<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; Hacking</title>
	<atom:link href="http://www.megapanzer.com/tag/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 13:02:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>By the way, Phrack #67 is there!</title>
		<link>http://www.megapanzer.com/2010/12/04/by-the-way-phrack-67-is-there/</link>
		<comments>http://www.megapanzer.com/2010/12/04/by-the-way-phrack-67-is-there/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 15:57:56 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Info]]></category>
		<category><![CDATA[Reading material]]></category>
		<category><![CDATA[ezine]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[phrack]]></category>
		<category><![CDATA[zine]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4834</guid>
		<description><![CDATA[I tweeted it but forgot to tell it here &#8230; Phrack #67 is there. What is Phrack? Phrack is an ezine written by and for hackers, the longest running hacker magazine first published in 1985. Here the TOC Introduction The Phrack Staff Phrack Prophile on Punk The Phrack Staff Phrack World News EL ZILCHO Loopback [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/books-150x150.jpg" alt="" title="books" width="75" height="75" class="alignright size-thumbnail wp-image-2238" />I tweeted it but forgot to tell it here &#8230; Phrack #67 is there.  What is Phrack? Phrack is an ezine written by and for <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hackers</a>, the longest running <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hacker</a> magazine  first published in 1985.<br />
<br/><br />
<br/><br />
Here the TOC<br />
<br/></p>
<table border="0">
<tr height="30">
<td>
<strong>Introduction</strong></td>
<td>The Phrack Staff
</td>
</tr>
<tr height="30">
<td>
<strong>Phrack Prophile on Punk</strong></td>
<td>The Phrack Staff
</td>
</tr>
<tr height="30">
<td>
<strong>Phrack World News</strong></td>
<td>EL ZILCHO
</td>
</tr>
<tr height="30">
<td>
<strong>Loopback (is back)</strong></td>
<td>The Phrack Staff
</td>
</tr>
<tr height="30">
<td>
<strong>How to make it in Prison</strong></td>
<td>TAp
</td>
</tr>
<tr height="30">
<td>
<strong>Kernel instrumentation using kprobes</strong></td>
<td>ElfMaster
</td>
</tr>
<tr height="30">
<td>
<strong>ProFTPD with mod_sql pre-authentication, remote root</strong></td>
<td>FelineMenace
</td>
</tr>
<tr height="30">
<td>
<strong>The House Of Lore: Reloaded ptmalloc v2 &#038; v3: Analysis &#038; Corruption</strong></td>
<td>	blackngel
</td>
</tr>
<tr height="30">
<td>
<strong>A Eulogy for Format Strings</strong></td>
<td>Captain Planet
</td>
</tr>
<tr height="30">
<td>
<strong>Dynamic Program Analysis and Software <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">Exploitation</a></strong></td>
<td>BSDaemon
</td>
</tr>
<tr height="30">
<td>
<strong><a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">Exploiting</a> Memory Corruptions in Fortran Programs Under Unix/VMS</strong></td>
<td>Magma
</td>
</tr>
<tr height="30">
<td>
<strong>Phrackerz: Two Tales</strong></td>
<td>Antipeace &#038; The Analog Kid
</td>
</tr>
<tr height="30">
<td><strong><br />
Scraps of notes on remote <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Stack overflow" target="_blank">stack overflow</a> <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=2563" title="Glossary: Exploit" target="_blank">exploitation</a></strong></td>
<td>pi3
</td>
</tr>
<tr height="30">
<td>
<strong>Notes Concerning The Security, Design and Administration of Siemens DCO-CS</strong></td>
<td>	The Philosopher
</td>
</tr>
<tr height="30">
<td>
<strong>Hacking the mind for fun and profit</strong></td>
<td>lvxferis
</td>
</tr>
<tr height="30">
<td>
<strong>International scenes</strong></td>
<td>various
</td>
</tr>
</table>
<p><br/></p>
<p>Read it <a href="http://www.phrack.com/issues.html?issue=67" target="_blank">here</a>.</p></glossarycode></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/12/04/by-the-way-phrack-67-is-there/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers go head-to-head in first ever cyber sport</title>
		<link>http://www.megapanzer.com/2010/11/27/hackers-go-head-to-head-in-first-ever-cyber-sport/</link>
		<comments>http://www.megapanzer.com/2010/11/27/hackers-go-head-to-head-in-first-ever-cyber-sport/#comments</comments>
		<pubDate>Sat, 27 Nov 2010 13:30:58 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4616</guid>
		<description><![CDATA[Is computer hacking a sport? Should it be rewarded with trophies, awards, and maybe even, jobs? A growing trend points to yes. What used to be a frowned upon and shady underworld of computer hackers is now emerging as a network of professionals that boasts teamwork and helps provide insight into the world of cyber [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-thumbnail wp-image-2595" title="newspaper" src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" width="75" height="75" />Is computer hacking a sport? Should it be rewarded with trophies, awards, and maybe even, jobs? A growing trend points to yes.</p>
<p>What used to be a frowned upon and shady underworld of computer hackers is now emerging as a network of professionals that boasts teamwork and helps provide insight into the world of cyber security.</p>
<p>Bringing computer hacking out of the shadows and into the mainstream, multiple companies from app developers, security firms, and even the federal government have embraced.</p>
<p>Read more <a href="http://www.tgdaily.com/security-features/52682-packetwars-hackers-go-head-to-head-in-first-ever-cyber-sport" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/11/27/hackers-go-head-to-head-in-first-ever-cyber-sport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fishing sensitive data with MioStar</title>
		<link>http://www.megapanzer.com/2010/11/17/fishing-sensitive-data-with-miostar/</link>
		<comments>http://www.megapanzer.com/2010/11/17/fishing-sensitive-data-with-miostar/#comments</comments>
		<pubDate>Wed, 17 Nov 2010 14:31:58 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[C]]></category>
		<category><![CDATA[C#]]></category>
		<category><![CDATA[Coders corner]]></category>
		<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[Crypto]]></category>
		<category><![CDATA[DLL injection]]></category>
		<category><![CDATA[funkction hooking]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hooking]]></category>
		<category><![CDATA[injectin]]></category>
		<category><![CDATA[Passwords]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=4365</guid>
