Penetration Testing mailing list archives

Re: Botnets


From: "M.D.Mufambisi" <mufambisi () gmail com>
Date: Tue, 31 Mar 2009 17:49:35 +0200

Im not sure i get what you are saying. Do you want me to tell you
where i got the bot from? Is this allowed on this forum?

On 3/31/09, Rafael Torrales Levaggi <rtorrales () novared cl> wrote:
Maybe you should include the botnet that included information about warez
allocated. They used to be a .dll who worked with serv-u ftp server, it logs
in a irc channel and publish stats about the dump and its warez.

Rafael Torrales Levaggi
Analista de Seguridad
Teléfono: (56-2) 499-9090 | Fax: (56-2) 203-3180
e-mail: rtorrales () novared cl

-----Mensaje original-----
De: listbounce () securityfocus com [mailto:listbounce () securityfocus com] En
nombre de sr.
Enviado el: Friday, March 27, 2009 12:03 PM
Para: M.D.Mufambisi
CC: pen-test () securityfocus com
Asunto: Re: Botnets

The botnets will log into a usually private IRC channel, (as a bot)
and start issuing commands. IRC is also used to distribute links to
personal information that the botnets gather. Like, dishing out
compromised credit card numbers. These channels are usually by invite
only, or require a key.

fabrizio

On Wed, Mar 25, 2009 at 1:52 AM, M.D.Mufambisi <mufambisi () gmail com> wrote:
Hi Guys.

Can someone please explain to me how botnets use IRC? I want to make a
presentation to my group demonstrating this in my lab which comprises
of 4 winxp boxes. Unpatched. How are commands issued via IRC?

Kind regards,

Munyaradzi

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

Tired of using other people's tools? Why not learn how to write your own
exploits? InfoSec Institute's Advanced Ethical Hacking class teaches you
how to write stack and heap buffer overflow exploits for Windows and
Linux. Gain your Certified Expert Penetration Tester (CEPT) cert as well.

http://www.infosecinstitute.com/courses/advanced_ethical_hacking_training.html
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

No time or budget for traveling to a training course in this fiscal year?
Check out the online penetration testing courses available at InfoSec
Institute. More than a boring "talking head", train in our virtual labs for
a total hands-on training experience. Get the certs you need as well: CEH,
CPT, CEPT, ECSA, LPT.

http://www.infosecinstitute.com/request_online_training.html
------------------------------------------------------------------------



------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

No time or budget for traveling to a training course in this fiscal year? Check out the online penetration testing 
courses available at InfoSec Institute. More than a boring "talking head", train in our virtual labs for a total 
hands-on training experience. Get the certs you need as well: CEH, CPT, CEPT, ECSA, LPT.

http://www.infosecinstitute.com/request_online_training.html
------------------------------------------------------------------------


Current thread: