RE: Why attacker install irc after hacking?
- From: "Goran Pizent" <goran.pizent@xxxxxxxxx>
- Date: Fri, 21 Apr 2006 09:05:07 +0200
After they (intruders) install their tools (Trojans, Rootkits etc) on
hacked box, then the usual way to create a Botnet (where your hacked box is
just one in thousands) is through IRC.
Every Bot notifies its Master of its existance through password protected
IRC channel. On the same IRC channel every bot recieves its orders, e.g.
Distributed Denial of Service Attack on victim, or execute any kind of
attack through owned box/boxes.
Goran
-----Original Message-----
From: Monty Ree [mailto:chulmin2@xxxxxxxxxxx]
Sent: Thursday, April 20, 2006 6:56 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Why attacker install irc after hacking?
Hello, all.
I have operated linux server for a long time.
and I have found that some irc(psybnc etc) related program was installed
after scan or hacking.
I can't understand
Why attackers installed and executed irc program?
Why attackers use irc after hacking?
Just chatting is not...I guess..
Thanks in advance.
_________________________________________________________________
전세계인이 함께하는 웹 메일 서비스인 MSN Hotmail을 만나 보세요.
http://loginnet.passport.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&lc
=1042
-------------------------------------------------------------------------
This List Sponsored by: Webroot
Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise
http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------
-------------------------------------------------------------------------
This List Sponsored by: Webroot
Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise
http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------
- References:
- Why attacker install irc after hacking?
- From: Monty Ree
- Why attacker install irc after hacking?
- Prev by Date: Re: malware block my PC for to enter in internet, possible?
- Next by Date: Re: Why attacker install irc after hacking?
- Previous by thread: Re: Why attacker install irc after hacking?
- Next by thread: Re: Why attacker install irc after hacking?
- Index(es):
Relevant Pages
|
Loading