		<description><![CDATA[What is MioStar MioStar is an offspring of the SkypeTrojan. Unlike the SkypeTrojan MioStar puts its focus on hooking functions that deal with sensitive data like account information or network traffic. The initial objective was not to produce a hacker tool ready to use or incorporate in malware. But at the point we reached now [...]]]></description>
			<content:encoded><![CDATA[<h3>What is MioStar</h3>
<p> <img src="http://www.megapanzer.com/wp-content/uploads/code-300x300.jpg" alt="" title="code" width="75" height="75" class="alignright size-medium wp-image-3203" /><br />
MioStar is an offspring of the SkypeTrojan. Unlike the SkypeTrojan MioStar puts its focus on hooking functions that deal with sensitive data like account information or network traffic. The initial objective was not to produce a hacker tool ready to use or incorporate in malware. But at the point we reached now it is more than just a simple proof of concept. We have a nice, fancy GUI now and a handful of preconfigured applications where we can extract sensitive data. And in the future the list will grow.<br />
<br/></p>
<h3>What function calls are intercepted</h3>
<p>Currently the following functions can be intercepted with MioStar &#8230;<br />
</p>
<table width="500" border="0">
<tr valign="top">
<td width="50%">
    <strong>Files</strong></p>
<ul>
<li>CreateFile</li>
<li>ReadFile</li>
<li>WriteFile</li>
</ul>
</td>
<td width="50%" rowspan="4">
     <strong>Crypto</strong></p>
<ul>
<li>CryptEncrypt</li>
<li>CryptDecrypt</li>
<li>CryptHashData</li>
<li>EncryptFile</li>
<li>DecryptFile</li>
<li>NCryptEncrypt</li>
<li>NCryptDecrypt</li>
<li>NCryptCreatePersistedKey</li>
<li>SslEncryptPacket</li>
<li>SslDecryptPacket</li>
<li>BCryptEncrypt</li>
<li>BCryptDecrypt</li>
<li>BCryptHashData</li>
<li>BCryptGenerateSymmetricKey</li>
<li>CPEncrypt</li>
<li>CPDecrypt</li>
<li>CryptProtectData</li>
<li>CryptUnprotectData</li>
<li>CryptProtectMemory</li>
<li>CryptUnprotectMemory</li>
<li>CryptMsgGetParam</li>
<li>CryptMsgUpdate</li>
<li>CryptHashMessage</li>
<li>CryptDecryptMessage</li>
<li>CryptEncryptMessage</li>
<li>nss3.dll::PK11SDR_Encrypt</li>
<li>nss3.dll::PK11SDR_Decrypt</li>
</ul>
</td>
</tr>
<tr valign="top">
<td>
    <strong>Registry</strong></p>
<ul>
<li>RegOpenKey</li>
<li>RegOpenKeyEx</li>
<li>RegQueryValue</li>
<li>RegQueryValueEx</li>
<li>RegGetValue</li>
</ul>
</td>
</tr>
<tr valign="top">
<td>
    <strong>Networking</strong></p>
<ul>
<li>send</li>
<li>WSASend</li>
<li>WSPSendTo</li>
<li>GetAddrInfo</li>
<li>GetAddrInfoEx</li>
<li>WinHttpOpenRequest</li>
<li>WinHttpConnect</li>
<li>WinHttpWriteData</li>
</ul>
</td>
</tr>
<tr valign="top">
<td>
    <strong>System</strong></p>
<ul>
<li>LoadLibrary</li>
<li>LoadLibraryEx</li>
<li>GetProcAddress</li>
<li>GetModuleHandle</li>
<li>GetModuleHandleEx</li>
<li>FreeLibrary</li>
</ul>
</td>
</tr>
</table>
<p><br/></p>
<h3>Which applications use these calls</h3>
<p>MioStar can be used with any application but without guarantee of success. From following applications<br />
sensitive data can be extracted &#8230;</p>
<table width="500"  border="0">
<tr valign="top" height="40">
<td width="50%"><strong>Application name</strong></td>
<td width="50%"><strong>Function</strong></td>
</tr>
<tr valign="top">
<td>Safari</td>
<td>CryptProtectData<br />
	CryptUnprotectData</p>
</td>
</tr>
<tr valign="top">
<td>Chrome</td>
<td>CryptProtectData<br />
	CryptUnprotectData</p>
</td>
</tr>
<tr valign="top">
<td>GoogleTalk</td>
<td>CryptProtectData<br />
	CryptUnprotectData</p>
</td>
</tr>
<tr valign="top">
<td>Microsoft Live Messenger</td>
<td>CryptEncrypt</p>
</td>
</tr>
<tr valign="top">
<td>Microsoft Live Mail</td>
<td>CryptProtectMemory<br />
	CryptUnprotectMemory</p>
</td>
</tr>
<tr valign="top">
<td>Yahoo Messenger</td>
<td>SslEncryptPacke</p>
</td>
</tr>
<tr valign="top">
<td>Thunderbird</td>
<td>
        nss3.dll::PK11SDR_Decrypt<br />
	nss3.dll::PK11SDR_Encrypt</p>
</td>
</tr>
<tr valign="top">
<td>FireFox</td>
<td>
	nss3.dll::PK11SDR_Decrypt<br />
	nss3.dll::PK11SDR_Encrypt</p>
</td>
</tr>
<tr valign="top">
<td>SeaMonkey</td>
<td>
        nss3.dll::PK11SDR_Decrypt<br />
	nss3.dll::PK11SDR_Encrypt</p>
</td>
</tr>
<tr valign="top">
<td>RockMelt</td>
<td>
        CryptProtectData<br />
	CryptUnprotectData</p>
</td>
</tr>
</table>
<p><br/></p>
<h3>Manipulating functions</h3>
<p>Instead of extracting sensitive data you can also manipulate the function arguments and replace the passed values by your own. As an example the function  <strong>GetAddrInfoEx</strong> normally resolves hostnames and gives back the according IP address. Instead of resolving www.google.com replace this parameter by www.megapanzer.com. <strong>All traffic for google gets then redirected to Megapanzer.</strong><br />
<br/></p>
<h3>How can I participate</h3>
<p>You can participate in three ways. If you know of &#8230;</p>
<ul>
<li> applications using one of the functions mentioned in the list above that deal with sensitive data.</li>
<li> Windows functions that handle sensitive data and they are not implemented in MioStar yet.</li>
<li> DLLs providing functions that deal with sensitive data.</li>
</ul>
<p>&#8230; then please drop me a <a href="http://www.megapanzer.com/contact/">mail</a> and let me know.<br />
<br/></p>
<h3>Feedback</h3>
<p>In case you encounter any problems with the tool, you find a bug, you have suggestions to improve it, or you tested it with a Windows version i&#8217;ve not yet tested please drop me an <a href="http://www.megapanzer.com/contact/">email</a>.<br />
<br/></p>
<h3>Where can I download it</h3>
<table border="0">
<tr>
<td>
<img style="background:none; border-top:none; border-left:none;" src="http://www.megapanzer.com/wp-content/uploads/App_DOS.jpg" width="12" height="12" class="alignleft size-full wp-image-4358" />Version 0.1 &#8211; <a href="http://www.megapanzer.com/wp-content/uploads/MioStar_0_1.zip">Binary &#038; source</a>
</td>
</tr>
<tr>
<td>
<img style="background:none; border-top:none; border-left:none;" src="http://www.megapanzer.com/wp-content/uploads/App_WIN.png" width="12" height="12" class="alignleft size-full wp-image-4358" />Version 0.2 &#8211; <a href="http://www.megapanzer.com/wp-content/uploads/MioStar_0_2.zip">Binary &#038; source</a>
</td>
</tr>
</table>
<p><br/></p>
<h3>Why this strange name</h3>
<p>There are many security related tools out there with heroic, martial, elite or marketing strategic, odd sounding names. Why not name a tool something like a household appliance? MioStar is a product line of a Swiss store that offers great products for your household like MioStar mixer, MioStar hair dryer, MioStar vacuum. MioStar, a great name for a tool!<br />
