Re: what protocol
"Keith" <[email protected]>
| Newsgroups | gmane.network.irc.bopm |
|---|---|
| Message-ID | <001401c3a825$87773a20$0200a8c0@laptop> |
We're getting hit by it too, the bot uses a random nick and also the port is random so I dont know how you could get bopm to scan for it. We have obtained the list of servers that we believe it uses - if anyone is interested weve made the list available http://www.tscnow.com/Fyleserverlist.txt The only stratergy we have at the moment is to set channels to +s so they wont display in a /list and thus they are invisible to the bot I dont really think scanning for Trojans is something that bopm is designed to do. Its purpose is to detect open proxies. Tho it is interesting to note this particular trojan also functions as a bnc server with no password so in effect it is like an open proxy ? . One of our security staff obtained the following information when telneting to the IP and port given by the bot bash-2.05b# telnet 217.165.64.241 1984 Trying 217.165.64.241... Connected to 217.165.64.241. Escape character is '^]'. :x 002 :3Welcome to Backdoor BnC by Fyle :x 002 :3Use /con <server> [port] to connect :x 002 :3Currently 0 BnC users online Keith http://www.tscnow.com ----- Original Message ----- From: "TS Lee" <[email protected]> To: <[email protected]> Sent: Tuesday, November 11, 2003 5:33 PM Subject: [bopm] what protocol > Greetings > > We are getting slammed by a new trojan/spam virus bot, much like the > MsCleo virus that > went around a few months ago. Anyone have a patch or know what to set the > bopms to scan for? > > <\_|> Come watch me on my webcam and chat /w me :-) > http://027.c.004.mel.iprimus.net.au:1188/me.mpg > > I tried setting http:1188 but so far they pass all the bopms > >