Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 53 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow need a complt tutorial about designing botnets
EH-Net
May 23, 2013, 10:59:48 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3]   Go Down
  Print  
Author Topic: need a complt tutorial about designing botnets  (Read 28303 times)
0 Members and 1 Guest are viewing this topic.
dean
Guest
« Reply #30 on: December 17, 2007, 06:51:37 AM »

themadhatter, Yes a lot do get away with it but there are successes too.

Have a look at the FBI's Botroast & Botroast II. The shadowserver team shut down C&C Servers on a regular basis.

Remember that the server(s) controlling the bots are really just another host that is 'told' to act as a server and not a zombie, so the server could be anywhere in the world and likely is just another home users machine.

Additionally, some countries have very (read: non-existent) lax laws as to computer based crime. Hosting a malware server or malicious website used to infect users is not illegal. The Russian Business Network (RBN) have gotten away with this for years. Although recently they did move their servers.

There is also the issue of collaboration between the various law enforcement agencies in the different countries. All this takes time and is difficult to coordinate.

dean
Logged
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #31 on: December 19, 2007, 06:18:52 AM »

actually my conception is not cleared in IRC botnets...can you please tell me about that..


and i heared that if sum1 is tacing storm bot then the bot automatically dossed his/her system..is it rite actually???
Logged
dean
Guest
« Reply #32 on: December 19, 2007, 06:55:31 AM »

Proudindian, what are you not sure about when it come to IRC-based botnets? 

You're correct about the stormworm DDoS'ing people tracing it's activity and spread. It tracks the source IP and downloads of the malware and duration between downloads. So if you're going to script the downloads of the malware then make sure that you randomize time between downloads.

dean
Logged
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #33 on: January 05, 2008, 09:03:02 AM »

hey people again in this topic,

I am not geting it,please help,actually i got it how botnet works and what they do and what it is actually,thanx for all of this,now my problem is i am not getting it with irc,actually i was looking in deans post,that google search code,but not geting how actually that code will work wid irc?

i mean how bots actually work with irc?Huh?please help...
Logged
dean
Guest
« Reply #34 on: January 05, 2008, 10:58:18 AM »

proudindian,

Here is a brief explanation of how a C&C IRC botnet works:

Once a host has been compromised and a new botclient has been created, the client will initiate communications with the Command & Control server. The client will join an IRC server (which can also be hosted anywhere).

The client will normally upload information into the channel about the compromised host as well. It then waits for commands to be issued through the channel.

For example: The botherder wants to DDoS a specific site for a customer. The botherder will send a command to some or all of the bots in the channel to DDoS the victim. That command could take the form of:

!ddos {target} {duration} {ddos type}

Each bot will then respond to those commands and initiate a denial of service attack against the target. After completing the attack the botclients will report back to the C&C server.

Today the botnets are far more complex and use far different mechanisms to communicate and remain active.

With regards to the perl code I posted about a bot that could do google lookups. That bot would be connected to an IRC server using the following command:

perl bot.pl {server}{port}{channel}

Once in the channel the bot will listen for commands such as:

!google {term}

It will then parse the results and display the first couple of urls. This is not a malicious bot and is really used to provide extra functionality in a channel. BTW the code I posted is not complete.

dean
Logged
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #35 on: January 05, 2008, 11:11:52 AM »

hmmm,dean thanx man you really helped me a lot,.
Logged
Pages: 1 2 [3]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.057 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.