<br/></p>
<h3>MioStar video</h3>
<p>Will follow soon &#8230;<br />
<br/></p>
<h3>Screenshot</h3>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/Miostar.jpg" target="_blank"><img src="http://www.megapanzer.com/wp-content/uploads/Miostar-300x230.jpg" alt="Fishing sensitive data with MioStar" title="Miostar" width="150" height="115" class="alignleft size-medium wp-image-4364" /></a>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/11/17/fishing-sensitive-data-with-miostar/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cars: The next hacking frontier?</title>
		<link>http://www.megapanzer.com/2010/09/03/cars-the-next-hacking-frontier/</link>
		<comments>http://www.megapanzer.com/2010/09/03/cars-the-next-hacking-frontier/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 10:48:50 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Car]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3907</guid>
		<description><![CDATA[Read on CNet Of course, your car is probably not a high-priority target for most malicious hackers. But security experts tell CNET that car hacking is starting to move from the realm of the theoretical to reality, thanks to new wireless technologies and evermore dependence on computers to make cars safer, more energy efficient, and [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /><strong>Read on CNet</strong></p>
<p>Of course, your car is probably not a high-priority target for most malicious <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1220" title="Glossary: Hacker" target="_blank">hackers</a>. But security experts tell CNET that car hacking is starting to move from the realm of the theoretical to reality, thanks to new wireless technologies and evermore dependence on computers to make cars safer, more energy efficient, and modern.<br />
&#8220;Now there are computerized systems and they have control over critical components of cars like gas, brakes, etc.,&#8221; said Adriel Desautels, chief technology officer and president of NetraGard, which does vulnerability assessments and <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Penetration test" target="_blank">penetration testing</a> on all kinds of systems. &#8220;There is a premature reliance on technology.&#8221;</p>
<p>Often the innovations are designed to improve the safety of the cars. For instance, after a recall of Firestone tires that were failing in Fords in 2000, Congress passed the TREAD (Transportation Recall Enhancement, Accountability and Documentation) Act that required that tire pressure monitoring systems (TPMS) be installed in new cars to alert drivers if a tire is underinflated.</p>
<p>Read more <a href="http://news.cnet.com/8301-27080_3-20015184-245.html" target="_blank">here</a>.</p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/09/03/cars-the-next-hacking-frontier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cell phone eavesdropping enters script-kiddie phase</title>
		<link>http://www.megapanzer.com/2010/07/29/cell-phone-eavesdropping-enters-script-kiddie-phase/</link>
		<comments>http://www.megapanzer.com/2010/07/29/cell-phone-eavesdropping-enters-script-kiddie-phase/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 13:19:50 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Eavesdropping]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Kraken]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3628</guid>
		<description><![CDATA[Black Hat Independent researchers have made good on a promise to release a comprehensive set of tools needed to eavesdrop on cell phone calls that use the world&#8217;s most widely deployed mobile technology. “The whole topic of GSM hacking now enters the script-kiddie stage, similar to Wi-Fi hacking a couple years ago, where people started [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /><strong><a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Black hat" target="_blank">Black Hat</a></strong> Independent researchers have made good on a promise to release a comprehensive set of tools needed to eavesdrop on cell phone calls that use the world&#8217;s most widely deployed mobile technology.</p>
<p>“The whole topic of GSM hacking now enters the script-kiddie stage, similar to Wi-Fi hacking a couple years ago, where people started cracking the neighbor&#8217;s Wi-Fi,” said Karsten Nohl, a cryptographer with the Security Research Labs in Berlin who helped spearhead the project. “Just as with Wi-Fi, where they changed the encryption to <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1322" title="Glossary: WPA" target="_blank">WPA</a>, hopefully that will happen with GSM, too.”<br />
The suite of applications now includes Kraken, software being released at the <a class="glossaryLink" href="http://www.megapanzer.com/" title="Glossary: Black hat" target="_blank">Black Hat</a> security conference on Thursday that can deduce the secret key encrypting SMS messages and voice conversations in as little as 30 seconds. It was developed by Frank A. Stevenson, the same Norwegian programmer who almost a decade ago developed software that cracked the CSS encryption scheme protecting DVDs.</p>
<p>
Find whole article here : <a href="http://www.theregister.co.uk/2010/07/29/cell_phone_snooping/" target="_blank">Cell phone eavesdropping enters script-kiddie phaset</a></p></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/07/29/cell-phone-eavesdropping-enters-script-kiddie-phase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China rejects accusations on Google hack, Internet freedom</title>
		<link>http://www.megapanzer.com/2010/01/25/china-rejects-accusations-on-google-hack-internet-freedom/</link>
		<comments>http://www.megapanzer.com/2010/01/25/china-rejects-accusations-on-google-hack-internet-freedom/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 19:31:48 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[censor]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[freedom]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Hacking]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3412</guid>
		<description><![CDATA[China on Monday dismissed accusations of any official involvement in hacking attacks on Google and other U.S. companies, adding to tension between the two countries over the issue. A Chinese official also defended online censorship of political topics and said the country would not change how it regulates the Internet, according to the official Xinhua [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />China on Monday dismissed accusations of any official involvement in hacking attacks on Google and other U.S. companies, adding to tension between the two countries over the issue.</p>
