<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Bot Networks: Jacking the Jackers</title>
	<atom:link href="http://www.rfxn.com/bot-networks-jacking-the-jackers/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rfxn.com/bot-networks-jacking-the-jackers/</link>
	<description> Linux Software &#38; Blog</description>
	<lastBuildDate>Thu, 26 Jan 2012 07:01:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Brad</title>
		<link>http://www.rfxn.com/bot-networks-jacking-the-jackers/#comment-10357</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Fri, 22 Jul 2011 18:39:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?p=589#comment-10357</guid>
		<description>I love it! I run an IRCd company.. were constantly trying to keep on top of these kiddies.. We&#039;ve gotten to the point that I have alerts smsed to me if our bandwidth spikes to more than double a past few hours average... I usually can expect some sort of service issues and can hop on and block traffic if something happens.

I&#039;ve also had to experience a C&amp;C network being hosted on my server... guy thought he was all that locking the server down.. when we turned off the actual ircd process he never came back to turn it on.. but we knew he was the root cause..

I really wish there was a way to scan files they upload and then modify..</description>
		<content:encoded><![CDATA[<p>I love it! I run an IRCd company.. were constantly trying to keep on top of these kiddies.. We&#8217;ve gotten to the point that I have alerts smsed to me if our bandwidth spikes to more than double a past few hours average&#8230; I usually can expect some sort of service issues and can hop on and block traffic if something happens.</p>
<p>I&#8217;ve also had to experience a C&amp;C network being hosted on my server&#8230; guy thought he was all that locking the server down.. when we turned off the actual ircd process he never came back to turn it on.. but we knew he was the root cause..</p>
<p>I really wish there was a way to scan files they upload and then modify..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pascal</title>
		<link>http://www.rfxn.com/bot-networks-jacking-the-jackers/#comment-3928</link>
		<dc:creator>Pascal</dc:creator>
		<pubDate>Wed, 24 Nov 2010 18:30:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?p=589#comment-3928</guid>
		<description>I&#039;d like to have your knowledge as, for it takes me long long time, to find I&#039;ve been attack, and more long to understand how/why and long time to recreate a fresh/clean server.

Last one was a S99lvm in /etc/rc3.d/ which one launched a pscd process which connect to ns10.dnetnoc.net:ircd

Bad bad one. Not find yet how they had root access. What I know, is S99lvm having a CWD of /root, using libresolv.so, having its file descriptors set to a pseudo-terminal (instead of /dev/null) and being run by root.</description>
		<content:encoded><![CDATA[<p>I&#8217;d like to have your knowledge as, for it takes me long long time, to find I&#8217;ve been attack, and more long to understand how/why and long time to recreate a fresh/clean server.</p>
<p>Last one was a S99lvm in /etc/rc3.d/ which one launched a pscd process which connect to ns10.dnetnoc.net:ircd</p>
<p>Bad bad one. Not find yet how they had root access. What I know, is S99lvm having a CWD of /root, using libresolv.so, having its file descriptors set to a pseudo-terminal (instead of /dev/null) and being run by root.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

