<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>IRC-Junkie.org - IRC News &#187; DDoS</title>
	<atom:link href="http://www.irc-junkie.org/tag/ddos/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.irc-junkie.org</link>
	<description>All about Internet Relay Chat</description>
	<lastBuildDate>Sun, 27 Nov 2011 23:50:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<atom:link rel='hub' href='http://www.irc-junkie.org/?pushpress=hub'/>
<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/de/</creativeCommons:license>		<item>
		<title>GeekShed suffers from DDoS</title>
		<link>http://www.irc-junkie.org/2010-04-26/geekshed-suffers-from-ddos/</link>
		<comments>http://www.irc-junkie.org/2010-04-26/geekshed-suffers-from-ddos/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 15:16:32 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Botnets/DDoS]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Networks]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[GeekShed]]></category>
		<category><![CDATA[Scum]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=970</guid>
		<description><![CDATA[GeekShed, the "free to use and family-friendly Internet Relay Chat network", is currently suffering from a large scale DDoS attack that cripples their infrastructure consisting of 15 servers.

Even though those servers are in datacentres that offer DDoS-protection and are hosted with a number of large backbones they cannot seem to withstand the sheer volume ...<p><a href="http://www.irc-junkie.org/2010-04-26/geekshed-suffers-from-ddos/">GeekShed suffers from DDoS</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-04-08/majority-of-junk-traffic-consists-of-ddos-targetted-at-irc-servers/' rel='bookmark' title='Permanent Link: Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers'>Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers</a></li>
<li><a href='http://www.irc-junkie.org/2005-03-06/ddoser-of-irc-network-arrested/' rel='bookmark' title='Permanent Link: DDoS&#8217;er of IRC network arrested'>DDoS&#8217;er of IRC network arrested</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-05/jay-r-echouafni-on-the-run/' rel='bookmark' title='Permanent Link: Jay R. Echouafni on the run'>Jay R. Echouafni on the run</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.geekshed.net/">GeekShed</a>, the <em>&#8220;free to use and family-friendly Internet Relay Chat network&#8221;</em>, is currently suffering from a large scale DDoS attack that cripples their infrastructure consisting of 15 servers.</p>
<p>Even though those servers are in datacentres that offer DDoS-protection and are hosted with a number of large backbones they cannot seem to withstand the sheer volume of ICMP and UDP traffic directed at them.</p>
<p>Some of the servers have been null-routed by the hosting providers, others have been null-routed by GeekShed staff to <em>&#8220;prevent damage to other machines and customers&#8221;</em> according to network owner <em>Phil</em>.</p>
<p>The cause, as usual, seems to be a disgruntled user that has been banned from <em>Chris Pirillo&#8217;s</em> channel <em>#chris</em> who then engaged in spamming the channel with floodbots and after the channel staff has put a stop to the spamming, resorted to throwing large volumes of traffic at the servers using a botnet.</p>
<p>Since its split from the <em>Wyldryde</em> network, this is the second time somebody felt the necessity to bombard the network with junk traffic after being banned from <em>#chris</em>, however that miscreant was put to jail-time after the incident.</p>
<div id="attachment_980" class="wp-caption aligncenter" style="width: 430px"><a href="http://www.irc-junkie.org/wp-content/uploads/GeekShed_DDoS_Outtage_Graph1.png"><img class="size-full wp-image-980" title="Netsplit.de Graph showing outtages on GeekShed" src="http://www.irc-junkie.org/wp-content/uploads/GeekShed_DDoS_Outtage_Graph1.png" alt="Netsplit.de Graph showing outtages on GeekShed" width="420" height="123" /></a><p class="wp-caption-text">Netsplit.de Graph showing outtages on GeekShed</p></div>
<p>GeekShed staff are currently trying to sort out the situation and are working on restoring service for their users but since there is only so much one can do on the receiving end of a DDoS attack, service will be <em>&#8220;intermittent&#8221;</em> as <a href="http://www.geekshed.net/2010/04/denial-of-service/"><em>Phil </em>has posted on GeekSheds official website</a>.</p>
<p><em>Note: At the time of publishing it seems the network is back in normal operation.</em></p>
<p><!--Digiprove_Start--><span style="vertical-align:middle; display:inline-table; padding:3px; line-height:normal;border:1px solid #bbbbbb;background-color:#FFFFFF;" title="certified 27 April 2010 18:22:08 UTC by Digiprove certificate P15279" ><a href="http://www.digiprove.com/show_certificate.aspx?id=P15279;guid=JduHZ0b4uUWPK2A9RHzTIA" style="text-decoration:none" target="_blank" style="border:0px; float:none; display:inline; text-decoration: none;background-color:#FFFFFF;"><img src="http://www.digiprove.com/images/dp_seal_trans_16x16.png" style="vertical-align:middle; display:inline; border:0px; margin:0px; float:none; background-color:transparent" border="0"/><span style="font-family: Tahoma, MS Sans Serif; font-size:11px; color:#636363; border:0px; float:none; display:inline; text-decoration:none; letter-spacing:normal" onmouseover="this.style.color='#A35353';" onmouseout="this.style.color='#636363';">&nbsp;&nbsp;Copyright secured by Digiprove</span></a><!--D3D81EABAEABC34DE1809DA49A47E76A9BA87157AF6D6EC848805A71DBB8E958--></span><!--Digiprove_End--></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=970&amp;md5=c7ca6a29cf846b2f98857b32a61cfc19" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-04-26/geekshed-suffers-from-ddos/">GeekShed suffers from DDoS</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-04-08/majority-of-junk-traffic-consists-of-ddos-targetted-at-irc-servers/' rel='bookmark' title='Permanent Link: Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers'>Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers</a></li>
<li><a href='http://www.irc-junkie.org/2005-03-06/ddoser-of-irc-network-arrested/' rel='bookmark' title='Permanent Link: DDoS&#8217;er of IRC network arrested'>DDoS&#8217;er of IRC network arrested</a></li>
<li><a href='http://www.irc-junkie.org/2004-11-05/jay-r-echouafni-on-the-run/' rel='bookmark' title='Permanent Link: Jay R. Echouafni on the run'>Jay R. Echouafni on the run</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-04-26/geekshed-suffers-from-ddos/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Australian ISPs unite to disconnect botnet zombies</title>
		<link>http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/</link>
		<comments>http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 18:37:29 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Botnets/DDoS]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Scum]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=748</guid>
		<description><![CDATA[Yesterday a group consisting of major Australian ISPs - amongst them are Optus, Telstra, Vodafone, AAPT, Virgin, Hutchison 3G as well as Facebook, Google and Microsoft - announced that they prepare "a voluntary industry code to come into force this year" which could mean that "Computers infected with viruses could be "expelled" from the ...<p><a href="http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/">Australian ISPs unite to disconnect botnet zombies</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2005-11-09/australian-isps-hunt-down-zombies/' rel='bookmark' title='Permanent Link: Australian ISP&#8217;s Hunt Down Zombies'>Australian ISP&#8217;s Hunt Down Zombies</a></li>
<li><a href='http://www.irc-junkie.org/2006-03-22/australian-man-charged-with-ddos-to-irc-networks/' rel='bookmark' title='Permanent Link: Australian Man Charged with DDoS to IRC Networks'>Australian Man Charged with DDoS to IRC Networks</a></li>
<li><a href='http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/' rel='bookmark' title='Permanent Link: Another 100.000 Zombies Botnet bust'>Another 100.000 Zombies Botnet bust</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Yesterday a group consisting of major Australian ISPs &#8211; amongst them are Optus, Telstra, Vodafone, AAPT, Virgin, Hutchison 3G as well as Facebook, Google and Microsoft &#8211; <a href="http://www.theaustralian.com.au/news/call-to-cut-net-link-on-virus-hit-computers/story-e6frg6n6-1225823060022">announced</a> that they prepare <em>&#8220;a voluntary industry code to come into force this year&#8221; </em>which could mean that <em>&#8220;Computers infected with viruses could be &#8220;expelled&#8221; from the internet&#8221;.</em></p>
<p>The <em>Internet Industry Association</em>, which is made up of over 200 ISP and IT-related companies, is preparing that code in response to an ultimatum of the federal government.</p>
<p>Even though similar efforts <a href="http://www.irc-junkie.org/2005-11-09/australian-isps-hunt-down-zombies/">have been reported in the past</a>, Australia advanced to be #3 regarding botnet activity worldwide &#8211; only beaten by the U.S. and China. Interestingly, Australia wasn&#8217;t even to be found in the Top10 of McAfee&#8217;s Global Threat report 2 years ago</p>
<p>The sheer abundance of potential victims also explains why it is relatively cheap &#8211; <a href="http://blog.trendmicro.com/sdbot-irc-botnet-continues-to-make-waves/#ixzz0ZPTHBlIz">25$ per install</a> &#8211; to get malware such as fake anti-virus solutions installed on Australian computers.</p>
<p>The internet industry&#8217;s voluntary code of conduct is being pushed by the federal Department of Broadband, Communications and the Digital Economy which wants to make the ISPs contact offending customers first before stepping up to more drastic measures like reducing the customers speed or changing their password so they have to contact the helpdesk.</p>
<p>As a last resort, the customers connection will be terminated if they fail to clean up the infection in a given timeframe.</p>
<p>If this gets done right it could very well mean a new era for all of us, meaning less spam, DDoS and other common nuisances found on todays internet.</p>
<p>What do you think about that? Should other countrys follow suit?</p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=748&amp;md5=aa005eb28b720ff17d87f823c23d6f13" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/">Australian ISPs unite to disconnect botnet zombies</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2005-11-09/australian-isps-hunt-down-zombies/' rel='bookmark' title='Permanent Link: Australian ISP&#8217;s Hunt Down Zombies'>Australian ISP&#8217;s Hunt Down Zombies</a></li>
<li><a href='http://www.irc-junkie.org/2006-03-22/australian-man-charged-with-ddos-to-irc-networks/' rel='bookmark' title='Permanent Link: Australian Man Charged with DDoS to IRC Networks'>Australian Man Charged with DDoS to IRC Networks</a></li>
<li><a href='http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/' rel='bookmark' title='Permanent Link: Another 100.000 Zombies Botnet bust'>Another 100.000 Zombies Botnet bust</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Freenode under DDoS</title>
		<link>http://www.irc-junkie.org/2009-12-15/freenode-under-ddos/</link>
		<comments>http://www.irc-junkie.org/2009-12-15/freenode-under-ddos/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 20:49:50 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Botnets/DDoS]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Networks]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[freenode]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=670</guid>
		<description><![CDATA[What many have suspected has now been confirmed - the root cause of the many netsplits on the freenode IRC network during the last days have been caused by ongoing DDoS attacks on their sponsors.

Freenode staffer JonathanD writes in their blogpost that they are experiencing a "heavy DDoS against several locations at which some ...<p><a href="http://www.irc-junkie.org/2009-12-15/freenode-under-ddos/">Freenode under DDoS</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2009-12-08/freenode-issues/' rel='bookmark' title='Permanent Link: Freenode issues'>Freenode issues</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-08/majority-of-junk-traffic-consists-of-ddos-targetted-at-irc-servers/' rel='bookmark' title='Permanent Link: Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers'>Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers</a></li>
<li><a href='http://www.irc-junkie.org/2009-01-30/happy-15th-birthday-freenode/' rel='bookmark' title='Permanent Link: Happy 15th Birthday, freenode!'>Happy 15th Birthday, freenode!</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>What many have suspected has now <a href="http://blog.freenode.net/2009/12/december-15th-ddos/">been confirmed</a> &#8211; the root cause of the many netsplits on the freenode IRC network during the last days have been caused by ongoing DDoS attacks on their sponsors.</p>
<p>Freenode staffer <em>JonathanD</em> writes in their blogpost that they are experiencing a <em>&#8220;heavy DDoS against several locations at which some of our servers are hosted. The attack is ongoing and cause a lot of disruption, both to users of the network and unfortunately to projects/companies/individuals whos infrastructure is hosted at the same locations as us&#8221; </em>but also writes that they are <em>&#8220;working hard to try curb the attacks as best they can.&#8221;</em></p>
<p>He also writes that they will keep their staffblog updated on the issues and recommends that <em>&#8220;users of the network will also be able to receive (infrequent) status updates via global notice and slightly more frequent updates via wallops for those who have chosen to go +w (<strong>/umode +w</strong> or <strong>/mode yournick +w</strong>) will enable wallops in your irc client should you wish to see these.&#8221;</em></p>
<p>In closing he apologizes for &#8220;<em>the inconvenience this no doubt causes for you and your project(s) and we would like to thank you all (in particular, our very generous and dedicated sponsors) for the patience and support while the issues are still ongoing.&#8221;</em></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=670&amp;md5=f969368971f208b1c337d1219ddbebe8" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2009-12-15/freenode-under-ddos/">Freenode under DDoS</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2009-12-08/freenode-issues/' rel='bookmark' title='Permanent Link: Freenode issues'>Freenode issues</a></li>
