BotNets

Saldrin

OSNN Junior Addict
Joined
1 Dec 2005
Messages
31
How can you tell if you have been or are part of a botnet?

From what I have been reading, most botnets use IRC, so would a simple netstat with ports like 6667 being open lead me to believe I've been comprimised? Note: I haven't used IRC in years, so I have no reason to be using that port. Also, that port is not really open on my machine, just a hypothetical question.

What other signs can a user look for, or be aware of, to protect themselves from botnets?

Thanks in advance.
 
yep, just open up a command prompt and run 'netstat -a'

if you see things connected to ports 6666 to 6669 or 7000 to 7002 then its likely that something is connected to an IRC server somewhere.

also check your process listing for any programs you dont know the names of. then google the name of the process and see what comes up.
 
Cool, thank you. I used to use netstat all the time to check for trojans, now I'm pretty much converted to the network monitor within Kaspersky IS 6.0. They really made some nice updates!! It will tell you what process is using what open port; one of the things I could never strangle out of netstat.

What picked my concern, is I was reading this article: http://blog.spywareguide.com/ and I started digging through some other blogs there, and one of the things that jumped out at me was when one person was checking into a botnet, the IRC server denied him accesses for spamming. Long story short, this happened to me many many years ago (probably the last time I did use IRC...), and I knocked it off as I got a bad selection of an IP from my ISP (DHCP) at the time. Wonder if I got spanked many years back....

Thanks for the reply.
Sal
 

Members online

No members online now.

Latest profile posts

Also Hi EP and people. I found this place again while looking through a oooollllllldddd backup. I have filled over 10TB and was looking at my collection of antiques. Any bids on the 500Mhz Win 95 fix?
Any of the SP crew still out there?
Xie wrote on Electronic Punk's profile.
Impressed you have kept this alive this long EP! So many sites have come and gone. :(

Just did some crude math and I apparently joined almost 18yrs ago, how is that possible???
hello peeps... is been some time since i last came here.
Electronic Punk wrote on Sazar's profile.
Rest in peace my friend, been trying to find you and finally did in the worst way imaginable.

Forum statistics

Threads
62,015
Messages
673,494
Members
5,621
Latest member
naeemsafi
Back