<p>A Chinese official also defended online censorship of political topics and said the country would not change how it regulates the Internet, according to the official Xinhua news agency.</p>
<p>Google has said it was hit by cyberattacks from China that caused the loss of intellectual property and were also aimed at accessing the Gmail accounts of Chinese human rights activists. Google cited the attacks, which hit at least 20 other large U.S. companies, as one reason it plans to stop censoring its Chinese search engine, even if that means closing its China offices.</p>
<p>Google did not blame the Chinese government for the attacks, but U.S. Secretary of State Hillary Clinton has called on China to investigate the claims.</p>
<p>&#8220;Whether through explicit or implicit means, criticizing &#8216;Chinese government participation in hacking attacks&#8217; is totally baseless,&#8221; China&#8217;s official Xinhua news agency cited a spokesperson for China&#8217;s IT ministry as saying. &#8220;We resolutely oppose this.&#8221; The Xinhua article quoting the ministry official was posted on the ministry&#8217;s Web site.</p>
<p>The official repeated previous government statements that Chinese law forbids hacking attacks and that the country is open to international cooperation to fight cybercrime. </p>
<p>Read more <a href="http://www.computerworld.com/s/article/9147799/China_rejects_accusations_on_Google_hack_Internet_freedom" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/01/25/china-rejects-accusations-on-google-hack-internet-freedom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inmate gets 18 months for thin client prison hack</title>
		<link>http://www.megapanzer.com/2009/12/28/inmate-gets-18-months-for-thin-client-prison-hack/</link>
		<comments>http://www.megapanzer.com/2009/12/28/inmate-gets-18-months-for-thin-client-prison-hack/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 08:41:41 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[prison]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3253</guid>
		<description><![CDATA[A former prison inmate has been ordered to serve 18 months for hacking the facility&#8217;s computer network, stealing personal details of more than 1,100 of its employees and making them available to other inmates. Francis G. Janosko, 44, received the sentence earlier this week in federal court in Boston after pleading guilty to the hacking [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.megapanzer.com/wp-content/uploads/newspaper.jpg"><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" /></a>A former prison inmate has been ordered to serve 18 months for hacking the facility&#8217;s computer network, stealing personal details of more than 1,100 of its employees and making them available to other inmates.</p>
<p>Francis G. Janosko, 44, received the sentence earlier this week in federal court in Boston after pleading guilty to the hacking offenses in September.</p>
<p>In 2006, Janosko hacked a thin client that was connected to a prison server to access the employee database for the Plymouth County Correctional Facility in Massachusetts, prosecutors alleged. After obtaining the names, addresses, dates of birth, social security numbers and telephone numbers of the employees, he made them accessible to other inmates.</p>
<p>Read more <a href="http://www.theregister.co.uk/2009/12/24/inmate_prison_hack/" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/12/28/inmate-gets-18-months-for-thin-client-prison-hack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010 cyberthreat forecast: Attack vectors</title>
		<link>http://www.megapanzer.com/2009/12/21/2010-cyberthreat-forecast-attack-vectors/</link>
		<comments>http://www.megapanzer.com/2009/12/21/2010-cyberthreat-forecast-attack-vectors/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 12:12:51 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[News & media]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[trend]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3227</guid>
		<description><![CDATA[2009 was dominated by sophisticated malicious programs with rootkit functionality, Conficker, web attacks and botnets, SMS fraud and attacks on social networks. With the start of 2010 quickly approaching, researchers and analysts from Kaspersky Lab have come up with a list of six predictions for what will be the New Year’s greatest threats and newest [...]]]></description>
			<content:encoded><![CDATA[<glossarycode><glossarycode><glossarycode><glossarycode><p><img src="http://www.megapanzer.com/wp-content/uploads/newspaper-150x150.jpg" alt="newspaper" title="newspaper" width="75" height="75" class="alignright size-thumbnail wp-image-2595" />2009 was dominated by sophisticated malicious programs with <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1240" title="Glossary: Rootkit" target="_blank">rootkit</a> functionality, Conficker, web attacks and <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1307" title="Glossary: Botnet" target="_blank">botnets</a>, SMS fraud and attacks on social networks. With the start of 2010 quickly approaching, researchers and analysts from Kaspersky Lab have come up with a list of six predictions for what will be the New Year’s greatest threats and newest attack vectors.</p>
<p><strong>1. A rise in attacks originating from file sharing networks.</strong> In the coming year we will see a shift in the types of attacks on users, from attacks via websites and applications toward attacks originating from file sharing networks.</p>
<p><strong>2. An increase in mass <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1210" title="Glossary: Malware" target="_blank">malware</a> epidemics via P2P networks.</strong> In 2009 a series of mass <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1210" title="Glossary: Malware" target="_blank">malware</a> epidemics has been “supported” by malicious files that are spread via file sharing networks. This method has been used to spread notorious threats such as TDSS and Virut as well as the first <a class="glossaryLink" href="http://www.megapanzer.com/?page_id=1301" title="Glossary: Backdoor" target="_blank">backdoor</a> for Mac OS X. In 2010, we expect to see a significant increase in these types of incidents on P2P networks.</p>
<p>Read more <a href="http://www.net-security.org/secworld.php?id=8643" target="_blank">here</a>.</p></glossarycode></glossarycode></glossarycode></glossarycode>]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/12/21/2010-cyberthreat-forecast-attack-vectors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Economics of Botnets</title>
