the more you slow it down but it's still there.
All they had back then was lambskin.
Just like a real war..
"We got Charlie boxed in"
For justice, we must go to Don Corleone
Hurricane Electric.. there's the problem. Blocked all email from their scummy network years ago and never looked back.
There are stories about botnets all the time, but I usually don't see anything about how to remove them. I'm pretty confident in my browsing habits, but the same can't be said for my relatives. What's the easiest way to check a machine for infestation? Do standard virus scanners handle it, or programs like Malewarebytes?
/.
Double Tap
This is actually informative. Botnets are the very model of enterprise redundant high-availability. The technology is remarkable in its resilience. You could wipe out Europe and Asia with dual asteroids, and the thing would keep going.
If you want to keep your enterprise up no matter what happens then you need to be prepared for a headshot. They are, and it's not enough to bring them down. How prepared are you?
Help stamp out iliturcy.
Bazinga!
okay so HE hosts McColo and is the upstream for this shit and my company gets shit canned from them for what a spamcop complaint? Was it a legit complaint? Yes and I shit canned the customer, but this really pisses me off. They let really bad people run on their network and they shoot the little guy getting abused. I guess if you have enough money it doesn't matter what you do on their network till the feds get involved.
To tell the truth, the only thing i got was that
these losers did not pay their Internet bills to take over the world like Stewie!
Stewie had the world and let it go!
We probably need to bild new great firewall around countries and ISPs hosting C&C nodes. Those are the same countries every time where to the botnet owners move their activity ( names are in articel )
I've had a website hosted on Hurricane Electric since 1997. Email too. They've been really reliable. So it'd suck for them to go down because of some vigilante reaction to a botnet.
-B
Ash and Hickory, straight-grained and true, make excellent bludgeons, dandy for the cudgeling of vegetarians.
When SkyNet comes, we will know how to fight it!
Why do I have the Major General's song in my head now?
"I am the very model of good "high availability.
My peers and I retain a certain level of redundancy."
Damnit, I'm meant to be at work, not filking...
RoseColor red={0, 0xffff, 0x0000, 0x0000};VioletColour blue={0, 0x0000, 0x0000, 0xffff};find / -name *mybase*|chown you
All they had back then was lambskin.
So? Banging sheep is a perfectly good method of birth control.
Hah! captcha = untapped
Some people really need to stop posting what they are doing or about to do....gives a heads up to the trojan writers what
to think of next to counter the attacks. I think it is a great feat none the less, but could we have really kept them down longer had we not
had a play by play....also like the Borg, now they know the type of attack vectors that are being used against them, so they will adapt, and figure a new way to connect to control and command centers, I know I would had i just finished spending all my time on my botnet, and someone figured out how to munch my communication to it.
Well if I could steal my service from a few million locations I'd probably have pretty good uptime too. Oh and if the only service I needed to deliver was 1kb/s ascii text control channel, yeah, I think I'd do ok.
Cardio
'We have taken some of their territory, they are trying to out flank us,' the researcher said
I posted a remark in the topic about New Zealand ISPs agreeing to filter. I think it fits better here.
A well-distributed botnet, with fast flux DNS switching, could be turned into a pretty good replacement for freenet, and an efficient way past these clumsy government-inspired filters. Somebody with a botnet could sell such a service.
There are several problems with trust. One is how to trust the owner with your credit card details. CCBill maybe?
Powerful malware on the zombie exit points ought to offer better assurance of anonymity than is available on the volunteer nodes of freenet.