Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Richard M. Smith
    New trojan turns home PCs into porno Web site hosts
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    New trojan turns home PCs into porno Web site hosts

    Hi,

    Some individual appears to have hijacked more than a 1,000 home
    computers starting in late June or early July and has been installing a
    new trojan horse program on them. The trojan allows this person to run a
    number of small Web sites on the hijacked home computers. These Web
    sites consists of only a few Web pages and apparently produce income by
    directing sign-ups to for-pay porno Web sites through affiliate
    programs. Spam emails messages get visitors to come to the small Web
    sites.

    To make it more difficult for these Web sites to be shut down, a single
    home computer is used for only 10 minutes to host a site. After 10
    minutes, the IP address of the Web site is changed to a different home
    computer. The hacker is able to do this quick switching because he has
    installed DNS name servers for his domains on other home computers under
    his control. The DNS name servers specify that a
    hostname-to-IP-address mapping should only live for 10 minutes.

    Over the long July 4th weekend, some of these same Web servers were used
    in an apparent phishing scam to collect stolen PayPal passwords and
    credit card numbers. Silicon.com has an article about this scam:

    Russian hackers behind fake PayPal email scam?
    http://silicon.com/news/500013-500001/1/5061.html

    Joe Stewart of LURHQ has obtained a copy of the trojan which he has
    named Migmaf. His analysis of the trojan can be found on the LURHQ Web
    site:

    http://www.lurhq.com/migmaf.html

    The initial theory was that the trojan was installing a mini-Web server
    on hacked computer to host the porno Web sites. However, Joe's analysis
    shows that the Trojan is actually a reverse HTTP proxy that makes a
    home computer act as a front for a home base Web server.

    The New York Times is also running an article about the trojan in its
    July 11th edition of the paper:

    http://www.nytimes.com/2003/07/11/te...11HACK.html?hp

    Some of the domain names used by the Web sites of the trojan are:

    onlycoredomains.com
    pizdatohosting.com
    bigvolumesites.com
    wolrdofpisem.com
    arizonasiteslist.com
    nomorebullshitsite.com
    linkxxxsites.com

    I've been monitoring these domains since July 5th and found over 2,000
    unique IP address used by hosts in these domains. Almost all of these
    IP addresses are for commercial ISPs used by home computer users.
    AOL.COM was the most used ISP.

    One interesting feature of the trojan is that it times the connection
    speed of a home computer that it is running on and reports the
    connection speed back to home base. The home base computer seems to
    only select a computer to run a reverse proxy server or the DNS name
    server if the computer has a high-speed cable or DSL Internet
    connection.

    It is not known at the present time how the trojan gets installed on
    people's computers. My theory is that the Sobig.e virus might be
    involved, but the evidence is not strong at the moment.

    Richard M. Smith
    http://www.ComputerBytesMan.com



  2. #2
    ge
    New trojan turns home PCs into porno Web site hosts
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: New trojan turns home PCs into porno Web site hosts

    > Some individual appears to have hijacked more than a 1,000 home
    computers starting in late June or early July and has been installing a
    new trojan horse
    > program on them.


    Let us consider ourselves lucky. That is an extremely low number.

    > To make it more difficult for these web sites to be shut down, a

    single home computer is used for only 10 minutes to host a site. After
    10 minutes, the IP address of the Web site is changed to a different
    home
    > computer. The hacker is able to do this quick switching because he

    has installed DNS name servers for his domains on other home computers
    under his control. The DNS name servers specify that a hostname
    > to-IP-address mapping should only live for 10 minutes.


    As I see it, someone in the states should file a complaint with the FBI
    (if one has not already been charged) and they can handle this guy.
    If not, the best way, as I see, it is to check where the Trojan gets the
    information it uses from, a.k.a. where it connects. Should give you the
    right IP for abuse mail.
    If you get rid of that one IP, you effectively get rid of the thousand
    infected machines.

    > Some of the domain names used by the Web sites of the trojan are:
    >
    > onlycoredomains.com
    > pizdatohosting.com
    > bigvolumesites.com
    > wolrdofpisem.com
    > arizonasiteslist.com
    > nomorebullshitsite.com
    > linkxxxsites.com


    Here's a place to start with the abuse mails, find out what ISP hosts
    them and cross your fingers they won't send your emails to /dev/null.

    > It is not known at the present time how the trojan gets installed on

    people's computers. My theory is that the Sobig.e virus might be
    involved, but the evidence is not strong at the moment.

    The DSL and Cable IP ranges get scanned _even_ more than the rest of the
    world. Anybody remembers that paper that stated a computer would get
    scanned 36 hours after it establishes a connection to the Internet?
    Well, I am on ADSL with my home machine, and surprisingly enough I got
    hit the second I switched to ADSL and I get ten to fifteen scans a
    minute. That said not mentioning being a secondary victims to kiddies
    using these IP ranges to spoof attacks (ICMP echo 3).

    > Richard M. Smith
    > http://www.ComputerBytesMan.com



    Gadi (i.e. ge),
    ge@linuxbox.org.

    --------
    gevron@netvision.net.il
    PGP Key: 2048/2048 (Size) 0x2D3D6741 (ID).
    Fingerprint: 0EB3 00BC 974B 3C2B 336D 6486 ECA5 2D0D 2D3D 6741.



Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics