Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

ISP Telenor cripples zombie PC network

Internet Relay Chat communications were used to trace the illicit network

September 10, 2004 12:00 PM ET

IDG News Service - Authorities in Singapore shut down a large network of around 10,000 robot, or "zombie," computers this week, after technicians at Norwegian Internet service provider Telenor ASA stumbled on the illicit network by tracing Internet Relay Chat (IRC) communications from compromised customer PCs on its system.
On Tuesday, officials at the Infocomm Development Authority of Singapore worked with a local service provider to shut down a server controlling the army of IRC robot PCs, or "botnet," after being alerted to the existence of the server by The SANS Institute's Internet Storm Center (ISC) in Bethesda, Md. Although the controlling server has been shut down, malicious hackers may have already resurrected it by pointing compromised hosts to a server at a new Internet address, according to Johannes Ullrich, chief technology officer at the ISC.
Botnets are networks of computers that act like robots, communicating with one another and with a central server, often using IRC. Such networks are created by installing remote access and communication software on the remote systems, often after they are compromised by a computer virus, worm or targeted hacking.
Botnets act in unison through text commands issued via IRC from the central server by the hacker or hackers controlling the network. For example, malicious hackers can instruct the network to flood a particular server or Internet domain with traffic in a denial-of-service (DoS) attack.
"In some sense, botnets are a more dangerous problem than worms and viruses," Ullrich said. "They're an easy way to control 10,000 systems, and you can do absolutely anything with them -- instruct [the compromised machines] to pick up a program and install it, or go to a particular URL or scan for other vulnerable hosts."
Often, the compromised hosts are programmed to look for a particular IRC host name, such as botserver.irc.net. Authorities can cripple such networks by banning that particular host name, he said.
In the case of the network discovered this week, Telenor staff were unable to determine the IRC host name that the machines were seeking. That means the individuals controlling the network may already have relaunched it by assigning to a different server the host name for the robot systems, Ullrich said.
The systems on Telenor's network have been cleaned of the remote-control software used by the botnet, but other systems on the network are likely still infected and can be used in future actions, he said. Even when the host name is known, malicious hackers often maintain a number of different, geographically dispersed servers that all use the


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Cybercrime/Hacking

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Southern Company
Download Now  

Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.

Mitigate Risk, Lower Costs and Improve Network Efficiency
Create a stable IP network that not only meets today's challenges, but is flexible enough to also meet future demands.

Share our Strength
Download Now  

Preparing Your Business Services for the Future
Would you trust your network monitoring tools enough to know when something is truly halting a business service?

IPAM: Slashing Network Costs
Slashing Network Costs by Consolidating and Automating Core Network Services

Horror stories: Managing IT Across Multiple Locations
How one extra sharp IT manager eliminates daily agony, hassle and repetition.