Archive for 'Botnets'
Sanctioning Services
(The following was prepared in response to a recent invitation to describe “two dangerous but common security mistakes companies make”)
Rather than looking at this in terms of mistakes, I’d rather take this as a chance to describe two simple things network administrators can do to have an immediate positive impact on data security:
1) Don’t get [...]
Posted: September 30th, 2007 under Botnets, Content Mgmt.
Comments: none
DNSbot Servers
Not long ago, it was fairly simple to decommission even largely distributed botnets serving up web content (e.g. online-pharmacies, cheap software) by reporting the abuse to the DNS provider. In an effort to build more robust botnets, the botmasters have responded by adding DNS servers to their armies.
Browse to your EmailSecurity junkbox and have a [...]
Posted: May 9th, 2007 under Botnets.
Comments: none
Search engines the new security vendors?
NewScientist has a good article on the evolution of Botnet infestations, reinforcing the need for Web Application Firewalls to protect against injection attacks.
Seeing a publication like NewScientist providing coverage to this topic suggests an expanded set of minds offering consideration to this problem. The research paper cited in the article was produced by Google (not [...]
Posted: May 9th, 2007 under Botnets, Content Mgmt, WebApp Sec.
Comments: none
Zombie Master Masquerade
The Metaeye Security group (bonus points for not capitalizing the “e” in “eye”) have released ZmbScap (Zombie Scapper), a Perl script designed to detect and disable various zombie DDoS tools (including Stacheldraht, Wintrinoo, Mstream, Tribal Flood Network, Trinoo, Shaft, Trinitinty, and Entitee). It achieves this by attempting to issue a kill command to the infected [...]
Posted: February 22nd, 2007 under Botnets, Remediation.
Comments: none
Botnet Estimates
As if the previously cited estimate wasn’t bad enough, now Vint Cerf (the man who lives in Al Gore’s shadow) submits that of the 600 million internet connected machines, 150 million (1/4) are infected, active members of botnets.
It’s clear that we can’t expect individual users to defend themselves, let alone to clean-up this situation. ISPs [...]
Posted: January 29th, 2007 under Botnets, Stats.
Comments: none
