<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; zombies</title>
	<atom:link href="http://www.darknet.org.uk/tag/zombies/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Next-Gen Botnets Taking The Place of Storm and Srizbi</title>
		<link>http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/</link>
		<comments>http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/#comments</comments>
		<pubDate>Thu, 15 Jan 2009 14:04:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[bobax]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rustock]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[srizbi]]></category>
		<category><![CDATA[storm]]></category>
		<category><![CDATA[storm botnet]]></category>
		<category><![CDATA[storm worm]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worms]]></category>
		<category><![CDATA[xarvester]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1386</guid>
		<description><![CDATA[Back in November there was a considerable drop in Spam when Spam friendly ISP McColo was cut off from the Internet by it&#8217;s upstream peer. Srizbi worm was pretty smart though and was picking up again by the end of November. Later in the year the botnets were somewhat neutralised leading to a huge drop [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Back in November there was a considerable drop in Spam when <a href="http://www.darknet.org.uk/2008/11/spam-isp-mccolo-cut-off-from-the-internet/">Spam friendly ISP McColo was cut off from the Internet</a> by it&#8217;s upstream peer.</p>
<p><a href="http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/">Srizbi worm was pretty smart though</a> and was picking up again by the end of November. Later in the year the botnets were somewhat neutralised leading to a huge drop in spam.</p>
<p>But now, they are back &#8211; re-engineered &#8211; and ready to spam without going down again.</p>
<blockquote><p>The demise late last year of four of the world&#8217;s biggest spam botnets was good news for anyone with an email inbox, as spam levels were cut in half &#8211; almost overnight. But the vacuum has created opportunities for a new breed of bots, some of which could be much tougher to bring down, several security experts are warning.</p>
<p>New botnets with names like Waledac and Xarvester are filling the void left by the dismantling of Storm and the impairment of Bobax, Rustock, and Srizbi, these researchers say. The new breed of botnets &#8211; massive networks of infected Windows machines that spammers use to blast out billions of junk messages &#8211; sport some new designs that may make them more immune to current take-down tactics.</p>
<p>Waledac is a good example. It appears to be a complete revision of Storm, that includes the same state-of-the-art peer-to-peer technology and fast-flux hosting found in its predecessor, according to researcher Joe Stewart of Atlanta-based security provider SecureWorks. But it differs from Storm in one significant way: Weak encryption protocols, which proved to be an Achilles Heel that led to its downfall, have been completely revamped</p></blockquote>
<p>That&#8217;s one problem with attacking these botnets and the malware behind them, the people doing it aren&#8217;t kids having fun. They are business syndicates making serious money, so whatever you do &#8211; they are going to learn from it and adapt their software and methods to circumnavigate it.</p>
<p>That&#8217;s what seems to be happening now with Waledac, a new re-engineered version of Storm with stronger encryption protocols. They learnt from their mistakes and released a new, updated and more powerful version.</p>
<p>What amazes me is that in the Xarvester malware, it actually makes use of the Windows crash reports &#8211; sending them to the developers to make the bot more stable!</p>
<blockquote><p>&#8220;Several researchers are actively studying the communications, but I don&#8217;t know if and when it will be broken and hijackable,&#8221; said Jose Nazario, a security researcher at Arbor Networks. &#8220;The guys behind the botnet seems intent on staying up and so evading researchers seems like the most appropriate thing to do.&#8221;</p>
<p>Waledac has amassed some 10,000 zombie computers so far, a tiny fraction of the bigger botnets. But Stewart expects it to be a major player in the coming months. Meanwhile, a spam botnet called Xarvester is making similar inroads. It is the world&#8217;s third-biggest spammer, accounting for over 13 percent of the world&#8217;s spam, according to Marshall. What&#8217;s more, its uncanny resemblance to Srizbi has sparked suspicions it is a reincarnation of that notorious botnet. Similarities include an HTTP-based command and control center that uses non-standard ports, encrypted template files used to send spam and configuration files with the common formats and data.</p>
<p>It also has a sophisticated feedback system that helps bot developers squash bugs so the software is harder to detect on a victim&#8217;s machine.</p>
<p>&#8220;Just like Srizbi, Xarvester has the ability to upload the Windows minidump crash dump file to a control server in the event that the bot crashes a system,&#8221; according to this analysis from Marshall. &#8220;This is presumably to help the botnet controllers debug their bot software.&#8221;</p></blockquote>
<p>It seems like Xarvester has some uncanny resembelances to Srizbi too, so maybe it&#8217;s a new updated release from the same group which fixes the flaws that made Srizbi fail in the long term.</p>
<p>The infection rates for these bots are quite low currently, but due to the new measures the developers have taken they are likely to gain many more infections and be much harder to remove/detect and stop.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/01/14/botnets_of_2009/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Next-Gen+Botnets+Taking+The+Place+of+Storm+and+Srizbi+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1386+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/&amp;t=Next-Gen+Botnets+Taking+The+Place+of+Storm+and+Srizbi" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/&amp;title=Next-Gen+Botnets+Taking+The+Place+of+Storm+and+Srizbi" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/&amp;title=Next-Gen+Botnets+Taking+The+Place+of+Storm+and+Srizbi" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/&amp;title=Next-Gen+Botnets+Taking+The+Place+of+Storm+and+Srizbi" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/&amp;title=Next-Gen+Botnets+Taking+The+Place+of+Storm+and+Srizbi" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Fnext-gen-botnets-taking-the-place-of-storm-and-srizbi%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/next-gen-botnets-taking-the-place-of-storm-and-srizbi/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Spam Back on the Rise with Srizbi Resurrected</title>
		<link>http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/</link>
		<comments>http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 07:57:37 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[e-mail spam]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[mccolo]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[scammers]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam botnet]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[srizbi]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[worms]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1264</guid>
		<description><![CDATA[After McColo was partially disconnected from the Internet by it&#8217;s peers global spam dropped noticeably. It seems however that the spam was emanating from a zombie network and the control servers were hosted by McColo, the creators of the botnet (Srizbi) were smart about it though and built a fail-safe system into the the malware. [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>After <a href="http://www.darknet.org.uk/2008/11/spam-isp-mccolo-cut-off-from-the-internet/">McColo was partially disconnected from the Internet</a> by it&#8217;s peers global spam dropped noticeably.</p>
<p>It seems however that the spam was emanating from a zombie network and the control servers were hosted by <a href="http://www.darknet.org.uk/tag/mccolo/">McColo</a>, the creators of the botnet (<a href="http://en.wikipedia.org/wiki/Srizbi_botnet">Srizbi</a>) were smart about it though and built a fail-safe system into the the malware.</p>
<p>It should be expected that spam will return to normal levels within a week or so.</p>
<blockquote><p>On Nov. 11, the Internet servers used to control the Srizbi botnet were disconnected when a Web hosting firm identified by security experts as a major host of organizations engaged in spam activity was taken offline by its Internet providers.</p>
<p>Turns out, Srizbi&#8217;s authors had planned ahead for such a situation by building into each bot a fail-safe mechanism in case its master control servers were unavailable: A mathematical algorithm that generates a random but unique Web site domain name to check for new instructions and software updates.</p>
<p>With such a system in place, the malware authors can regain control over the bots merely by registering the Web site names that the infected machines are trying to visit and placing the instructions there.</p></blockquote>
<p>It seems to be a pretty advanced piece of malware, it acts as a rootkit so it&#8217;s hard to remove, it&#8217;s has a Python mailing component which allows 3rd party access &#8211; this makes it very probably the botnet is &#8216;rented&#8217; out to spam houses. It also pretty powerful on the network level as it can directly attach NDIS and TCP/IP drivers to its own process to hide network traffic it generates.</p>
<p>Some claim Srizbi is the largest botnet and is responsible for over half of the spam being produced globally, so this is a worrying turn of events.</p>
<blockquote><p>According to FireEye, a security company in Milpitas, Calif., that has closely tracked the botnet&#8217;s actviity, a number of those rescue domains <a href="http://blog.fireeye.com/research/2008/11/its-srizbi-trun-now.html">were registered Tuesday evening</a>, apparenly directing at least 50,000 of the Srizbi-infected machines to receive new instructions and malicious software updates from servers in Estonia.</p>
<p>FireEye senior security researcher Alex Lanstein said he fully expects spam volumes to recover to their pre-Nov. 11 levels within a couple of days.</p>
<p>&#8220;Srizbi was the spam king,&#8221; Lanstein said. &#8220;And now it&#8217;s back.&#8221;</p></blockquote>
