EricR23 | 13 years ago | on: How I Wrote a Book in 3 Days
EricR23's comments
EricR23 | 13 years ago | on: Have you ever chatted with a hacker within a virus?
EricR23 | 13 years ago | on: Have you ever chatted with a hacker within a virus?
EricR23 | 13 years ago | on: Have you ever chatted with a hacker within a virus?
EricR23 | 13 years ago | on: Have you ever chatted with a hacker within a virus?
EricR23 | 13 years ago | on: Have you ever chatted with a hacker within a virus?
EricR23 | 13 years ago | on: Have you ever chatted with a hacker within a virus?
One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~10K botnet. I spent hours running a packet sniffer and seeing how the client interacted with the IRC network it called home to. Upon connecting to the privately run IRC network, the bot would authenticate with a user and pass. I assume it created one upon connecting the first time to the network. My best guess as to why this is is so that the bot master could track the total number of zombies and compare it to how many were actively connected to the botnet. Kind of a cleaver way to get metrics, now that I think about it.
When I temporarily stopped the bot from connecting to IRC, I decided it might be fun to login as the bot and join the channel I saw it connecting to. Upon joining the channel, I saw thousands of other users on the channel. I spent a couple of days sitting there, masquerading myself as a bot, and watching the botmaster interact with the bots. The botmaster would issue commands that I can't really recall anymore, but I do remember seeing a lot of commands that I assumed told the bots to download extra malware from a remote host. I remember seeing URLs for zip and exe files.
Eventually I got a little bored of this, so I decided to message the botmaster. It was easy to spot him; out of the three ops on the channel, he was the only full op. I tried a "hello" and waited. And waited. And then I was k-lined from the IRC network.
The next day when I logged onto my computer, I found my Internet connectivity was being overwhelmed with bogus TCP requests. I had pissed off the botmaster by snooping, and now I was getting DDoS'd. I imagine he/she commandeered a small number of the bots to do this. It wouldn't take many... I imagine back then, given my bandwidth, 10-15 would have done it.
Fun times. I remember posting about my botnet adventures to Security Focus way back when. Some people got really interested and followed my posts, while other professionals asked me to stop because I wasn't running a sandbox.
IMO, those were different times. I'm not sure I'd recommend something like this these days. After hearing about certain botnets being tied to various mafias and gangs around the world (which is probably more common than you think. See http://www.ibtimes.co.uk/articles/321149/20120329/mafia-cont...), I'm not sure I'd really want to risk interfering with their activities.
EricR23 | 14 years ago | on: Barack Obama Directs All Federal Agencies to Have an API
EricR23 | 14 years ago | on: Show HN: movies.io — torrent search like it should be
EricR23 | 14 years ago | on: Ruby 1.9 lands NaCl support, can run in Chrome
EricR23 | 14 years ago | on: New PHP Vulnerability:?-s may expose source code for mod_cgi
EricR23 | 14 years ago | on: Fake S3 – Save time, money, and develop offline
EricR23 | 14 years ago | on: Awesome jQuery File Upload
EricR23 | 14 years ago | on: Pebble E-Paper Watch Raises $1M In 28 Hours
EricR23 | 14 years ago | on: Try right clicking GitHub's logo
EricR23 | 14 years ago | on: Caller ID Made Simple
EricR23 | 14 years ago | on: An HN style social news site written in Ruby/Sinatra/Redis/JQuery by Antirez
EricR23 | 14 years ago | on: Ask HN: Review my startup - GiftBait.com
EricR23 | 14 years ago | on: JQuery 1.6.2 syntax error? You may be the victim of SEO.
EricR23 | 15 years ago | on: CIA.gov Possibly Down, LulzSec Claims Responsibility