Re: what protocol

"Keith" <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <001401c3a825$87773a20$0200a8c0@laptop>
We're getting hit by it too,
the bot uses a random nick and also the port is random
so I dont know how you could get bopm to scan for it.
We have obtained the list of servers that we believe it uses - if anyone
is interested weve made the list available
http://www.tscnow.com/Fyleserverlist.txt

The only stratergy we have at the moment is to set channels to +s so they
wont display in a /list and thus they are invisible to the bot

I dont really think scanning for Trojans is something that bopm is designed
to
do. Its purpose is to detect open proxies. Tho it is interesting to note
this
particular trojan also functions as a bnc server with no password so
in effect it is like an open proxy ? . One of our security staff obtained
the following
information when telneting to the IP and port given by the bot

bash-2.05b# telnet 217.165.64.241 1984
Trying 217.165.64.241...
Connected to 217.165.64.241.
Escape character is '^]'.
:x 002 :3Welcome to Backdoor BnC by Fyle
:x 002 :3Use /con <server> [port] to connect
:x 002 :3Currently 0 BnC users online

Keith
http://www.tscnow.com


----- Original Message ----- 
From: "TS Lee" <[email protected]>
To: <[email protected]>
Sent: Tuesday, November 11, 2003 5:33 PM
Subject: [bopm] what protocol


> Greetings
>
> We are getting slammed by a new trojan/spam virus bot, much like the
> MsCleo virus that
> went around a few months ago. Anyone have a patch or know what to set the
> bopms to scan for?
>
> <\_|> Come watch me on my webcam and chat /w me :-)
> http://027.c.004.mel.iprimus.net.au:1188/me.mpg
>
> I tried setting http:1188 but so far they pass all the bopms
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.