<p>Seen as though the main activity is happening in Eastern Europe it seems unlikely anyone will be able to stop it and due to the very nature of botnets (completely distributed) IP blacklisting is futile as the mail could be coming from anywhere.</p>
<p>Anyhow it&#8217;ll be an interesting story to watch and I hope there are some new developments in taking these botnets out.</p>
<p></p>
<p>Source: <a href="http://voices.washingtonpost.com/securityfix/2008/11/spam_volumes_expected_to_rise.html">Security Fix</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Spam+Back+on+the+Rise+with+Srizbi+Resurrected+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1264+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/&amp;t=Spam+Back+on+the+Rise+with+Srizbi+Resurrected" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/&amp;title=Spam+Back+on+the+Rise+with+Srizbi+Resurrected" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/&amp;title=Spam+Back+on+the+Rise+with+Srizbi+Resurrected" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/&amp;title=Spam+Back+on+the+Rise+with+Srizbi+Resurrected" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/&amp;title=Spam+Back+on+the+Rise+with+Srizbi+Resurrected" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F11%2Fspam-back-on-the-rise-with-srizbi-resurrected%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/11/spam-back-on-the-rise-with-srizbi-resurrected/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8216;Security Consultant&#8217; Caught for Running Large Bot Network</title>
		<link>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/</link>
		<comments>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/#comments</comments>
		<pubDate>Tue, 13 Nov 2007 08:37:22 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security consultant]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[trust]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-botnet/</guid>
		<description><![CDATA[Apparently he stopped his naughty activities back in 2006, but still&#8230;a guy that is supposed to securing machines was installing malware and had a bot totaling about a quarter of a million zombies. Most used for info gathering, Paypal accounts and installing Malware for comission, he claims to have made $19,000 in a week installing [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Apparently he stopped his naughty activities back in 2006, but still&#8230;a guy that is supposed to securing machines was installing malware and had a bot totaling about a quarter of a million zombies.</p>
<p>Most used for info gathering, Paypal accounts and installing Malware for comission, he claims to have made $19,000 in a week installing TopConverting (<a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/02/14/AR2006021401342_pf.html">read more</a>).</p>
<blockquote><p>A Los Angeles security professional has admitted to infecting more than a quarter million computers with malicious software and installing spyware that was used to steal personal data and serve victims with online advertisements.</p>
<p>John Kenneth Schiefer, 26, variously known online as &#8220;acid&#8221; and &#8220;acidstorm,&#8221; agreed to plead guilty to at least four felony charges of fraud and wiretapping, charges punishable by $1.75 million in fines and nearly 60 years in prison.</p>
<p>Investigators say Schiefer and two minors &#8212; identified in the complaint only by their online screen names &#8220;pr1me&#8221; and &#8220;dynamic&#8221; &#8212; broke into about 250,000 PCs. On at least 137,000 of those infected systems, Schiefer and his cohorts installed programs that allowed them to control the machines remotely. </p></blockquote>
<p>That&#8217;s a pretty reasonable sized network, enough to rent out for some serious DDoS attacks, and certainly enough Paypal accounts to earn some good money.</p>
<blockquote><p>Schiefer said he and his friends spread the bot programs mainly over AOL Instant Messenger (AIM). By using malicious &#8220;spreader&#8221; programs such as Niteaim and AIM Exploiter, Schiefer and his co-conspirators spammed out messages inviting recipients to click on a link. Anyone who took the bait had a &#8220;Trojan horse&#8221; program downloaded to their machine, an invader that then tried to fetch the malicious bot program.</p>
<p>Schiefer admits he and friends used several hjacked PayPal accounts to purchase Web hosting that helped facilitate the spreading of their bot programs. </p></blockquote>
<p>Pretty lame, but most of the infections were done with pre-built AIM tools. This is ultimate script kiddy stuff, but hey I guess it works right.</p>
<p></p>
<p>Source: <a href="http://blog.washingtonpost.com/securityfix/2007/11/security_pro_admits_to_hijacki.html?nav=rss_blog">Washington Post</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=%E2%80%98Security+Consultant%E2%80%99+Caught+for+Running+Large+Bot+Network+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D742+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/&amp;t=%E2%80%98Security+Consultant%E2%80%99+Caught+for+Running+Large+Bot+Network" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/&amp;title=%E2%80%98Security+Consultant%E2%80%99+Caught+for+Running+Large+Bot+Network" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/&amp;title=%E2%80%98Security+Consultant%E2%80%99+Caught+for+Running+Large+Bot+Network" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/&amp;title=%E2%80%98Security+Consultant%E2%80%99+Caught+for+Running+Large+Bot+Network" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/&amp;title=%E2%80%98Security+Consultant%E2%80%99+Caught+for+Running+Large+Bot+Network" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F11%2Fsecurity-consultant-caught-for-running-large-bot-network%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/11/security-consultant-caught-for-running-large-bot-network/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>TimeWarner DNS Hijacking IRC Servers to Stop DDoS Attacks</title>
