Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 22 guests and 4 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Incident Responsearrow MS06-040 Botnets
Ethical Hacker Community Forums
January 09, 2009, 03:34:02 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: MS06-040 Botnets  (Read 3491 times)
0 Members and 1 Guest are viewing this topic.
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« on: August 31, 2006, 06:16:12 PM »

Anybody else see any significant activity?

We had quite abit and had to block access to 7 different IRC servers, most in Korea but some in China. It was based off of Rbot and issued commands to have the infected computers scan on both 139 and 445 for targets. It also spread via open or weak shares. The funny thing is that it had a rootkit component which was probably the easiest rootkit to remove that I've ever seen. It didn't make that many reg changes and was zapped instantly by our AV. Overall, it wasn't hardly able to do any damage to the machines, however did generate alot of noisy scan activity. Another unique thing about this bot was that it was running its IRC on channel on port 443 to try to hide in the normal SSL traffic, but it stood out like a sore thumb. ISC is reporting an NT version of this, however I'm thinking that its just a target of opportunity because its no longer supported. Hope you don't have any NT still running :-)
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #1 on: August 31, 2006, 08:39:19 PM »

if you have NT running, you are just plain wrong...
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
tmartin
Recruiters
Newbie
*
Offline Offline

Posts: 46


View Profile
« Reply #2 on: September 05, 2006, 06:06:12 AM »

Then many businesses are dead wrong. Some systems won't run on upgraded OSes. NT will be around for at least another 5 years. Until the systems go down due to an attack.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2442


Editor-In-Chief


View Profile WWW
« Reply #3 on: September 05, 2006, 09:59:19 AM »

In my work at the university, we have a number of labs that are attached to older lab equipment that simply won't run on anything newer than NT. But the equipment still does viable work for the investigators. To mitigate problems, we have removed their NICs. They complain and insist that internet access is crucial. When we explain that it's either no network or no lab results, we quickly learn how internet access was optional and not essential.

So yes, there are still some valid uses of NT, but you have to be careful out there.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #4 on: September 05, 2006, 02:48:38 PM »

Then many businesses are dead wrong. Some systems won't run on upgraded OSes. NT will be around for at least another 5 years. Until the systems go down due to an attack.

yes those business are dead wrong and they shouldnt be on the net

Don, takes the right approach if you have a system that only runs on NT it shouldnt be on the net. 

guess i should have been a little more specific in my reply.  believe me i understand, work had to pay a couple of thousand dollars to have some build a "new" 486 P2 computer because the software would only run on Windows 98!  i didnt say NT wasnt useful but running any unsupported OS is a bad idea, IMO, from a security standpoint.  especially if they are tied to internal or trusted networks.  there are safe ways to do it but most people probably dont.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.048 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.