Security Incidents mailing list archives

Re: Strange Windows behavior / Spamming customers


From: Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net>
Date: Thu, 4 Mar 2004 22:46:44 +0100

On 2004-03-04 Christopher Kunz wrote:
I don't know how many german-speaking members this list has, but I'd
like to point all people who are working on the spamming/trojan issues
to a rather good article in the german IT magazine "c't"
(http://www.heise.de/ct/inhalt.shtml).

Basically, this article links the numerous trojans that circulate in
peer2peer networks, irc networks like QuakeNet and IRCNet and via mail
to the exact problem you're seeing. Seems like the creators of the
trojan variants (built with a trojan building kit) use the trojans to

1) create massive botnets with tens of thousands of compromised hosts
and use them for their own purposes (mainly dDoS)
2) create a steady revenue stream by renting out these botnets to
spammers, who in turn relay millions of spam mails through these
networks.

According to the article, there have been several arrests in the UK
and USA connected to the investigations done by "c't" and a german
student.

I suppose you are referring to "Unter fremder Kontrolle" in c't 3/04.
There is an excerpt of this article available online [1]. Unfortunately
no translation to english.

[1] http://www.heise.de/ct/04/03/118/

Regards
Ansgar Wiechers

---------------------------------------------------------------------------
Free 30-day trial: firewall with virus/spam protection, URL filtering, VPN,
wireless security

Protect your network against hackers, viruses, spam and other risks with Astaro
Security Linux, the comprehensive security solution that combines six
applications in one software solution for ease of use and lower total cost of
ownership.

Download your free trial at 
http://www.securityfocus.com/sponsor/Astaro_incidents_040301
----------------------------------------------------------------------------


Current thread: