Mar 16 2005

More Than 1 Million Bots On The Attack

  • Written by SutterKayn
  • No Comments

At least a million machines are under the control of hackers worldwide, said security experts in Germany, indicating that the bot and botnet problem is worse than anyone thought.

Using only three computers as “honeypots,” machines deliberately left open to attack, thus attracting hackers and their bots so researchers can capture data on their actions, German security analysts at Aachen University were able to identify more than 100 botnets during a three-month project. Those botnets ranged in size from only a few hundred compromised PCs to several of up to 50,000 systems.

The volume, the Honeynet Project researchers said, was staggering. Even using conservative estimates, they projected over a million PCs worldwide are currently under the control of hackers running botnets.

“That number wouldn’t surprise me,” said Ken Dunham, the director of malicious code research at iDefense, a Reston, Va.-based security intelligence firm.

The number of bots in attacker botnets is hard to pin down, added Dunham, but the figures cited by the Germans, he said, are probably conservative. “In just the last six months, the numbers of botnets surged from only a few hundred to over 6,000 total by our count,” Dunham said. “It’s not uncommon to see botnets with more than 50,000 PCs, so there could easily be a million or more total.”

The largest botnet that iDefense has tracked was one in 2003 that controlled a whopping 120,000 machines.

These massive collections of compromised PCs are used by attackers primarily for profit, and are the root of most denial-of-service (DoS) attacks against corporate networks, the foundation of most spamming, as well as leveraged to infect other PCs with worms and viruses (”in most cases, botnets are used to spread new bots,” wrote the researchers), to host the bogus Web sites that phishers rely on to trick users into giving up personal information, and to distribute spyware.

“The explosion of botnets is a huge problem,” said Dunham.

The vast majority of botnets are made up of Windows systems, said the honeypot researchers. More than 80 percent of the traffic captured by the honeypot machines was directed at four ports used by common services in Windows, such as RPC (Remote Procedure Call) and the NetBIOS Name Service.

In fact, the bulk of the botnets were assembled using just a handful of exploits that take advantage of a few Windows vulnerabilities.

“It’s the easy-to-use tools now available to hackers, as well as the source code for some exploits, that’s behind the growth of botnets,” said Dunham. “We’ve seen as many as a dozen exploit families, not exploits, but entire families, appear in just days after source code is made public. All [hackers] do is pick up [the code], and copy and paste.”

Related Posts

  1. MSNBC: Worm creates P2P attack network
  2. Windows XP Firewall Hack Released
  3. Mac Attack: One Million PC Users Get Apple
  4. Apple fixes critical iTunes bug
  5. Hackers Attack Key Net Traffic Computers
Zeropaid on Facebook
Trackbacks url:

Leave a Comment...

  • Advertisement

    Giganews Newsgroups

1 Star2 Stars3 Stars4 Stars5 Stars Loading ... Loading ...

  • DrewWilson: To my knowledge, the ACTA hass been officially deemed illegal in a few countries already and is likely to be technically...
  • 11x17: Hello , I can not use it , I got a "failed to create directory" error...
  • Lethal: that statement sounds like a confession of guilt to a MAJOR international crime. @Bogus LOL this is the type of in...
  • MPAA Dismisses Demand for Copyright Treaty Transparency as “Distraction”: [...] that it affects its very survival, but again conveniently leaves out the fact that it’s enjoying another in ...
  • Quaranj: I have hated how Flash has gotten really poor since Adobe took over. (Upgrade issues anyone?) If Adobe spent half the t...
  • dbr357: never been on ip torrent would like to would anyone like to invite me. thanks....
  • eddie: please can i have an invite to ip torrents my e-mail is eddiebroaders@live.ie...
  • eddie: please can i have an invite to ip torrents...
  • sdsd