<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: New Botnet Malware Spreading SQL Injection Attack Tool</title>
	<atom:link href="http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 08 Jan 2009 20:44:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123123</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Tue, 20 May 2008 19:05:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123123</guid>
		<description>1337ullus,

Thanks for clarifying that for me. interesting problem.</description>
		<content:encoded><![CDATA[<p>1337ullus,</p>
<p>Thanks for clarifying that for me. interesting problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1337ullus</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123121</link>
		<dc:creator>1337ullus</dc:creator>
		<pubDate>Tue, 20 May 2008 16:48:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123121</guid>
		<description>@Bogwitch 
No bug to patch in the FTP issue, here is the story:

Afaik, our customers got infected. The botnet agent either sniff ftp user/pass from network or use well known ftp client config file (filezilla), and send the FTP account to the botnet.

The botnet then connect with the stolen FTP account and modify specific files (index, js, ...) to inject javascripts (trojan downloader). 

New customers get infected while browsing infected websites and botnet life goes on.

I agree that solution to FTP problem is not to use FTP anymore.
BUT we got thousands customers accustomed to use FTP with their favorite FTP Client. Then MS secured ftp is ... inexistant.
Also we did change FTP user/pass, but it's useless as long as customers are infected.

We also setted blacklists on attackers ip classes, but as fast as it goes, we'll be blacklisting the whole internet next week.

The FTP authpf bridge was setted up last week, then the SQL Injection attack stroke. I'll give you stats of my bridge later.</description>
		<content:encoded><![CDATA[<p>@Bogwitch<br />
No bug to patch in the FTP issue, here is the story:</p>
<p>Afaik, our customers got infected. The botnet agent either sniff ftp user/pass from network or use well known ftp client config file (filezilla), and send the FTP account to the botnet.</p>
<p>The botnet then connect with the stolen FTP account and modify specific files (index, js, &#8230;) to inject javascripts (trojan downloader). </p>
<p>New customers get infected while browsing infected websites and botnet life goes on.</p>
<p>I agree that solution to FTP problem is not to use FTP anymore.<br />
BUT we got thousands customers accustomed to use FTP with their favorite FTP Client. Then MS secured ftp is &#8230; inexistant.<br />
Also we did change FTP user/pass, but it&#8217;s useless as long as customers are infected.</p>
<p>We also setted blacklists on attackers ip classes, but as fast as it goes, we&#8217;ll be blacklisting the whole internet next week.</p>
<p>The FTP authpf bridge was setted up last week, then the SQL Injection attack stroke. I&#8217;ll give you stats of my bridge later.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jinesh</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123104</link>
		<dc:creator>Jinesh</dc:creator>
		<pubDate>Mon, 19 May 2008 13:42:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123104</guid>
		<description>These botnets are scarry. One which i had on my machine used to upload files on torrent. weird huh!!!</description>
		<content:encoded><![CDATA[<p>These botnets are scarry. One which i had on my machine used to upload files on torrent. weird huh!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123100</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Mon, 19 May 2008 11:54:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123100</guid>
		<description>@1337ullus,

"We’ve been and are still beeing attacked by Storm, that is (re)injecting ftp sites every friday or so."

I have to ask, how is Storm (re)injecting your ftp sites? It suggest to me that you may have patch issues that need to be resolved. As for your authpf bridge, is that not a kludge?

Please correct me if I am wrong!</description>
		<content:encoded><![CDATA[<p>@1337ullus,</p>
<p>&#8220;We’ve been and are still beeing attacked by Storm, that is (re)injecting ftp sites every friday or so.&#8221;</p>
<p>I have to ask, how is Storm (re)injecting your ftp sites? It suggest to me that you may have patch issues that need to be resolved. As for your authpf bridge, is that not a kludge?</p>
<p>Please correct me if I am wrong!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1337ullus</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123098</link>
		<dc:creator>1337ullus</dc:creator>
		<pubDate>Mon, 19 May 2008 09:02:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123098</guid>
		<description>Look like the injection code use an open source librairy from http://www.indyproject.org/.

Last week-end attack queries contained : "User-agent: Mozilla/3.0 (compatible; Indy Library)."</description>
		<content:encoded><![CDATA[<p>Look like the injection code use an open source librairy from <a href="http://www.indyproject.org/" rel="nofollow">http://www.indyproject.org/</a>.</p>
<p>Last week-end attack queries contained : &#8220;User-agent: Mozilla/3.0 (compatible; Indy Library).&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zupakomputer</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123066</link>
		<dc:creator>zupakomputer</dc:creator>
		<pubDate>Fri, 16 May 2008 16:05:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123066</guid>
		<description>That's what happens though, when anything gets complicated (like webpage coding, and database coding) then it becomes a haven for being able to hide all kinds of activity in.

And personally, I really think that the over-complicated coding is pushed for exactly those reasons. Same way they do that in the law and in any kinds of bureacracies, it's ordered in such a way that no-one can ever know all of it, and there's loads of avenues to exploit things through.

Keep things simple and straightforward, and it's easy to see who's doing what and where they are doing it.</description>
		<content:encoded><![CDATA[<p>That&#8217;s what happens though, when anything gets complicated (like webpage coding, and database coding) then it becomes a haven for being able to hide all kinds of activity in.</p>
<p>And personally, I really think that the over-complicated coding is pushed for exactly those reasons. Same way they do that in the law and in any kinds of bureacracies, it&#8217;s ordered in such a way that no-one can ever know all of it, and there&#8217;s loads of avenues to exploit things through.</p>
<p>Keep things simple and straightforward, and it&#8217;s easy to see who&#8217;s doing what and where they are doing it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 1337ullus</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123061</link>
		<dc:creator>1337ullus</dc:creator>
		<pubDate>Fri, 16 May 2008 07:13:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123061</guid>
		<description>Actually, it's real pain to get protected against the botnets. We've been and are still beeing attacked by Storm, that is (re)injecting ftp sites every friday or so. The sql injection ome stroke once on may 1st..

We built an authpf bridge that let you ftp in only if you connected your website first. Hope it'll stop Storm for a while.
As for the sql injections, we had to fix a lot of scripts...

I wonder if there are dnsbl that report botnet infected hosts ..</description>
		<content:encoded><![CDATA[<p>Actually, it&#8217;s real pain to get protected against the botnets. We&#8217;ve been and are still beeing attacked by Storm, that is (re)injecting ftp sites every friday or so. The sql injection ome stroke once on may 1st..</p>
<p>We built an authpf bridge that let you ftp in only if you connected your website first. Hope it&#8217;ll stop Storm for a while.<br />
As for the sql injections, we had to fix a lot of scripts&#8230;</p>
<p>I wonder if there are dnsbl that report botnet infected hosts ..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eM3rC</title>
		<link>http://www.darknet.org.uk/2008/05/new-botnet-malware-spreading-sql-injection-attack-tool/comment-page-1/#comment-123060</link>
		<dc:creator>eM3rC</dc:creator>
		<pubDate>Fri, 16 May 2008 00:01:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=856#comment-123060</guid>
		<description>When I first found out about botnets I though it was an amazing concept.

Not that their being used to distribute files a whole new market of exploiting has just opened. I wonder what the next step is.</description>
		<content:encoded><![CDATA[<p>When I first found out about botnets I though it was an amazing concept.</p>
<p>Not that their being used to distribute files a whole new market of exploiting has just opened. I wonder what the next step is.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