		<link>http://www.megapanzer.com/2009/11/27/the-economics-of-botnets/</link>
		<comments>http://www.megapanzer.com/2009/11/27/the-economics-of-botnets/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 17:31:03 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[Reading material]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[click fraud]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3139</guid>
		<description><![CDATA[Nice article about botnets, click fraud and spamming. You can find the original article (written by Yury Namestnikov) on www.viruslist.com. The Economics of Botnets In the past ten years, botnets have evolved from small networks of a dozen PCs controlled from a single C&#038;C (command and control center) into sophisticated distributed systems comprising millions of [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.megapanzer.com/wp-content/uploads/books-150x150.jpg" alt="books" title="books" width="75" height="75" class="alignright size-thumbnail wp-image-2238" />Nice article about botnets, click fraud and spamming.<br />
You can find the original article (written by Yury Namestnikov) on <a href="http://www.viruslist.com/" target="_blank">www.viruslist.com</a>.</p>
<p>
<strong>The Economics of Botnets</strong></p>
<p>In the past ten years, botnets have evolved from small networks of a dozen PCs controlled from a single C&#038;C (command and control center) into sophisticated distributed systems comprising millions of computers with decentralized control. Why are these enormous zombie networks created? The answer can be given in a single word: money.</p>
<p>A botnet, or zombie network, is a network of computers infected with a malicious program that allows cybercriminals to control the infected machines remotely without the users’ knowledge. Zombie networks have become a source of income for entire groups of cybercriminals. The invariably low cost of maintaining a botnet and the ever diminishing degree of knowledge required to manage one are conducive to growth in popularity and, consequently, the number of botnets.<br />
<span id="more-3139"></span><br />
So how does one start? What does a cybercriminal in need of a botnet do? There are many possibilities, depending on the criminal’s skills. Unfortunately, those who decide to set up a botnet from scratch will have no difficulty finding instructions on the Internet.<br />
<br />
You can simply create a new zombie network. This involves infecting computers with a special program called a bot. Bots are malicious programs that unite compromised computers into botnets. If someone who wants to start a ‘business’ has no programming skills, there are plenty of ‘bot for sale’ offers on forums. Obfuscation and encryption of these programs’ code can also be ordered in the same way in order to protect them from detection by antivirus tools. Another option is to steal an existing botnet.<br />
<br />
The cybercriminal’s next step is to infect user machines with bot malware. This is done by sending spam, posting messages on user forums and social networks, or via drive-by downloads. Alternatively, the bot itself can include self-replication functionality, like viruses and worms.<br />
<br />
Various social engineering techniques are used when ordering spam mailings or posting messages on user forums and social networks in order to cause potential victims to install a bot. For example, users can be offered an interesting video to view, which requires downloading a special codec. Of course, the user won’t be able to watch the video after downloading and launching the file. In fact, the user will probably not notice any changes at all, but at the same time the computer will be infected. As a result, the computer will become an obedient servant at the beck and call of the botnet owner without the user being any the wiser.<br />
<br />
Another widely used method involves covertly downloading malware via drive-by-downloads. This method is based on taking advantage of various vulnerabilities in applications, primarily popular browsers, to download malware to the computer when the user visits an infected web page. This is done with special programs called exploits, which use vulnerabilities not only to covertly download, but also to run a malicious program without the user’s knowledge. If the attack is successful, the user will not even suspect that there is something wrong with the computer. This method of distributing malicious software is particularly dangerous, since tens of thousands of people get infected when a popular web resource is compromised.<br />
</p>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/botnet_11.png" target="_blank"><br />
<img src="http://www.megapanzer.com/wp-content/uploads/botnet_11-1024x609.png" alt="botnet_1" title="botnet_1" width="512" height="305" class="alignleft size-large wp-image-3161" /></a>
</td>
</tr>
<tr>
<td>
<strong>Figure 1: A snare for users (a fake Youtube post)</strong>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
<p>A bot can be designed to include the feature of self-propagation in computer networks, e.g., by infecting all the executable files it can access or by scanning the network for vulnerable computers and infecting them. The Virus.Win32.Virut and Net-Worm.Win32.Kido families are examples of such bots. The former is a polymorphic file infector, the latter a network worm. It is hard to overestimate the effectiveness of this approach: today, the zombie network created by Kido is the world’s largest.<br />
<br />
The botnet owner can control unsuspecting users’ infected computers via the botnet’s command &#038; control center, by connecting to bots via an IRC channel, a web connection or any other available means. It is sufficient to unite a few dozen machines into a network for the botnet to start making money for its owner. The income is directly proportional to the zombie network’s stability and growth rate.</p>
<p><strong>How botnet owners make money</strong><br />
<br />
So how do botnet owners make money with infected computers? There are several major sources of income: DDoS attacks, theft of confidential information, spam, phishing, SEO spam, click fraud and distribution of adware and malicious programs. It should be noted that, if chosen, any of these sources can provide a cybercriminal with a good income. But why choose? A botnet can perform all of these activities… at the same time!<br />
</p>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/botnet_21.png" target="_blank"><br />
