<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Twitter Being Used As Botnet Command Channel</title>
	<atom:link href="http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comment-158729</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Wed, 19 Aug 2009 00:41:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024#comment-158729</guid>
		<description>Didn&#039;t conficker get its command and control from websites and a long list of domains, also using p2p between bots, I am sure I even read about one that generated blogspot sub domains and visited their for their C&amp;C. It is a natural progression.
The bot programmers will obfuscate and disperse their C&amp;C infrastructure so that it is both difficult to find and nice and distributed on free services, it seems common sense to me, like a story I heard a few years ago about a terrorist cell comunicating via a public messaging board using keywords in their usually on topic posts, combined with images posted that contained stenographically encapsulated data. Or back in WW1 and WW2 ending news broadcasts with non-sensical messages as a way to communicate with the resistance.
What is being done now has been done before.</description>
		<content:encoded><![CDATA[<p>Didn&#8217;t conficker get its command and control from websites and a long list of domains, also using p2p between bots, I am sure I even read about one that generated blogspot sub domains and visited their for their C&amp;C. It is a natural progression.<br />
The bot programmers will obfuscate and disperse their C&amp;C infrastructure so that it is both difficult to find and nice and distributed on free services, it seems common sense to me, like a story I heard a few years ago about a terrorist cell comunicating via a public messaging board using keywords in their usually on topic posts, combined with images posted that contained stenographically encapsulated data. Or back in WW1 and WW2 ending news broadcasts with non-sensical messages as a way to communicate with the resistance.<br />
What is being done now has been done before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sighK</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comment-158711</link>
		<dc:creator>sighK</dc:creator>
		<pubDate>Mon, 17 Aug 2009 22:46:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024#comment-158711</guid>
		<description>Maybe they can use that to their advantage, twitter can see how it works, then block the person from logging on and then post something to make them all delete themselves</description>
		<content:encoded><![CDATA[<p>Maybe they can use that to their advantage, twitter can see how it works, then block the person from logging on and then post something to make them all delete themselves</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comment-158708</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Mon, 17 Aug 2009 16:45:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024#comment-158708</guid>
		<description>If anyone is interested in taking apart the malware that was being propagated in this botnet, I wrote up a post of my experiences, along with malware samples should you wish to follow along: http://wp.me/pBV1X-n</description>
		<content:encoded><![CDATA[<p>If anyone is interested in taking apart the malware that was being propagated in this botnet, I wrote up a post of my experiences, along with malware samples should you wish to follow along: <a href="http://wp.me/pBV1X-n" rel="nofollow">http://wp.me/pBV1X-n</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comment-158706</link>
		<dc:creator>John</dc:creator>
		<pubDate>Mon, 17 Aug 2009 16:23:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024#comment-158706</guid>
		<description>I like Twitter, but it is becoming more spammy.</description>
		<content:encoded><![CDATA[<p>I like Twitter, but it is becoming more spammy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GZero</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comment-158700</link>
		<dc:creator>GZero</dc:creator>
		<pubDate>Mon, 17 Aug 2009 08:09:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024#comment-158700</guid>
		<description>Web Based C&amp;Cs are (for me) the next natural step.

Just like P2P networks made the switch from obscure custom protocols (Gnutella, Direct Connect) to HTTP based services (BitTorrent), so too will the bots.</description>
		<content:encoded><![CDATA[<p>Web Based C&amp;Cs are (for me) the next natural step.</p>
<p>Just like P2P networks made the switch from obscure custom protocols (Gnutella, Direct Connect) to HTTP based services (BitTorrent), so too will the bots.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NNM</title>
		<link>http://www.darknet.org.uk/2009/08/twitter-being-used-as-botnet-command-channel/#comment-158699</link>
		<dc:creator>NNM</dc:creator>
		<pubDate>Mon, 17 Aug 2009 06:27:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2024#comment-158699</guid>
		<description>I&#039;m not sure why anyone uses twitter at all...
It&#039;s childish, buggy, hacked, unsecured...
I signed up a year ago to &quot;see what it is&quot;... 
I have never used it, and I have about 300 followers, all spammers or bots.

I find it very amusing how they get abused...
&quot;Now comes evidence that the microblogging website is being used to feed the very types of infected machines that took it out of commission.&quot;</description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure why anyone uses twitter at all&#8230;<br />
It&#8217;s childish, buggy, hacked, unsecured&#8230;<br />
I signed up a year ago to &#8220;see what it is&#8221;&#8230;<br />
I have never used it, and I have about 300 followers, all spammers or bots.</p>
<p>I find it very amusing how they get abused&#8230;<br />
&#8220;Now comes evidence that the microblogging website is being used to feed the very types of infected machines that took it out of commission.&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

