Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 24 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow need a complt tutorial about designing botnets
Ethical Hacker Community Forums
January 07, 2009, 09:44:25 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: 1 2 [3]   Go Down
  Print  
Author Topic: need a complt tutorial about designing botnets  (Read 12215 times)
0 Members and 1 Guest are viewing this topic.
dean
Full Member
***
Offline Offline

Posts: 130


View Profile
« Reply #30 on: December 17, 2007, 06:51:37 AM »

themadhatter, Yes a lot do get away with it but there are successes too.

Have a look at the FBI's Botroast & Botroast II. The shadowserver team shut down C&C Servers on a regular basis.

Remember that the server(s) controlling the bots are really just another host that is 'told' to act as a server and not a zombie, so the server could be anywhere in the world and likely is just another home users machine.

Additionally, some countries have very (read: non-existent) lax laws as to computer based crime. Hosting a malware server or malicious website used to infect users is not illegal. The Russian Business Network (RBN) have gotten away with this for years. Although recently they did move their servers.

There is also the issue of collaboration between the various law enforcement agencies in the different countries. All this takes time and is difficult to coordinate.

dean
Logged

<script>alert('%52%54%46%4D')</script>
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #31 on: December 19, 2007, 06:18:52 AM »

actually my conception is not cleared in IRC botnets...can you please tell me about that..


and i heared that if sum1 is tacing storm bot then the bot automatically dossed his/her system..is it rite actually???
Logged
dean
Full Member
***
Offline Offline

Posts: 130


View Profile
« Reply #32 on: December 19, 2007, 06:55:31 AM »

Proudindian, what are you not sure about when it come to IRC-based botnets? 

You're correct about the stormworm DDoS'ing people tracing it's activity and spread. It tracks the source IP and downloads of the malware and duration between downloads. So if you're going to script the downloads of the malware then make sure that you randomize time between downloads.

dean
Logged

<script>alert('%52%54%46%4D')</script>
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #33 on: January 05, 2008, 09:03:02 AM »

hey people again in this topic,

I am not geting it,please help,actually i got it how botnet works and what they do and what it is actually,thanx for all of this,now my problem is i am not getting it with irc,actually i was looking in deans post,that google search code,but not geting how actually that code will work wid irc?

i mean how bots actually work with irc?Huh?please help...
Logged
dean
Full Member
***
Offline Offline

Posts: 130


View Profile
« Reply #34 on: January 05, 2008, 10:58:18 AM »

proudindian,

Here is a brief explanation of how a C&C IRC botnet works:

Once a host has been compromised and a new botclient has been created, the client will initiate communications with the Command & Control server. The client will join an IRC server (which can also be hosted anywhere).

The client will normally upload information into the channel about the compromised host as well. It then waits for commands to be issued through the channel.

For example: The botherder wants to DDoS a specific site for a customer. The botherder will send a command to some or all of the bots in the channel to DDoS the victim. That command could take the form of:

!ddos {target} {duration} {ddos type}

Each bot will then respond to those commands and initiate a denial of service attack against the target. After completing the attack the botclients will report back to the C&C server.

Today the botnets are far more complex and use far different mechanisms to communicate and remain active.

With regards to the perl code I posted about a bot that could do google lookups. That bot would be connected to an IRC server using the following command:

perl bot.pl {server}{port}{channel}

Once in the channel the bot will listen for commands such as:

!google {term}

It will then parse the results and display the first couple of urls. This is not a malicious bot and is really used to provide extra functionality in a channel. BTW the code I posted is not complete.

dean
Logged

<script>alert('%52%54%46%4D')</script>
proudindian
Newbie
*
Offline Offline

Posts: 32


View Profile
« Reply #35 on: January 05, 2008, 11:11:52 AM »

hmmm,dean thanx man you really helped me a lot,.
Logged
Pages: 1 2 [3]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.049 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.