<img src="http://www.megapanzer.com/wp-content/uploads/botnet_21.png" alt="botnet_2" title="botnet_2" width="493" height="277" class="alignright size-full wp-image-3160" /></a>
</td>
</tr>
<tr>
<td>
<strong>Figure 2: The ‘botnet business’</strong>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
<p><strong>DDoS attacks</strong><br />
<br />
Many researchers believe that even the earliest botnets provided DDoS functionality. A DDoS attack is an attack on a computer system which aims to force the system into denial of service, when it can no longer receive and process requests from legitimate users. One of the most common attack methods involves sending numerous requests to the victim computer, leading to denial of service if the computer under attack has insufficient resources to process all incoming requests. DDoS attacks are a potent weapon for hackers and botnets are an ideal tool for carrying out such attacks. DDoS attacks can be used as a tool for unfair competition or be manifestations of cyberterrorism.<br />
<br />
A botnet owner can render services to any unscrupulous entrepreneur by organizing a DDoS attack on his competitor’s website. The competitor’s website will be down due to the stress caused by the attack and the cybercriminal will receive a modest (or not-so-modest) reward. Botnet owners themselves can use DDoS attacks in the same way to extort money from large companies. Companies often choose to give in to cybercriminals’ demands because dealing with the consequences of successful DDoS attacks is even more expensive. In January 2009, an attack on godaddy.com, a major web hosting provider, resulted in several thousand websites hosted on the company’s web servers being inaccessible for almost 24 hours. What was it, an illegal move by another popular hosting provider in the combat for a place in the sun, or was Go Daddy blackmailed by cybercriminals? We think that both scenarios are quite likely. Incidentally, the same hosting provider experienced a similar attack in November 2005, but then the service was unavailable for only an hour. The new attack was much more powerful, primarily due to the growth of botnets.<br />
<br />
In February 2007, a series of attacks was conducted targeting the root name servers, on which the entire Internet depends for normal operation. It is unlikely that the purpose of the attacks was to crash the Internet, since zombie networks cannot function without the Internet. It is more likely that this was a demonstration of the power and capabilities of zombie networks.<br />
<br />
Adverts for organizing DDoS attacks are openly displayed on many user forums devoted to the relevant topics. As for the price tag, it can range from $50 to several thousand dollars for 24-hour continuous operation of a botnet carrying out a DDoS attack. The price range makes sense. The task of stopping the sales of a modest unprotected online store for one day can be tackled by a relatively small botnet (about a thousand computers), and will cost the criminal a relatively small amount of money. But if the competitor is a large international company with a well-protected website, the price will be much higher, since a successful DDoS attack will require a much larger number of zombie computers, so the customer will have to pay up.<br />
<br />
According to shadowserver.org, about 190 000 DDoS attacks were carried out in 2008, “earning” cybercriminals about $20 million. Naturally, this estimate does not include revenues from blackmail, which are impossible to assess.</p>
<p><strong>Theft of confidential information</strong><br />
<br />
Confidential information stored on users’ computers will always attract cybercriminals. The most valuable data includes credit card numbers, financial information and passwords to various services, such as email, ftp, IM systems etc. Today’s malicious programs allow criminals to choose the data they want by installing the relevant module on the infected computer.<br />
<br />
Cybercriminals can either sell the information stolen or use it in their own interests. Hundreds of new bank-accounts-for-sale advertisements appear on underground forums every day. The price of an account can range from $1 to $1500. The low minimum price demonstrates that the cybercriminals involved in this business have to reduce their prices due to competition. To make a really significant amount of money, they need a steady inflow of fresh data, which is provided primarily by a stable growth of zombie networks.<br />
<br />
Financial information is of special interest to carders, i.e., people who forge bank cards. The profitability of their operations is well illustrated by the story of a group of Brazilian cybercriminals who were arrested two years ago. They were able to withdraw $4.74 million from bank accounts using information stolen from computers.<br />
<br />
Personal data not directly related to users’ finances are of interest to cybercriminals who forge documents, open fake bank accounts, conduct illegal transactions etc.<br />
<br />
The cost of stolen personal data is directly dependent on the country of its legal owner’s residence. For example, a complete set of data on a US resident costs $5 to 8. EU resident data is particularly valued on the black market and is two or three times more expensive than data for US and Canadian residents. This is because cybercriminals can use this data in any EU country. Worldwide, the average cost of a full package of data on one person is about $7.<br />
<br />
Another type of information collected by botnets is email addresses. Unlike credit card numbers and accounts, numerous email addresses can be harvested from one infected computer. The addresses harvested are then put up for sale, sometimes ‘in bulk’, by megabyte. Spammers are naturally the main buyers. One list of a million email addresses costs $20 to 100, while spammers charge $150 to 200 for a mailing to these same million addresses, making a clear profit.<br />
<br />
Criminals are also interested in user accounts for various paid services and online stores. These are certainly cheaper than bank accounts, but their sale involves lower risk of prosecution by law-enforcement agencies. For example, accounts for Steam, a popular online store, with access to ten games are sold for $7 to 15 per account.<br />
</p>
<table>
<tr>
<td>
<a href="http://www.megapanzer.com/wp-content/uploads/botnet_31.png" target="_blank"><br />
<img src="http://www.megapanzer.com/wp-content/uploads/botnet_31-1024x590.png" alt="botnet_3" title="botnet_3" width="512" height="295" class="alignright size-large wp-image-3159" /></target>
</td>
</tr>
<tr>
<td>
<strong>Figure 3: Forum post offering Steam accounts for sale</strong>
</td>
</tr>
<tr>
<td>&nbsp;</td>
</tr>
</table>
<p><strong>Phishing</strong><br />
<br />
New phishing sites are now mass-produced, but they need protection from closure. Zombie networks obligingly provide an implementation of fast flux technology, which allows cybercriminals to change website IP addresses every few minutes without affecting the domain name. This extends the lifetime of phishing sites, making it hard to detect them and take them offline. The idea involves using people’s home computers that are part of a botnet as web servers with phishing content. Fast flux is better than proxy servers at hiding fake websites on the Web.<br />
<br />
Thus, Rock Phish, a well-known phishing ring, works in cooperation with Asprox, a botnet operator. In the middle of last year the ‘Rock Phishers’, who are responsible for half the online phishing attacks and millions of dollars lost by online banking users, upgraded their infrastructure for fast-flux compatibility. This took about five months and everything was done at a highly professional level. Instead of creating their own fast flux network, the phishers acquired a ready-made solution from the owners of the Asprox botnet.<br />
<br />
Cybercriminals, mostly phishers, pay botnet owners $1000 to 2000 per month for hosting fast flux services.<br />
<br />
The average income from phishing is comparable to that from the theft of confidential data using malicious programs and adds up to millions of dollars per year.</p>
<p><strong>Spam</strong><br />
<br />
Millions of spam messages are sent globally every day. Sending unsolicited mail is a major function of today’s botnets. According to Kaspersky Lab data, about 80% of all spam is sent via zombie networks.<br />
<br />
Billions of messages with adverts for Viagra, watch replicas, online casinos etc. are sent from computers of law-abiding users. These messages clutter up communication channels and mailboxes. In this way, hackers expose innocent users’ computers: the sender addresses to which mass mailings are traced are blacklisted by antivirus companies.<br />
<br />
In recent years, the scope of spam services has broadened to include ICQ spam, spam in social networks, user forums and weblogs. This is also an ‘achievement’ of botnet owners: it doesn’t take a lot of effort to add a new module to a bot client in order to open up new horizons for a new business with slogans such as “Spam in Facebook. Cheap”.<br />
<br />
Spam prices vary depending on the target audience and the number of target addresses. The price of a targeted mailing can range from $70 for a few thousand addresses to $1000 for tens of millions.<br />
<br />
In the past year, spammers made about $780,000,000 sending messages. An impressive result for adverts that nobody wants, isn’t it?</p>
<p><strong>Search engine spam</strong><br />
<br />
Another application for botnets is search engine optimization (SEO). Webmasters use SEO in order to improve their websites’ positions in search results, since the higher they get the more visitors will reach the site via search engines.<br />
<br />
Search engines use a number of criteria to assess the relevance of a website. One of the main parameters is the number of links to the site located on other pages or domains. The more such links are found, the higher the search robot rates the site. The words used in the link also affect the rating. For example, the link “buy our computers” will have a greater weight for such queries as “buy a computer”.<br />
<br />
SEO is a flourishing business in itself. Many companies pay lots of money to web masters to bring their websites to top positions in search results. Botnet operators have borrowed some of their techniques and automated the search engine optimization process.<br />
<br />
So if you see lots of links created by an unknown user or even your friend in comments on your favorite live journal entry, don’t be surprised. It only means that somebody has hired the owners of a botnet to promote a web resource. A specially designed program is installed on a zombie computer and leaves comments containing links to the site being promoted on popular resources.<br />
<br />
The average price of illegal SEO spam is about $300 per month.</p>
<p><strong>Adware and malware installation</strong><br />
<br />
Imagine that you are reading your favorite online automobile magazine and suddenly a popup window appears, offering genuine auto accessories for sale. It would seem that there is nothing wrong with that, but you are confident that you didn’t install any software to look for useful (or useless) things. It’s simple: botnet owners have ‘taken care’ of you.<br />
<br />
Many companies that offer online advertising services pay for each installation of their software. As a rule, this is not a lot of money – from 30 cents to $1.50 for each program installed. However, when a cybercriminal has a botnet at his disposal, he can install any software on thousands of computers with a few mouse clicks and earn serious money. J. K. Shiefer, a well-known cybercriminal who was convicted in 2007, ‘earned’ over $14,000 in one month using a botnet of over 250,000 machines to install adware on 10,000 computers.<br />
<br />
Cybercriminals who distribute malicious programs often use the same approach, paying for each installation of their software. This type of cooperation between cybercriminals is called an “affiliate network”. Rates for the installation of software on computers in different countries differ significantly. For example, the average price of installing a malicious program on a thousand computers in China is $3 and in the US $120. This makes sense, since computers of users in developed countries can provide cybercriminals with much more valuable information that can be used to make a lot more money.</p>
<p><strong>Click fraud</strong><br />
<br />
Online advertising agencies that use the PPC (Pay-Per-Click) scheme pay for unique clicks on advertisements. Botnet owners can make significant amounts of money by cheating on such companies.<br />
<br />
An example is the well-known Google AdSense network. Advertisers pay Google for clicks on their ads in the hope that users who visit their sites in this way will buy something from them.<br />
<br />
