Login

Username:

Password:

 
Lost Password?
Register now!


Did you know?
What is Key-logger?



Random FAQ
What is soft-keyboard?

Vulnerabilities & Exploits : Evil Trojan twins control most of world's botnets
Posted by glm on 2008/12/22 18:27:34 (41 reads)





By :Clement James


Apr 13, 2007 1:57 PM




Two types of Trojan are responsible for the control of most botnets worldwide, a security firm revealed today.

The Sdbot and Gaobot malware groups were responsible for 80 percent of detections related to bots during the first quarter of 2007, according to PandaLabs. Other culprits, although on a much lesser scale, included Oscarbot, IRCbot or RXbot.

Bots are automated worms or Trojans that install themselves on computers to carry out certain actions automatically, such as sending spam and turning the compromised computers into zombies. Botnets, or networks made up of computers infected with bots, have become a lucrative business model.

"This dominance is not so much due to any special features of Gaobot or Sdbot, but simply because their code is much more widely available on the internet.

This means that any criminals that want to make a bot can simply base it on the source code of these threats, making any modifications they choose. Essentially, this saves them a lot of work," said Luis Corrons, technical director of PandaLabs.

In 2006, bots accounted for 13 percent of all new threats detected by PandaLabs. Of those, 74 percent belonged to the Sdbot and Gaobot families.

Until now, most of them were controlled through IRC servers, which allowed attackers to send orders while hiding behind the anonymity of chat servers, however, now there are bots that can be controlled through web consoles using HTTP.

"Control through IRC is useful for controlling isolated computers. However, this system is not so useful when it comes to botnets. By using HTTP, bot herders can control many more computers at the same time, and can even see when one of them is online or if the commands have been executed correctly," added Corrons.




Source from:Copyright © 2008 vnunet.com







Other articles
2009/2/4 23:20:16 - Cloud computing is a storage spot for malware
2009/2/4 23:20:15 - Microsoft responds to Windows 7 security gripe
2009/2/4 23:20:12 - Web identity hijacking on the rise
2009/2/4 23:20:12 - Google glitch puts surfers in a quandary
2009/2/4 23:20:11 - Facebook plays down privacy concerns
2009/2/4 23:20:10 - Australian Computer Society to use Sophos security solution
2009/2/4 23:20:09 - Google working on fix for clickjacking vulnerability in Chrome
2009/2/4 23:20:08 - McAfee: Malware will use web and USB sticks to spread in 2009
2009/2/4 23:20:07 - With economy in tailspin, Monster discloses major breach
2009/2/4 23:20:06 - OS X 'pirate' trojan resurfaces
2009/2/4 23:20:05 - IE 8 approaching on formal release
2009/2/4 23:20:04 - Companies warned over use of Netbooks
2009/2/4 23:20:03 - Trend Micro signs up with BigFix
2009/2/4 23:17:08 - Banks urged to change security policies
2009/2/4 23:17:08 - Heartland incident provides opportunity to standardise data breach notification laws

The comments are owned by the poster. We aren't responsible for their content.

Articles