Username: 
Password: 
Restrict session to IP 

Botnet

Global Rank: 15
Totalscore: 431070
Posts: 40
Thanks: 36
UpVotes: 21
Registered: 15y 230d







The User is Offline
Botnet
Google/translate0Thank You!0Good Post!1Bad Post! link
Assuming I run a server which hosts ~200 websites. I know for sure that one is infected with a botnet. Can any of you think of a suitable way of detecting that particular site without having to analyze each website's source code ?
Loading...
Global Rank: 202
Totalscore: 101912
Posts: 65
Thanks: 66
UpVotes: 43
Registered: 15y 252d
xen`s Avatar






The User is Offline
RE: Botnet
Google/translate0Thank You!0Good Post!0Bad Post! link
"infected with a botnet" could you expand on this more?
do you mean the website is running as part of the botnet,,,,
or it propagates the malware to spread the botnet?

if as part then could you listen for patterns with input/output? e.g. botnet C&C sends instructions and address/ip range, the site then acts on that.
chmod ---x--x--x,, i'm illiterate!
Global Rank: 537
Totalscore: 47139
Posts: 37
Thanks: 21
UpVotes: 24
Registered: 11y 357d
stormsurfer`s Avatar



Last Seen: 7y 103d
The User is Offline
RE: Botnet
Google/translate0Thank You!0Good Post!0Bad Post! link
yeah, "infected by botnet" needs further explenation.

anywhy, if it's a script, you can find /home/*/public_html -type f -exec grep -H <something> {} \;
or if it's actualy connecting to the net, using lsof you can cross reference ports with full path names of files.
tunelko, stormsurfer, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, kalungmas have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 4011 times.