		<link>http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/</link>
		<comments>http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/#comments</comments>
		<pubDate>Thu, 26 Jul 2007 08:33:52 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[denial-of-service]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dns-hijacking]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[irc-servers]]></category>
		<category><![CDATA[time-warner]]></category>
		<category><![CDATA[timewarner]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/</guid>
		<description><![CDATA[An interesting happening this week, some ISP&#8217;s have been jacking the DNS entries for certain IRC networks to crack down on zombie/bot infections. Is it ethical? Should they be doing this to their users? I first got wind of this from a post on Full Disclosure mailing list from an IRC network administrator. You can [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>An interesting happening this week, some ISP&#8217;s have been jacking the DNS entries for certain IRC networks to crack down on zombie/bot infections.</p>
<p>Is it ethical? Should they be doing this to their users?</p>
<p>I first got wind of this from a post on Full Disclosure mailing list from an IRC network administrator.</p>
<p>You can read that e-mail here:</p>
<p><a href="http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/55016">Major ISPs arbitrarily blocking IRC and hijacking DNS entries</a></p>
<blockquote><p>Internet service provider Cox Communications is reportedly diverting attempts to reach certain online chat channels and redirecting them to a server that attempts to remove spyware from the computer.  By doing so the company seems to be attempting to cleanse computers of malware that hijacks the computers resources to send spam and participate in online service attacks as part of a large network of compromised computers known as a botnet. </p>
<p>Specifically, Cox&#8217;s DNS server is responding to a domain name request for an Internet Relay Chat server. Instead of responding with the correct IP address for the server, Cox sends the IP address of its own IRC server (70.168.70.4).  That server then sends commands to the computer that attempt to remove malware. </p></blockquote>
<p>They seem to run some kind of script when the user connects to try and &#8216;clean&#8217; the machine from infection&#8230;.even if it&#8217;s not infected.</p>
<p>IRC is still used heavily, I don&#8217;t really use it much anymore apart from Freenode. The Darknet channel used to be on DALnet back in the day.</p>
<p>Freenode is pretty happening for open source projects though.</p>
<blockquote><p>Though clever, the tactic is being heavily debated by networking experts on the NANOG mailing list, some of whom question the effectiveness of the technique and who question whether blocking access to the channels for all users (by breaking the DNS protocol) in order to stop some malware is the appropriate solution. Cox does not seem to be blocking all IRC channels, but anyone trying to reach those channels using Cox&#8217;s DNS servers will be unable to reach them.</p>
<p>IRC channels are heavily used by programmers, non-traditional communities and black-hat hackers, among others.  The malware-infected zombie computers Cox is attempting to clean can also be controlled remotely by having them connect to an IRC channel where they get instructions from their controller.</p></blockquote>
<p>Interesting stuff eh?</p>
<p>I&#8217;m not really sure where I stand ethically on this&#8230;what about you?</p>
<p></p>
<p>Source: <a href="http://blog.wired.com/27bstroke6/2007/07/isp-seen-breaki.html">Wired Blog</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D644+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;t=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/&amp;title=TimeWarner+DNS+Hijacking+IRC+Servers+to+Stop+DDoS+Attacks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F07%2Ftimewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/07/timewarner-dns-hijacking-irc-servers-to-stop-ddos-attacks/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Bot Infections Surges to 1.2 Million</title>
		<link>http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/</link>
		<comments>http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/#comments</comments>
		<pubDate>Fri, 27 Apr 2007 05:32:02 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[bot-infections]]></category>
		<category><![CDATA[bots]]></category>
		<category><![CDATA[email-spam]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[securityfocus]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[spam-filter]]></category>
		<category><![CDATA[spam-filtering]]></category>
		<category><![CDATA[spammers]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/</guid>
		<description><![CDATA[I have noticed an increase in Spam activity lately, especially in Spam blog comments there has been a noticeable surge in the frequency and number. That&#8217;s why we&#8217;ve implemented stricter measures against spammers on Darknet and our other sites. It seems there has been a big raise in the number of bot infected systems, so [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I have noticed an increase in Spam activity lately, especially in Spam blog comments there has been a noticeable surge in the frequency and number.</p>
<p>That&#8217;s why we&#8217;ve implemented stricter measures against spammers on Darknet and our other sites.</p>
<p>It seems there has been a big raise in the number of bot infected systems, so it&#8217;s suggested you ramp up your anti-spam filters and get ready for the onslaught.</p>
<blockquote><p>The number of compromised computers that are part of a centrally controlled bot net has tripled in the past two weeks, according to data gathered by the Shadowserver Foundation, a bot-net takedown group.</p>
<p>The weekly tally of bot-infected PCs tracked by the group rose to nearly 1.2 million this week, up from less than 400,000 infected machines two weeks ago. The surge reversed a sudden drop in infected systems&#8211;from 500,000 to less than 400,000&#8211;last December.</p></blockquote>
<p>A pretty big change in the numbers.</p>
<blockquote><p>The threat to Internet users from bot nets has steadily increased over the past few years. Increasingly, computer systems in China have become infected with bot software and used to attack or spam other targets, according to the latest Internet Security Threat Report published by Symantec, the owner of SecurityFocus. Spammers have taken a shine to bot nets as a way to reliably send stock-touting e-mail campaigns and other mass mailings of junk advertisements. Worms are rapidly being replaced by Trojan horse programs, such as the misnamed Storm Worm, that use a bot net to spam out more copies of the malicious code.</p></blockquote>
<p>As far as I know the stats are collected by <a href="http://www.darknet.org.uk/2006/06/shadowserver-battles-the-botnets/">Shadowserver</a>, the guys who are battling the botnets.</p>
<p>Wonder how many of these hosts are Linux based machines, I guess not many.</p>
<p></p>
<p>Source: <a href="http://www.securityfocus.com/brief/466">Security Focus</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Bot+Infections+Surges+to+1.2+Million+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D530+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/&amp;t=Bot+Infections+Surges+to+1.2+Million" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/&amp;title=Bot+Infections+Surges+to+1.2+Million" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/&amp;title=Bot+Infections+Surges+to+1.2+Million" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/&amp;title=Bot+Infections+Surges+to+1.2+Million" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/&amp;title=Bot+Infections+Surges+to+1.2+Million" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F04%2Fbot-infections-surges-to-12-million%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/04/bot-infections-surges-to-12-million/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hackers Attack Root Servers and Slow Internet Key Traffic</title>
		<link>http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/</link>
		<comments>http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/#comments</comments>
		<pubDate>Mon, 26 Mar 2007 08:08:05 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[denial-of-service]]></category>
		<category><![CDATA[dns-attack]]></category>
		<category><![CDATA[dns-hacking]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[hacking-root-dns]]></category>
		<category><![CDATA[root-dns]]></category>
		<category><![CDATA[root-server-attack]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/</guid>
		<description><![CDATA[Well at least it shows the Internet is not very susceptible to such attacks due to its distributed nature, even if the root nameservers are down, the DNS system still functions. This was a pretty heavy attack though and the most significant in the past 5 years or so, someone testing their ego I guess. [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Well at least it shows the Internet is not very susceptible to such attacks due to its distributed nature, even if the root nameservers are down, the DNS system still functions.</p>
<p>This was a pretty heavy attack though and the most significant in the past 5 years or so, someone testing their ego I guess.</p>
<p><em>I CAN H4XOR YOUR INTERWEBNETS!</em></p>
<blockquote><p>The attack, which began Tuesday at about 5:30 a.m. Eastern time, was the most significant attack against the root servers since an October 2002 distributed denial of service (DDOS) attack, said Ben Petro, senior vice president of services with Internet service provider Neustar. Root servers manage the Internet&#8217;s Domain Name System (DNS), used to translate Web addresses such as Amazon.com into the numerical IP addresses used by machines.</p></blockquote>
<p>Thankfully the Internet didn&#8217;t crash, if it did I&#8217;d be very sad!</p>
<blockquote><p>&#8220;Two of the root servers suffered badly, although they did not completely crash; some of the others also saw heavy traffic,&#8221; said John Crain, chief technical officer with the Internet Corporation for Assigned Names and Numbers (ICANN), in an e-mail interview</p>
<p>The two hardest-hit servers are maintained by the U.S. Department of Defense and ICANN, he added.</p>
<p>The botnet briefly overwhelmed these servers with useless requests, causing them to occasionally hang, but did not disrupt Internet service, Petro said. By 10:30 a.m., Internet service providers were able to filter enough of the traffic from the botnet machines that traffic to and from the root servers was essentially back to normal. </p></blockquote>
<p>It seems the attack wasn&#8217;t that strong and they managed to filter it out, it was in terms of MB rather than GB frequently seen in modern DDoS attacks.</p>
<p>It was just very focused, targeting only the root servers.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2007/020707-hackers-slow-internet-root-servers.html?fsrc=rss-security">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers+Attack+Root+Servers+and+Slow+Internet+Key+Traffic+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D483+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/&amp;t=Hackers+Attack+Root+Servers+and+Slow+Internet+Key+Traffic" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/&amp;title=Hackers+Attack+Root+Servers+and+Slow+Internet+Key+Traffic" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/&amp;title=Hackers+Attack+Root+Servers+and+Slow+Internet+Key+Traffic" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/&amp;title=Hackers+Attack+Root+Servers+and+Slow+Internet+Key+Traffic" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/&amp;title=Hackers+Attack+Root+Servers+and+Slow+Internet+Key+Traffic" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F03%2Fhackers-attack-root-servers-and-slow-internet-key-traffic%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/03/hackers-attack-root-servers-and-slow-internet-key-traffic/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Up to a Quarter of Internet Connected Machines Could be Zombies</title>
		<link>http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/</link>
		<comments>http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/#comments</comments>
		<pubDate>Tue, 20 Mar 2007 07:37:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[internet-security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/</guid>
		<description><![CDATA[It&#8217;s a scary thought to find out perhaps a quarter of Internet connected machines could be zombies&#8230;The sad part is, I think it could well be true, as most of the non tech savvy Internet users I know still use Internet Exploder and their machines are riddled with crapware, trojans, viruses and spyware. Imagine how [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It&#8217;s a scary thought to find out perhaps a quarter of Internet connected machines could be zombies&#8230;The sad part is, I think it could well be true, as most of the non tech savvy Internet users I know still use Internet Exploder and their machines are riddled with crapware, trojans, viruses and spyware.</p>
<p>Imagine how many Internet enabled PC&#8217;s there are&#8230;</p>
<blockquote><p>Criminals controlling millions of personal computers are threatening the internet&#8217;s future, experts have warned.</p>
<p>Up to a quarter of computers on the net may be used by cyber criminals in so-called botnets, said Vint Cerf, one of the fathers of the internet.</p>
<p>Technology writer John Markoff said: &#8220;It&#8217;s as bad as you can imagine, it puts the whole internet at risk.&#8221;</p>
<p>The panel of leading experts was discussing the future of the internet at the World Economic Forum in Davos.</p></blockquote>
<p>The Internet was not built to be resilient to such things, there&#8217;s an inherent problem with the Internet and the level of education and awareness of the average Internet user. </p>
<p>Before AOL there was a certain intellectual barrier to getting online, it wasn&#8217;t that straight forwards and required a little bit of grey matter.</p>
<p>Now it&#8217;s SO easy to get online&#8230;.the average intelligence of Internet users has dropped dramatically.</p>
<blockquote><p>Mr Cerf, who is one of the co-developers of the TCP/IP standard that underlies all internet traffic and now works for Google, likened the spread of botnets to a &#8220;pandemic&#8221;.</p>
<p>Of the 600 million computers currently on the internet, between 100 and 150 million were already part of these botnets, Mr Cerf said</p>
<p>Botnets are made up of large numbers of computers that malicious hackers have brought under their control after infecting them with so-called Trojan virus programs. </p></blockquote>
<p>And yes, you guessed it&#8230;one of the main problems is our good friend Microsoft and their lovely secure Windows.</p>
<p>Plus on top of that, the proliferation of pirated copies of Windows, pressed pirated CD&#8217;s of Windows Vista are already available in China and probably other places like Malaysia and Thailand too.</p>
<p>A shocking 50% of these pirated versions come with Trojans pre-installed.</p>
<blockquote><p>Operating systems like Microsoft Windows, meanwhile, still made it too easy for criminals to infiltrate them, the experts said.</p>
