Live data from Hacker News

Have you ever chatted with a hacker within a virus?

blogs.avg.com

11–20 of 106 posts

Re: Have you ever chatted with a hacker within a virus?

#11
post #8

"I am sorry but AVG blogs are currently undergoing essential maintenance. Normal service will be resumed shortly, in the meantime go to AVG.com for more information about AVG products or go to our Facebook page to join our thriving online community. We apologise for any disruption this may have caused."

http://webcache.googleusercontent.com/search?q=cache:blogs.a...

No screen shots or links in this, obviously.

Re: Have you ever chatted with a hacker within a virus?

#12

Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .…

[deleted]

Re: Have you ever chatted with a hacker within a virus?

#13
post #8

"I am sorry but AVG blogs are currently undergoing essential maintenance. Normal service will be resumed shortly, in the meantime go to AVG.com for more information about AVG products or go to our Facebook page to join our thriving online community. We apologise for any disruption this may have caused."

Site seems to be going up and down. Just keep refreshing, and you should get the site again. With images.

Re: Have you ever chatted with a hacker within a virus?

#14

Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .…

I was reading that article thinking "I remember all of those features (and more) being in Sub7 about 12-13 years ago". Not so advanced, really.

Re: Have you ever chatted with a hacker within a virus?

#15
When I was a teenager I found it fun to intentionally infect myself with malware and try to study it. I know realize this wasn't the most responsible thing to do, as I wasn't in a sandboxed environment, but it was a great learning experience and taught me a lot about networking and security.

One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~10K botnet. I spent hours running a packet sniffer and seeing how the client interacted with the IRC network it called home to. Upon connecting to the privately run IRC network, the bot would authenticate with a user and pass. I assume it created one upon connecting the first time to the network. My best guess as to why this is is so that the bot master could track the total number of zombies and compare it to how many were actively connected to the botnet. Kind of a cleaver way to get metrics, now that I think about it.

When I temporarily stopped the bot from connecting to IRC, I decided it might be fun to login as the bot and join the channel I saw it connecting to. Upon joining the channel, I saw thousands of other users on the channel. I spent a couple of days sitting there, masquerading myself as a bot, and watching the botmaster interact with the bots. The botmaster would issue commands that I can't really recall anymore, but I do remember seeing a lot of commands that I assumed told the bots to download extra malware from a remote host. I remember seeing URLs for zip and exe files.

Eventually I got a little bored of this, so I decided to message the botmaster. It was easy to spot him; out of the three ops on the channel, he was the only full op. I tried a "hello" and waited. And waited. And then I was k-lined from the IRC network.

The next day when I logged onto my computer, I found my Internet connectivity was being overwhelmed with bogus TCP requests. I had pissed off the botmaster by snooping, and now I was getting DDoS'd. I imagine he/she commandeered a small number of the bots to do this. It wouldn't take many... I imagine back then, given my bandwidth, 10-15 would have done it.

Fun times. I remember posting about my botnet adventures to Security Focus way back when. Some people got really interested and followed my posts, while other professionals asked me to stop because I wasn't running a sandbox.

IMO, those were different times. I'm not sure I'd recommend something like this these days. After hearing about certain botnets being tied to various mafias and gangs around the world (which is probably more common than you think. See http://www.ibtimes.co.uk/articles/321149/20120329/mafia-cont...), I'm not sure I'd really want to risk interfering with their activities.

Re: Have you ever chatted with a hacker within a virus?

#16

Steve Gibson (grc.com) famously used chatroom credentials in a trojan he reverse-engineered to get in and chat with the bot maker. And, infamously, got DDOSed for it. Can't find the transcript now, which is a shame; I think he took it offline to let the intertubes cool down.

The Steve Gibson story was really interesting. He's a really cool guy, too. My botnet adventures happened around the same time as his, and I too was DDoS'd. We even exchanged a few e-mails about botnets and the script kiddie culture. Those were fun times.

Re: Have you ever chatted with a hacker within a virus?

#17

Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .…

I remember the joys of LAN gaming with friends. "Oi, who rotated my screen!"

Re: Have you ever chatted with a hacker within a virus?

#18
post #16

Steve Gibson (grc.com) famously used chatroom credentials in a trojan he reverse-engineered to get in and chat with the bot maker. And, infamously, got DDOSed for it. Can't find the transcript now, which is a shame; I think he took it offline to let the intertubes cool down.

The Steve Gibson story was really interesting. He's a really cool guy, too. My botnet adventures happened around the same time as his, and I too was DDoS'd. We even exchanged a few e-mails about botnets and the script kiddie culture. Those were fun times.

Except when he went on record opposing the addition of raw-sockets to Windows XP saying it would help hackers and spell the end of the world. I remember clutching my Redhat CD, just in case raw sockets were banned ;-)

http://www.theregister.co.uk/2001/06/25/steve_gibson_really_...

Re: Have you ever chatted with a hacker within a virus?

#19
To answer the title: yes.

It was my freshman year of college and my first introduction to broadband in 1998. I discovered irc via mIrc and somehow somebody put something on my computer where they could control the mouse/keyboard.

I watched the guy move the cursor around for a while then begin to type to him. He was cool, and told me how to prevent it from happening again.

Re: Have you ever chatted with a hacker within a virus?

#20

Steve Gibson (grc.com) famously used chatroom credentials in a trojan he reverse-engineered to get in and chat with the bot maker. And, infamously, got DDOSed for it. Can't find the transcript now, which is a shame; I think he took it offline to let the intertubes cool down.

http://www.crime-research.org/library/grcdos.pdf I think this is what you are talking about, really interesting read if I remember correctly.

>When those insecure and maliciously potent Windows XP machines are mated to high-bandwidth Internet connections, we are going to experience an escalation of Internet terrorism the likes of which has never been seen before.

He was right, too.

EDIT: That was an absolutely fascinating read. Thank you.

Post reply on HN