Features Podcasts Family Video Comics Music Tech Science Books Film & TV Games ✚

Jill

Botmasters include fake control interface to ensnare security researchers

Cory Doctorow at 8:17 am Fri, Nov 5, 2010

— FEATURED —

Book Review

Black Code: how spies, cops and crims are making cyberspace unfit for human habitation

Book Review

We Can Fix it! - a graphic novel time travel memoir

Science

The technology that links taxonomy and Star Trek

— FOLLOW US —

Boing Boing is on Twitter and Facebook. Subscribe to our RSS feed or daily email.

 

— POLICIES —

Except where indicated, Boing Boing is licensed under a Creative Commons License permitting non-commercial sharing with attribution

 

— FONTS —

Tweet
Kindle
Security researchers compromised what they believed to be a control server for the Zeus botnet, but after examining it in detail, they concluded that it was a fake, designed to allow botmasters to spy on security researcher tactics and plan countermeasures.

What particularly stands out about the EFTPS exploit toolkit is their admin interface. Note that it's common for most exploit toolkits to contain an admin interface that manages exploits, payloads, and tracks exploit success rates. However, the EFTPS exploit toolkit contains a completely fake admin console. This admin interface acts as a "hacker honeypot" that records detailed information about who attempted to access the admin console, as well as who attempted to hack into it. The fake login system conveniently accepts default/easily guessed credentials and common SQL injection strings...

Finally, notice that the user can also upload "new bot" malware, which is also logged. This should serve as a warning to researchers, don't always believe what you see on these stats pages...

Statistics Don't Lie... Or Do They? (via The Inquirer)
  • Time-lapse of botnet's spread around the world
  • Fighting spam with captured botnet hosts
  • Arrests made in "Mariposa" botnet that infected 13 million PCs ...
  • Botnet runners start their own ISPs
  • Have botnet prices crashed?
  • StormWorm botnet lashes out at security researchers
  • FBI nabs "Iserdo" the 23-yr-old Slovenian "Botnet" bandit - Boing ...
  • 1.4GB of personal data recovered from botnet server

I write books. My latest is a YA science fiction novel called Homeland (it's the sequel to Little Brother). More books: Rapture of the Nerds (a novel, with Charlie Stross); With a Little Help (short stories); and The Great Big Beautiful Tomorrow (novella and nonfic). I speak all over the place and I tweet and tumble, too.

MORE:  Technology

More at Boing Boing

The technology that links taxonomy and Star Trek

Hackers prepare for first "national holiday" in their honor

  • Andrew P.

    That’s what I wanted you to think, but it was in fact just a bot impersonating a security researcher! I spent the last few years building up an immunity to iocane powder.

  • Squid Tamer

    And then the security people upload a ton of nasty viruses for the botnet operator to find and open.
    No, it’d never work, but a guy can dream, right?

  • Anonymous

    Bot coders build bot interface to test bot busting hackers as they bust bots! http://bit.ly/cW7l8J (I should write headlines for The Sun!)

  • krische

    So the hunter, has be come the hunted.