Page 1 of 1

Botnets

Posted: Tue Jan 06, 2009 7:55 am
by Provant
Someone threatened to DDoS me with a botnet? Does that even make sense LOOOOOOOOOL, oh noez my computerz gunna be slow for a few dayz, oo god grow a set. LOOOOOOL

Re: Botnets

Posted: Tue Jan 06, 2009 2:14 pm
by BerryTheWest
Provant wrote:Someone threatened to DDoS me with a botnet? Does that even make sense LOOOOOOOOOL, oh noez my computerz gunna be slow for a few dayz, oo god grow a set. LOOOOOOL
If they do, then you can just use WireShark and gain evidence and the information of internet protocol address and block them.

Don't waste time making a topic when solution is simple. Either prepare yourself or ignore a threat.

Posted: Tue Jan 06, 2009 5:52 pm
by athlete501
uh actually more can happen when you're dos/ddos'd...it simply crashes the system...which is a very vulnerable time..if they're good they can inject backdoors and what not without being detected. otherwise your internet not only will not be slow..but if it works..you just wont be able to use it

Posted: Wed Jan 07, 2009 12:21 am
by PaRaDoX
athlete501 wrote:uh actually more can happen when you're dos/ddos'd...it simply crashes the system...which is a very vulnerable time..if they're good they can inject backdoors and what not without being detected. otherwise your internet not only will not be slow..but if it works..you just wont be able to use it
you can call your isp while its happening and they have all the info about your connections, wireshark not required, the evidence will already be with them as well.

Posted: Wed Jan 07, 2009 2:25 am
by athlete501
well you understand that the hacker controls the bots via irc, right?...soo they'll get the irc server and then they have to get a log of who was on that channel at that time..then if the hacker used a proxy/vpn..more hassle is needed to discover the hacker

Posted: Wed Jan 07, 2009 3:23 am
by PaRaDoX
athlete501 wrote:well you understand that the hacker controls the bots via irc, right?...soo they'll get the irc server and then they have to get a log of who was on that channel at that time..then if the hacker used a proxy/vpn..more hassle is needed to discover the hacker
true, but a quick investigation on each victim's comp reveals the hacker. of course, leave that to the police.

Posted: Wed Jan 07, 2009 3:34 am
by BerryTheWest
athlete501 wrote:well you understand that the hacker controls the bots via irc, right?...soo they'll get the irc server and then they have to get a log of who was on that channel at that time..then if the hacker used a proxy/vpn..more hassle is needed to discover the hacker
Incorrect

They can create their own communication and that call socket programming.
So they don't always control bots via irc.

Posted: Wed Jan 07, 2009 11:31 pm
by PaRaDoX
BerryTheWest wrote:
athlete501 wrote:well you understand that the hacker controls the bots via irc, right?...soo they'll get the irc server and then they have to get a log of who was on that channel at that time..then if the hacker used a proxy/vpn..more hassle is needed to discover the hacker
Incorrect

They can create their own communication and that call socket programming.
So they don't always control bots via irc.

lol@ first word. not like "thats not quite right", just INCORRECT. XD hits so much harder :3

Posted: Wed Jan 07, 2009 11:44 pm
by athlete501
waiiit a second...there's a difference between ddosing from one computer
and commanding a botnet to do it

if one computer ddos's..they're sending packets through more than one connection (instead of one which would just be dos'ing)

if a computer commands a botnet to do it...you have SEVERAL computers doing what that one computer was doing...but regardless..you're not going to get the commanders ip unless you netstat on one of the "slaves" and see where the command is coming from (which would work if they're directly sending the command..if through irc..it wont work..you'd have to again go to the irc server and get the ip logged in)

Posted: Fri Jan 09, 2009 12:37 am
by PaRaDoX
athlete501 wrote:waiiit a second...there's a difference between ddosing from one computer
and commanding a botnet to do it

if one computer ddos's..they're sending packets through more than one connection (instead of one which would just be dos'ing)

if a computer commands a botnet to do it...you have SEVERAL computers doing what that one computer was doing...but regardless..you're not going to get the commanders ip unless you netstat on one of the "slaves" and see where the command is coming from (which would work if they're directly sending the command..if through irc..it wont work..you'd have to again go to the irc server and get the ip logged in)
my exact point. find the slaves ip / isp, contact the isp, tell them to do the netstat on that computer while it happens and see what comes up.

Posted: Fri Jan 09, 2009 2:19 am
by athlete501
oh i thought you meant his own computer lol sorry