Showing posts with label storm botnet. Show all posts
Showing posts with label storm botnet. Show all posts

Monday, March 23, 2009

psyb0t Botnet Targeting Wireless Routers, Wireless DSL Modems

Update:
I was informed that this was discovered by Terry Baume a while ago, 12th January 2009. I have not verified the source. http://www.adam.com.au/bogaurd/PSYB0T.pdf


"psyb0t" botnet
DroneBL DNS Blacklist services is reporting the discovery of "psyb0t" botnet comprising internet modems and routers. It seems that wireless routers and internet modems with WAN accessible management control has fallen victim to botnet. If your router has weak password, it is possible that it is compromised.
Easiest way to detect if your router is affected is the try your web management portal of the router. If you cannot access it, most likely you are affected. This is because according to the current exploit, the worm shuts down web access, telnet and SSL access to the router/modem.
Following information are known so far;

* is the first botnet worm to target routers and DSL modems
* contains shellcode for many mipsel devices
* is not targeting PCs or servers
* uses multiple strategies for exploitation, including bruteforce username and password combinations
* harvests usernames and passwords through deep packet inspection
* can scan for exploitable phpMyAdmin and MySQL servers

This type of botnets are very dangerous as it is very hard for end user to know that her/his router / modem is compromised and this could easily be used as an attack vector for other attacks such as identity theft. The storm botnet we reported is very simple compared to this.
There are reports that the botnet was shutdown and there will be many more such botnet in the future and Please make sure that your routers and modems are protected and that you use strong passwords. Disable remote management from WAN unless you absolutely must have that capacity.
Dronebl (Bookmark this address, might come handy one day)

Friday, November 14, 2008

Spamalytics, Email Based Spam Marketing Analyzed

Storm Botnet
http://snapvoip.blogspot.com/
Researchers from UC Berkeley and University of San Diego have conducted a study on spam based marketing, "Spamalytics: An Empirical Analysis of Spam Marketing Conversion" and come out with very interesting results.
The paper was presented at the 15th ACM conference on Computer and communications security which was held on October 27-31, 2008.
The study was conducted by infiltrating storm botnet and inserting two websites in the botnets link indexes. So the researchers were basically sending you spam, which was harmless, to study how these botnets operate and the profitability in such operations.
The study found that viagra raises the expectations of many and e-greeting cards are good vehicles to deliver botnet agents. Almost half a billion spam emails were sent and it is estimated that around 25% of these reached the users email boxes and actually small fraction of these reached the site. But they did make sales (Pretend) and managed to deliver more bots to the net, again pretend. So the shear number of bots in the stormbonet and based on who is selling what, spam marketting is profitable but not in millions of dollars in a day.
I suggest you read the paper published by researchers that gives a good education on how these spam botnets operate and how our preventive measures work. Even the experts will learn a thing or two.

"Spamalytics: An Empirical Analysis of Spam Marketing Conversion"