Google, in its turn, places context-based advertising on the various websites participating in the AdSense program, paying a percentage from each click to website owners. Unfortunately, not all website owners are honest. With a zombie network, a hacker can generate thousands of unique clicks a day – one from each machine to avoid raising Google’s suspicion. Thus the money spent on an advertising campaign makes its way into the hacker’s pockets. Sadly, nobody has been convicted of this kind of fraud so far.<br />
<br />
According to Click Forensics, about 16-17% of all advertising link clicks in 2008 were fake, of which a third was generated by botnets. A simple calculation will show that botnet owners made $33 million ‘for clicks’. Not bad for simple mouse clicks!</p>
<p><strong>Leasing and selling botnets</strong><br />
<br />
Now to the busy botnet owners: for them, Marx’s world-famous formula, “goods – money – goods” translates into “botnet – money – botnet”. Keeping a botnet afloat, ensuring a steady inflow of new zombies, protecting bots from being detected by antivirus products and keeping the C&#038;C from being located requires both financial and time investment from the hacker, so he simply has no time left for sending spam, installing software or stealing and selling information. It is much easier to lease the botnet out or sell it, especially since there is no shortage of those who wish to acquire it.<br />
<br />
The lease of a mail botnet that can send about 1000 messages a minute (with 100 zombie machines working online) brings about $2000 per month. As in the case of leasing, the price of a ready-made botnet depends on the number of infected computers. Ready-made botnets are especially popular on English-speaking user forums. Small botnets of a few hundred bots cost $200 to 700, with an average price amounting to $0.50 per bot. Large botnets cost much more. The Shadow botnet, which was created by a 19-year-old hacker from Holland and included over 100,000 computers, was put on sale for $36,000. This is enough to buy a small house in Spain, but the Brazilian cybercriminal chose the botnet.</p>
<p><strong>Conclusion</strong><br />
<br />
Mind boggling sums make their way into the pockets of people in the botnet business. All sorts of methods are used to combat this business, but at the legislation level it is completely ineffective. Laws on spam and on the development and distribution of malicious programs or on breaking into computer networks are not applied in many countries, even where such laws do exist. Botnet owners or developers who have been prosecuted can be counted on the fingers of two hands. Which is not the case with botnets that are live on the Internet: the number of these has exceeded 3600. In fact, counting functioning botnets is not an easy task, because in addition to a few dozen large botnets that are hard to miss there are numerous smaller zombie networks that are not easy to detect or tell apart.<br />
<br />
At present, the most effective method of combating botnets is close cooperation between antivirus experts, ISPs and law enforcement agencies. Such cooperation has already resulted in the closure of three companies: EstDomains, Atrivo and McColo. Note that the closure of McColo, whose servers hosted command and control centers for several major spam botnets, resulted in a 50% reduction in the amount of spam circulating on the Internet.<br />
<br />
Experts follow the activity of thousands of botnets, and antivirus products detect and destroy bots across the globe, but only law enforcement agencies can stop the command and control centers and catch the cybercriminals, thereby ‘putting out’ botnets for extended periods of time. The closure of McColo only had a short-lived effect: several weeks later spam traffic began to go back to its usual levels. After botnet owners moved their command and control centers to other hosting providers, it was ‘business as usual’ for them again. What is needed is a continual effort rather than occasional inspections. Sadly, chopping off one head of the hydra is not enough!<br />
<br />
Without help from users, combating botnets cannot be effective. It is home computers that make up the lion’s share of the enormous army of bots. Neglecting to stick to simple security rules, such as using antivirus software, using strong account passwords and disabling the AutoPlay feature for removable media, can result in your computer becoming another botnet member, providing cybercriminals with your data and resources. Why help cybercriminals?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/11/27/the-economics-of-botnets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Tcpdump sniffer for network monitoring.</title>
		<link>http://www.megapanzer.com/2009/07/26/tcpdump-sniffer-for-network-monitoring/</link>
		<comments>http://www.megapanzer.com/2009/07/26/tcpdump-sniffer-for-network-monitoring/#comments</comments>
		<pubDate>Sun, 26 Jul 2009 17:00:53 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[External tools]]></category>
		<category><![CDATA[Fingerprinting]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Portscanner]]></category>
		<category><![CDATA[Scanner]]></category>
		<category><![CDATA[Tool]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=2370</guid>
		<description><![CDATA[&#160; &#160; &#160; Tool name : Tcpdump &#160; &#160; Description : Tcpdump is the IP sniffer we all used before Ethereal (Wireshark) came on the scene, and many of us continue to use it frequently. It may not have the bells and whistles (such as a pretty GUI or parsing logic for hundreds of application [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%">&nbsp;</td>
<td width="50%">&nbsp;</td>
<td width="20%">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Tool name</strong> :</td>
<td>Tcpdump</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong> :</td>
<td colspan="2">
Tcpdump is the IP sniffer we all used before Ethereal (Wireshark) came on the scene, and many of us continue to use it frequently. It may not have the bells and whistles (such as a pretty GUI or parsing logic for hundreds of application protocols) that Wireshark has, but it does the job well and with fewer security holes. It also requires fewer system resources. While it doesn’t receive new features often, it is actively maintained to fix bugs and portability problems. It is great for tracking down network problems or monitoring activity.
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Homepage</strong> :</td>
<td colspan="2"><a href="http://www.tcpdump.org/" target="_blank">www.tcpdump.org</a></td>
</tr>
</tbody>
</table>
<p><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/07/26/tcpdump-sniffer-for-network-monitoring/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

