Re: IRC DDoS bots

From: Johannes Ullrich (jullrich@euclidian.com)
Date: 03/14/03

  • Next message: Jason Falciola: "Re: Unknown attack, possible trojan?"
    Date: Fri, 14 Mar 2003 12:56:18 -0500
    From: "Johannes Ullrich" <jullrich@euclidian.com>
    To: "grwolf" <grwolf@adelphia.net>
    
    

    O
    > It's another mIRC based DDoS trojan that scans for NT-Password and IIS
    > unicode exploits.
    > So the next questions is... How do we go about apprehending the culprits?
    > Can we somehow get wxmail.net revoked?

    IRC bots are a common plague. We do play 'whack the bot' once in a while
    if we find out about it. So far, I have yet to see a case successfully
    prosecuted.

    The best bet is to call however hosts the IRC server and have them yank
    the server. Be ready to find some resistance and confusion as you talk
    to your first 'tech support' person about IRC bots. Try to get through
    to a security contact.

    It looks like the particular server you where monitoring is no longer
    responding. So maybe they took already care of it.

    Regarding prosecuting: Talk to your local FBI office and see if you can
    get them interested. However, usually they don't bother unless you have
    significant damages (the 'official' threshold of $5,000 is usually no
    enough).

    If whoever is hosting this server is not cooperating, you may want to
    try going for a civil suit. Its probably more promising but you need
    the stomach/money for it.

    If you need any further help, contact me off-list.

     

    -- 
    --------------------------------------------------------------------
    jullrich@euclidian.com             Collaborative Intrusion Detection
                                             join http://www.dshield.org
    ----------------------------------------------------------------------------
    <Pre>Lose another weekend managing your IDS?
    Take back your personal time.
    15-day free trial of StillSecure Border Guard.</Pre>
    <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
    

  • Next message: Jason Falciola: "Re: Unknown attack, possible trojan?"

    Relevant Pages

    • Re: Format of string output of a socket server
      ... What for example does your standard POP3 server send? ... The client program can then convert to Unicode or whatever they see fit? ... I am writing a socket server to deliver telephony events to clients on ... My socket server is currently sending out char*. ...
      (microsoft.public.win32.programmer.networks)
    • Re: MySQL Insert Unicode Problem
      ... I'm trying to insert some data from an XML file into MySQL. ... The database server has to support Unicode, ...
      (comp.lang.python)
    • Re: Unicode Problem
      ... irgendwie bekomme ich das mit dem unicode nicht in den kopf. ... Ich bin relativ neu mit dem Sql Server 2005 - also bitte nicht schlagen ... Mit den codepage einstellungen 65001 und utf-8 in einer ASP seite ...
      (microsoft.public.de.sqlserver)
    • Re: query doesn´t return some hungarian caracters
      ... did you use a field of type nvarchar or ntext for the field ... make sure that your nvarchar string is really OK on the server side ... by using the function Unicode() to print the unicode value of your letters ... Dim lSql As String ...
      (microsoft.public.data.ado)
    • Re: Unicode Attack
      ... Your Snort logs will include everything "odd" (as defined by the ... > web server); however, I cannot rule out the possibility of the host ... That server should not be vulnerable to the Unicode URL encoding ...
      (Incidents)