Re: ssh login attempts...new scan tool? ->MyDoom
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
I have been watching the list for a while and always think that when it comes down to the scanning and intrusions most of them are IRC based or are for use on IRC. There are rootkits that will set up a scanner on a remote machine and will connect back to irc so that people can send them commands through irc. These "scankits" usually are used to scan for Radmin that has been installed with no password. Most people do not know that Radmin installs with no password by default. Many of these new exploits are used for people making botnets. There is talk of some botnets as big as 33,000 pc's using lsass. These botnets are spread by MyDoom, lsass, dcom and many more as many of you must know. Many of the people that make thses bots hang out in irc channel and have websites where anybody (if you can find the site) can download a bot like phatbot or rbot ,compile it and have it going in no time. On the webpages are also bots coded in mIRC that will install anything from a radmin remote scanner to an xdcc server for an IRC channel. These bots should be able to be taken apart to see what and how they do what they do. They seem to come and go as most "underground" sites do. I have started a collection of these bots to take apart and some of them are very advanced. For more information on these sites feel to contact me. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions