Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here:
EH-Net
May 19, 2013, 06:11:55 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Should I be worried? CandC server  (Read 3210 times)
0 Members and 1 Guest are viewing this topic.
t3st
Newbie
*
Offline Offline

Posts: 3


View Profile
« on: December 17, 2012, 05:48:15 AM »

Hi there,
I have scanned the wi-fi in my workplace and have come across this connection:
CandC (00:**:7f:**:d6:**)
[WPS ESS]
[WPA-PSK-TKIP]
Ch 6 2437mhz

I have googled CandC server and worryingly came across this:
"A botnet's originator (known as a "bot herder" or "bot master") can control the group remotely, usually through an IRC, and often for criminal purposes. This server is known as the command-and-control (C&C) server."
So is this CandC server I have found something to worry about?
Please can you advise if there are innocent CandC servers or always related to botnets?
Thanks for your time,
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #1 on: December 17, 2012, 08:01:35 AM »

Without more information, I would have a hard time telling you that THIS particular machine you've listed is a C and C botnet controller / host, or simply a machine going by that name.  I fact, I have my doubts that it is, at least, solely from the information you've given us, thus far.  A name, alone, means little.

That said...

What tool did you use to 'scan' the wireless?  Where did you come by the name, "CandC"?  Can you, at least, give us the first set of MAC address numbers that you left out (between the 00 and 7F) so that we can see who makes the adapter (assuming it's MAC wasn't altered)?  What ports does it have open, etc?  We have VERY little information, here, to even begin to tell you anything about this box.

Let's assume, for instance, that it IS a C and C botnet box.  I'd be hard pressed to think the code would 'advertise' itself as C and C, as usually, they wouldn't want to be detected.  It's more likely just a chosen name that someone gave this box.  What I'd recommend / propose, is that you take the hostname and IP address, give it to IS&T (unless that's you), at your workplace, and let them find said machine and investigate it.  If your work has wifi, then it would be assumed that someone there would be capable of locating the box in question.  If not, I think it's time they contract someone who can.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #2 on: December 17, 2012, 09:34:00 PM »

I wonder if someone named it CandC, meaning CNC.
Logged

OSWP, Sec+
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #3 on: December 17, 2012, 10:11:22 PM »

Honestly wondered the same, but as there's been no further reply / info given...
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
t3st
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #4 on: December 18, 2012, 04:45:27 AM »

Hi there, thank you for your replies.

I didn't want to put down to much information, as if it was innocent, I would be posting details of an actual server on a public forum. I am in the "recon" stage of my learning and have been reading about how network admins make the mistake of doing this, so I was careful not to do the same.
I was using an android app called wi-fi analyser, but the CandC doesn't appear on another app called Network discovery (that brings up so many ip add's of computers, servers and mobile phones).

I have notfied our DBA.
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1630



View Profile
« Reply #5 on: December 18, 2012, 05:58:44 AM »

OK.  Well, if further info comes up, or more specific questions arise, we'll see what help we can provide, at that time.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
t3st
Newbie
*
Offline Offline

Posts: 3


View Profile
« Reply #6 on: December 18, 2012, 08:29:34 AM »

Thanks Hayabusa

rgds
Logged
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #7 on: December 19, 2012, 04:36:04 AM »

t3st,

assuming by wifi analyser you mean the wireless tool by Farpoc?

I use the same tool, as it's essentially a wireless spectrum analyser similar to aircrack/kismet/etc, My guess is CandC is merely a SSID of a neighbouring AP and (hopefully) not a direct threat to your environment.
Logged

chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #8 on: December 19, 2012, 09:59:05 AM »

I'm using the one by Farpoc, but other than finding access points, I haven't noticed it doing some of the same things of air crack or Kisment. Those don't just show the access points, but end points too.

The nice thing about Wifi Analyser, it helps you find the least congested channel.
Logged

OSWP, Sec+
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #9 on: December 20, 2012, 12:10:39 PM »

Maybe it's for multiplayer Command and Conquer games.

Legitimate attackers would probably be more discreet. I'm personally more suspicious of "Free WiFi" SSIDs Wink
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.073 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.