Live data from Hacker News

Have you ever chatted with a hacker within a virus?

blogs.avg.com

21–30 of 106 posts

Re: Have you ever chatted with a hacker within a virus?

#21
post #15

When I was a teenager I found it fun to intentionally infect myself with malware and try to study it. I know realize this wasn't the most responsible thing to do, as I wasn't in a sandboxed environment, but it was a great learning experience and taught me a lot about networking and security. One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~1…

Perhaps a rather naive questions, but: were the username and pw transfered in plaintext?

Re: Have you ever chatted with a hacker within a virus?

#22

To answer the title: yes. It was my freshman year of college and my first introduction to broadband in 1998. I discovered irc via mIrc and somehow somebody put something on my computer where they could control the mouse/keyboard. I watched the guy move the cursor around for a while then begin to type to him. He was cool, and told me how to prevent it from happening again.

This happened to a lot of people when they started out using IRC. I remember chatting with someone using mIRC and the started opening and closing my CD-ROM. I got duped into running a Sub7 client script or something.

Re: Have you ever chatted with a hacker within a virus?

#24
post #15

When I was a teenager I found it fun to intentionally infect myself with malware and try to study it. I know realize this wasn't the most responsible thing to do, as I wasn't in a sandboxed environment, but it was a great learning experience and taught me a lot about networking and security. One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~1…

Perhaps a rather naive questions, but: were the username and pw transfered in plaintext?

Yep, I remember both being sent via plaintext.

Re: Have you ever chatted with a hacker within a virus?

#26

Steve Gibson (grc.com) famously used chatroom credentials in a trojan he reverse-engineered to get in and chat with the bot maker. And, infamously, got DDOSed for it. Can't find the transcript now, which is a shame; I think he took it offline to let the intertubes cool down.

http://www.crime-research.org/library/grcdos.pdf I think this is what you are talking about, really interesting read if I remember correctly.

Very nice read, thanks for sharing

Re: Have you ever chatted with a hacker within a virus?

#27
post #18
post #16

Earlier quoted context omitted.

The Steve Gibson story was really interesting. He's a really cool guy, too. My botnet adventures happened around the same time as his, and I too was DDoS'd. We even exchanged a few e-mails about botnets and the script kiddie culture. Those were fun times.

Except when he went on record opposing the addition of raw-sockets to Windows XP saying it would help hackers and spell the end of the world. I remember clutching my Redhat CD, just in case raw sockets were banned ;-) http://www.theregister.co.uk/2001/06/25/steve_gibson_really_...

Ah, yeah, I remember that too now :)

Re: Have you ever chatted with a hacker within a virus?

#28
Recently a friend of mine sent me a piece of obfuscated JS that was in a phishing page that was being posted around his large gaming related website. Threw the JS into closure compiler with advanced optimisations and pretty print and out comes relatively unobfuscated code- it cleared up the series of horrible regexes anyway. The code injected a Java applet that downloaded a botnet virus. Decompiling the Java applet revealed the steamid of the guy orchestrating this. Added him on steam and had a great conversation in which he accidentally indirectly admitted the botnet was under his control. A fun use of a Sunday. The evidence was never sent to anyone, thinking nothing would come of it.

Re: Have you ever chatted with a hacker within a virus?

#29
post #15

When I was a teenager I found it fun to intentionally infect myself with malware and try to study it. I know realize this wasn't the most responsible thing to do, as I wasn't in a sandboxed environment, but it was a great learning experience and taught me a lot about networking and security. One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~1…

> I tried a "hello" and waited. And waited. And then I was k-lined from the IRC network. The next day when I logged onto my computer, I found my Internet connectivity was being overwhelmed with bogus TCP requests.

I'd probably do the same, upon discovering that one of my bots had become sentient.

Post reply on HN