{"id":1598,"date":"2009-12-21T22:30:37","date_gmt":"2009-12-22T03:30:37","guid":{"rendered":"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/?p=1598"},"modified":"2022-12-30T12:37:02","modified_gmt":"2022-12-30T17:37:02","slug":"botnets-attacking-servers","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/botnets-attacking-servers\/","title":{"rendered":"Botnets Attacking Servers"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-112447\" title=\"Botnets Attacking Servers\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pc_sick.jpg?resize=120%2C92&#038;ssl=1\" alt=\"Botnets Attacking Servers\" width=\"120\" height=\"92\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pc_sick.jpg?resize=150%2C115&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pc_sick.jpg?resize=75%2C58&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/pc_sick.jpg?w=506&amp;ssl=1 506w\" sizes=\"auto, (max-width: 120px) 100vw, 120px\" \/> Web servers, FTP servers, and even SSL servers are becoming prime targets for botnets. They are targets, not as command and control servers says Mikko Hypponen, chief research officer at <a href=\"http:\/\/www.f-secure.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">F-Secure<\/a>, in a recent <a href=\"https:\/\/www.darkreading.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>DarkReading<\/em><\/a> article, \u201c<em>but in some cases to execute high-powered spam runs<\/em>.&#8221;<\/p>\n<p><a href=\"https:\/\/www.f-secure.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-1602\" style=\"border: 0pt none; margin: 0px 2px;\" title=\"fsecure\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2009\/12\/fsecure-e1561856140884.jpg?resize=75%2C75&#038;ssl=1\" alt=\"\" width=\"75\" height=\"75\" \/><\/a>Botnet operators are going after certain types of servers specifically to harness their horsepower and bandwidth says Joe Stewart, director of malware research for <a href=\"https:\/\/www.secureworks.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">SecureWorks<\/a>. These bots are typically used as spamming engines: &#8220;<em>The general purpose of these attacks is to send spam, either email spam or blog spamming,<\/em>&#8221; Stewart told <em>DarkReading<\/em>. &#8220;<em>The benefits are having a large amount of bandwidth available and enhanced processing capacity to maximize the amount of spam you can send out.<\/em>&#8221;<\/p>\n<h3>Source of Web attacks<\/h3>\n<p>Marc Maiffret, chief security architect at <a href=\"https:\/\/www.fireeye.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">FireEye<\/a> says he expects trusted and legitimate Websites will start to become the source of the majority of Web attacks in 2010. &#8220;<em>I think that the focus there on servers is really again more to help more easily infect a larger number of desktops,<\/em>&#8221; Maiffret says.&#8221;You can think of this SQL\/Web-spread vector as the modernized version of what use to happen with email and such many years ago.&#8221;<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"wp-image-1603 size-full alignright\" style=\"border: 0pt none; margin: 0px 2px;\" title=\"ftp\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2009\/12\/ftp-e1561856179917.jpg?resize=80%2C52&#038;ssl=1\" alt=\"\" width=\"80\" height=\"52\" \/>&#8220;<em>FTP servers are a hot commodity in the underground. They are regularly used by drive-by download malware as well as a downloading component for regular bots<\/em>,&#8221; says Hypponen. Botnets often use stolen FTP credentials to break into other parts of the system, says Bill Ho, vice president of Internet products for <a href=\"https:\/\/web.archive.org\/web\/20130822061533\/http:\/\/www.biscom.com:80\/index.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Biscom<\/a>. &#8220;<em>FTP is being used to transfer bot code to other machines, servers, and users,<\/em>&#8221; Ho says. &#8220;<em>If the FTP server is not secured properly and an FTP site has access to other parts of the system with vulnerabilities, the attacker can install [malware] at that location and infect and compromise that server.<\/em>&#8221; \u00a0Paul French, vice president of products and solutions marketing for <a href=\"https:\/\/www.axway.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Axway<\/a> laments that. &#8220;<em>FTP is pretty ubiquitous &#8230; The reality is that FTP has been around long enough for people to know the risks associated with it. But sometimes convenience outweighs good IT security<\/em> [practices].\u201d<\/p>\n<h3>Botnets using SSL servers<\/h3>\n<p>&#8220;<em>Another thing we&#8217;ve noticed is the use of SSL servers. Sites with a valid SSL certificate get hacked and are used by drive-by-download<\/em>s&#8221; according to Hypponen.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"wp-image-1604 alignright\" style=\"border: 0pt none; margin-left: 2px; margin-right: 2px;\" title=\"ssl\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2009\/12\/ssl-e1561856260591-111x150.png?resize=64%2C86&#038;ssl=1\" alt=\"\" width=\"64\" height=\"86\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2009\/12\/ssl-e1561856260591.png?resize=111%2C150&amp;ssl=1 111w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2009\/12\/ssl-e1561856260591.png?resize=55%2C75&amp;ssl=1 55w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2009\/12\/ssl-e1561856260591.png?w=118&amp;ssl=1 118w\" sizes=\"auto, (max-width: 64px) 100vw, 64px\" \/>Why SSL servers? &#8220;<em>If a drive-by download gets the malware file through an HTTPS connection, proxy and gateway scanners won&#8217;t be able to scan for the malware in transit, making it easier to sneak in,<\/em>&#8221; Hypponen explains.<\/p>\n<p>Botnet operators are using these networks of captured servers to expand their operations. The servers are used to host exploits, serve up drive-by downloads, and help them distribute more malware to the bot-infected PCs in the botnet, <em>DarkReading<\/em> concludes.<\/p>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>F-Secure says that web servers, FTP servers, and  SSL servers are new targets for botnets in order to execute high-powered spam runs.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3216,58,107,118,1142,3079,1143,4,106,305],"class_list":["post-1598","post","type-post","status-publish","format-standard","hentry","category-security","tag-3216","tag-botnet","tag-f-secure","tag-fireeye","tag-ftp","tag-mikko-hypponen","tag-secureworks","tag-security","tag-servers","tag-ssl"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/1598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=1598"}],"version-history":[{"count":13,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/1598\/revisions"}],"predecessor-version":[{"id":132105,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/1598\/revisions\/132105"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=1598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=1598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=1598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}