<li><a href='http://www.irc-junkie.org/2008-04-08/majority-of-junk-traffic-consists-of-ddos-targetted-at-irc-servers/' rel='bookmark' title='Permanent Link: Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers'>Majority of Junk Traffic Consists of DDoS Targetted at IRC Servers</a></li>
<li><a href='http://www.irc-junkie.org/2009-01-30/happy-15th-birthday-freenode/' rel='bookmark' title='Permanent Link: Happy 15th Birthday, freenode!'>Happy 15th Birthday, freenode!</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2009-12-15/freenode-under-ddos/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>psyb0t &#8211; A stealthy router-based botnet discovered [Updated]</title>
		<link>http://www.irc-junkie.org/2009-03-22/psyb0t-a-stealthy-router-based-botnet-discovered/</link>
		<comments>http://www.irc-junkie.org/2009-03-22/psyb0t-a-stealthy-router-based-botnet-discovered/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 14:37:44 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Botnets/DDoS]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[DroneBL]]></category>
		<category><![CDATA[psyb0t]]></category>

		<guid isPermaLink="false">http://www.irc-junkie.org/?p=599</guid>
		<description><![CDATA[The folks at DroneBL discovered and analyzed a router-based botnet that is suspected to have DDoS'ed them for about 2 weeks.

The bot software, named "psyb0t", is the "first known botnet based on exploiting consumer network devices, such as home routers and cable/dsl modems".

Exploiting routers is in some cases more "useful" than infecting PC's - ...<p><a href="http://www.irc-junkie.org/2009-03-22/psyb0t-a-stealthy-router-based-botnet-discovered/">psyb0t &#8211; A stealthy router-based botnet discovered [Updated]</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-05-22/new-zealand-botnet-master-arrested/' rel='bookmark' title='Permanent Link: New Zealand Botnet Master Arrested'>New Zealand Botnet Master Arrested</a></li>
<li><a href='http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/' rel='bookmark' title='Permanent Link: Another 100.000 Zombies Botnet bust'>Another 100.000 Zombies Botnet bust</a></li>
<li><a href='http://www.irc-junkie.org/2009-12-15/irc-controlled-botnet-sdbot-is-still-going-strong/' rel='bookmark' title='Permanent Link: IRC-controlled botnet SDBot is still going strong'>IRC-controlled botnet SDBot is still going strong</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>The folks at DroneBL discovered and analyzed a router-based botnet that is suspected to have DDoS&#8217;ed them for about 2 weeks.</p>
<p>The bot software, named <strong><em>&#8220;psyb0t&#8221;</em></strong>, is the <em>&#8220;first known botnet based on exploiting consumer network devices, such as home routers and cable/dsl modems&#8221;</em>.</p>
<p>Exploiting routers is in some cases more &#8220;useful&#8221; than infecting PC&#8217;s &#8211; because <em>&#8220;most people will keep the router on 24/7&#8243;</em> as opposed to their computers which <em>&#8220;most people shut down [...] in the evening before they go to bed, or when they leave the office&#8221; nenolod</em> writes.<br />
In <a href="http://nenolod.net/~nenolod/router-malware.pdf">his paper</a> (which was written back in 2006 and at that time he&#8217;s been<em> &#8220;called looney for&#8221;</em>) he also mentions another reason why targeting SOHO routers is a good idea:</p>
<blockquote><p><em>Attacking the router will enable you to monitor network activity with a much higher level of stealth. As most people think the router is a dumb device which simply does NAT translation, it will not be considered a device with a high security risk. Most intrusion analysts at this time will not even consider the router as the place where the malware is hiding.</em></p></blockquote>
<p><em>nenolod</em>, <a href="http://www.adam.com.au/bogaurd/">amongst others</a>, disassembled and analyzed the botnet binary, coming to the conclusion that the current incarnation we&#8217;re seeing now <em>&#8220;was mostly a test botnet&#8221;.</em> <em>&#8220;Terry Baume discovered the first generation, which only targeted a handful of specific models. The current generation, would be the second generation, which targets a much wider range of devices&#8221;.</em></p>
<p>Version 17 of the malware contains <em>&#8220;shellcode for 30 different linksys models, and 10 netgear models, as well as several kinds of cable and dsl modems (15 different shellcodes)&#8221;</em> as well as a list of <em>&#8220;6000 usernames and 13000 passwords&#8221; </em>which is used for bruteforcing Telnet and SSH logins that are open to the LAN and sometimes even on the WAN side of those routers.</p>
<p>His efforts to shutdown the Command&amp;Control channel the bot uses have been successful and the DNS, which has been hosted with afraid.org, has been nullrouted. In a conversation held on IRC he also mentions that the <em>&#8220;current version is version 18, but he </em>[the author - ed.]<em> has changed the way he obfuscates the executable&#8221;</em> which formerly was packed using the <a href="http://upx.sourceforge.net/">UPX packer</a>.</p>
<p>The now defunct C&amp;C  was suspected to control <em>&#8220;100,000 hosts at the moment, but the ircd does not give us any information&#8221;</em>. The bot in its current incarnation does <em>&#8220;hijack DNS for rapidshare&#8221;</em> and <em>&#8220;phishes login info&#8221;</em> which leads <em>nenolod</em> to believe it is more of a proof-of-concept right now and is going to grow more sophisticated in the future. Asked about the origin of the worm he says that several traces point to Australia being the country of origin and given some <a href="http://forums.whirlpool.net.au/forum-replies.cfm?t=1164229">reports of increased telnet activity there</a> he could be right.</p>
<p>The bot is able to scan for vulnerable PHPMyAdmin and MySQL installations, contains an update function and the usual flooding functionality. It also disables access to the routers control interfaces using iptables rules, denying access to the ports 22, 23 and 80. Also, he notes that the bot is <em>&#8220;not linux-specific, a couple of the routers we have seen in the botnet are running <a href="http://en.wikipedia.org/wiki/VxWorks">VxWorks</a>&#8220;</em>.</p>
<p>Detecting the bot isn&#8217;t easy since you&#8217;d need to capture and analyze the traffic it sends and receives to find out if you are infected &#8211; which is impossible if the infected device does not have dedicated USB/Ethernet ports to configure them and it then <em>&#8220;would require monitoring at the CMTS or DSLAM&#8221;</em> level.</p>
<p>In his posting on the DroneBL blog <em>nenolod</em> writes that they <em>&#8220;are looking into finding out more information about this botnet, and its controller. If you have any information, we would like to know.&#8221;</em></p>
<p>Update and patch your routers so they don&#8217;t swallow a blue pill <img src='http://www.irc-junkie.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>Update:</strong></p>
<p>The botnet apparently has been shutdown by it&#8217;s owner:</p>
<pre>* Now talking on #mipsel
* Topic for #mipsel is: .silent on .killall .exit ._exit_ .Research is over:
 for those interested i reached 80K. That was fun <img src='http://www.irc-junkie.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> , time to get back to the real life... (To the DroneBL guys:
 I never DDOSed/Phished anybody or peeked on anybody's private data for that matter)
* Topic for #mipsel set by DRS at Sun Mar 22 17:02:15 2009</pre>
<p><em>nenolod</em> writes in their blog:</p>
<blockquote><p>While this information may or may not be true, we have received HTTP-based floods from IPs participating in this botnet.</p>
<p>We are still interested in this DRS person. If you have any information, please provide it to DroneBL. We will not disclose our sources.</p></blockquote>
<p>Further reading:</p>
<p><a href="http://www.dronebl.org/blog/8">http://www.dronebl.org/blog/8</a></p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=599&amp;md5=8e38f37e44caf8d889b00a82c7d7c395" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2009-03-22/psyb0t-a-stealthy-router-based-botnet-discovered/">psyb0t &#8211; A stealthy router-based botnet discovered [Updated]</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2008-05-22/new-zealand-botnet-master-arrested/' rel='bookmark' title='Permanent Link: New Zealand Botnet Master Arrested'>New Zealand Botnet Master Arrested</a></li>
<li><a href='http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/' rel='bookmark' title='Permanent Link: Another 100.000 Zombies Botnet bust'>Another 100.000 Zombies Botnet bust</a></li>
<li><a href='http://www.irc-junkie.org/2009-12-15/irc-controlled-botnet-sdbot-is-still-going-strong/' rel='bookmark' title='Permanent Link: IRC-controlled botnet SDBot is still going strong'>IRC-controlled botnet SDBot is still going strong</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2009-03-22/psyb0t-a-stealthy-router-based-botnet-discovered/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Another 100.000 Zombies Botnet bust</title>
		<link>http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/</link>
		<comments>http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 19:02:49 +0000</pubDate>
		<dc:creator>phrozen77</dc:creator>
				<category><![CDATA[Botnets/DDoS]]></category>
		<category><![CDATA[IRC]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[DDoS]]></category>

		<guid isPermaLink="false">http://dev.irc-junkie.org/?p=14</guid>
		<description><![CDATA[Yesterday, the creator of a Botnet consisting of more than 100.000 Zombies has been arrested. The 19-year old Dutch and his 16-year old brother are said to be the botmasters of what once was a botnet peaking 150.000 compromised hosts...

Also arrested was a 35-year old Brazilian that wanted to buy the botnet for his ...<p><a href="http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/">Another 100.000 Zombies Botnet bust</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>



Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/' rel='bookmark' title='Permanent Link: Australian ISPs unite to disconnect botnet zombies'>Australian ISPs unite to disconnect botnet zombies</a></li>
<li><a href='http://www.irc-junkie.org/2008-05-22/new-zealand-botnet-master-arrested/' rel='bookmark' title='Permanent Link: New Zealand Botnet Master Arrested'>New Zealand Botnet Master Arrested</a></li>
<li><a href='http://www.irc-junkie.org/2005-10-08/zombie-network-rolled-up-in-netherlands-upt/' rel='bookmark' title='Permanent Link: Zombie Network Rolled Up in Netherlands (upt)'>Zombie Network Rolled Up in Netherlands (upt)</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Yesterday, the creator of a Botnet consisting of more than 100.000 Zombies has been arrested. The 19-year old Dutch and his 16-year old brother are said to be the botmasters of what once was a botnet peaking 150.000 compromised hosts&#8230;</p>
<p>Also arrested was a 35-year old Brazilian that wanted to buy the botnet for his malicious activities &#8211; at the price of 25.000€ (US$37.290). The bust was a cooperation between the Dutch High Tech Crime unit and other international forces such as the F.B.I.</p>
<p>The botnet spread on Windows Live Messenger without the help of exploits but using a social engineering approach.</p>
<p>Would-be victims received a message from friends on their contactlist with a link and were asked to click on it &#8211; once infected they would then message their friends.</p>
<p>If you suspect to be zombified, one way to spot an infected machine is to check it for outgoing connections to the host &#8220;elena.ccpower.ru&#8221; on port 3306.</p>
<p>Antivirus company Kaspersky has put together a <a href="http://www.kaspersky.com/shadowbot">webpage</a> with information on how to get rid of the bot &#8211; it however is advised to perform a full system scan with AV as well as spyware scanners since Shadow possibly also installed adware on the victims computer.</p>
 <p><a href="http://www.irc-junkie.org/?flattrss_redirect&amp;id=14&amp;md5=e01cbce20b7b032203e66f4cf35c2fa8" title="Flattr" target="_blank"><img src="http://www.irc-junkie.org/wp-content/plugins/flattrss/img/flattr-badge-large.png" alt="flattr this!"/></a></p><p><a href="http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/">Another 100.000 Zombies Botnet bust</a> is a post from: <a href="http://www.irc-junkie.org">IRC-Junkie.org - IRC News</a>
<br><br>

This post is licensed under the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/de/">Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Deutschland</a> license.</p>
<p class="wp-flattr-button"></p>

<p>Related posts:<ol><li><a href='http://www.irc-junkie.org/2010-01-26/australian-isps-unite-to-disconnect-botnet-zombies/' rel='bookmark' title='Permanent Link: Australian ISPs unite to disconnect botnet zombies'>Australian ISPs unite to disconnect botnet zombies</a></li>
<li><a href='http://www.irc-junkie.org/2008-05-22/new-zealand-botnet-master-arrested/' rel='bookmark' title='Permanent Link: New Zealand Botnet Master Arrested'>New Zealand Botnet Master Arrested</a></li>
<li><a href='http://www.irc-junkie.org/2005-10-08/zombie-network-rolled-up-in-netherlands-upt/' rel='bookmark' title='Permanent Link: Zombie Network Rolled Up in Netherlands (upt)'>Zombie Network Rolled Up in Netherlands (upt)</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.irc-junkie.org/2008-08-15/another-100000-zombies-botnet-bust/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