<p>Microsoft had done a good job improving security for its latest operating system, Windows Vista, said Mr Markoff.</p>
<p>But already pirated copies of Vista were circulating in China, even though the consumer launch of Vista has been scheduled for next Tuesday.</p>
<p>Experience showed that about 50% of all pirated Windows programs came with Trojans pre-installed on them, Mr Markoff said.</p></blockquote>
<p>Ah what to do, just protect yourself and educate those you can be bothered to listen you.</p>
<p>We&#8217;ll just let the rest of the world screw themselves up.</p>
<p></p>
<p>Source: <a href="http://news.bbc.co.uk/2/hi/business/6298641.stm">BBC News</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Up+to+a+Quarter+of+Internet+Connected+Machines+Could+be+Zombies+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D472+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/&amp;t=Up+to+a+Quarter+of+Internet+Connected+Machines+Could+be+Zombies" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/&amp;title=Up+to+a+Quarter+of+Internet+Connected+Machines+Could+be+Zombies" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/&amp;title=Up+to+a+Quarter+of+Internet+Connected+Machines+Could+be+Zombies" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/&amp;title=Up+to+a+Quarter+of+Internet+Connected+Machines+Could+be+Zombies" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/&amp;title=Up+to+a+Quarter+of+Internet+Connected+Machines+Could+be+Zombies" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F03%2Fup-to-a-quarter-of-internet-connected-machines-could-be-zombies%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/03/up-to-a-quarter-of-internet-connected-machines-could-be-zombies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BeEF &#8211; Browser Exploitation Framework</title>
		<link>http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/</link>
		<comments>http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/#comments</comments>
		<pubDate>Sun, 01 Oct 2006 12:16:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[BEEF]]></category>
		<category><![CDATA[bindshell]]></category>
		<category><![CDATA[browser-exploitation]]></category>
		<category><![CDATA[Browser-Hacking]]></category>
		<category><![CDATA[browser-security]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking-framework]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[zombies]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/</guid>
		<description><![CDATA[There&#8217;s been a lot of nice Web relevant testing and hacking tools coming out lately, I&#8217;ve gotten quite a collection to post about, so do try them out and let me know what you think. BeEF is the browser exploitation framework. Its purposes in life is to provide an easily integratable framework to demonstrate the [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There&#8217;s been a lot of nice Web relevant testing and hacking tools coming out lately, I&#8217;ve gotten quite a collection to post about, so do try them out and let me know what you think.</p>
<p>BeEF is the browser exploitation framework. Its purposes in life is to provide an easily integratable framework to demonstrate the impact of browser and cross-site scripting issues in real-time. The modular structure has focused on making module development a trivial process with the intelligence existing within BeEF.</p>
<p>The current version is 0.2.1 and is still a work in progress.</p>
<p><strong>Modules Loaded</strong></p>
<p>The &#8216;Load Modules&#8217; area shows what modules are available. Clicking on them will load the module into the module console area. The modules are the parts of the application that provide code to be sent to the controlled browser. One of the main strengths of BeEF is the ease in with modules can be written. The require minimal effort to incorporate into the framework.</p>
<p>The module console area shows the modules input and configuration details. The following screenshot show the input options for the Port Scanning Module.</p>
<p><strong>Zombies</strong></p>
<p>The &#8216;Zombies&#8217; section of the sidebar displays basic details of the browser(s) under control of BeEF. All modules will execute within the zombies listed here.</p>
<p><strong>Download</strong></p>
<p>You can download BeEF here:</p>
<p></p>
<p><a href="http://www.bindshell.net/tools/beef/beef-v0.3.1.tgz">beef-v0.3.1.tgz</a> (md5sum: 8e160e72c7b9f1c292b5894d6b8d672c)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=BeEF+%E2%80%93+Browser+Exploitation+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D341+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/&amp;t=BeEF+%E2%80%93+Browser+Exploitation+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/&amp;title=BeEF+%E2%80%93+Browser+Exploitation+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/&amp;title=BeEF+%E2%80%93+Browser+Exploitation+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/&amp;title=BeEF+%E2%80%93+Browser+Exploitation+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/&amp;title=BeEF+%E2%80%93+Browser+Exploitation+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F10%2Fbeef-browser-exploitation-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/10/beef-browser-exploitation-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

