<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>udp-flood &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/udp-flood/</link>
	<description>Feed of posts on WordPress.com tagged "udp-flood"</description>
	<pubDate>Sun, 19 May 2013 17:31:33 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Botnet : Setting up HTTP Warbot Botnet]]></title>
<link>http://jameslovecomputers.wordpress.com/2013/02/26/botnet-http-warbot-botnet/</link>
<pubDate>Tue, 26 Feb 2013 13:52:26 +0000</pubDate>
<dc:creator>jameslovecomputers</dc:creator>
<guid>http://jameslovecomputers.wordpress.com/2013/02/26/botnet-http-warbot-botnet/</guid>
<description><![CDATA[Hello, Today i wish to demonstrate how malicious people set up a HTTP botnet. Warbot is an old HTTP]]></description>
<content:encoded><![CDATA[<p><strong>Hello</strong>,</p>
<p>Today i wish to demonstrate how malicious people set up a HTTP botnet. Warbot is an old HTTP bot net that does not require an irc server for its implementation. I will not be providing the download link, you could google it but there are many fake builders out there. </p>
<p><strong>Note to smart mouths :</strong> I am aware that this is not one of the stronger bots out there and that it cant handle heavy loads. But i am going through it as it allows me to demonstrate how a HTTP bot net is implemented in its simplest forms.<br />
&#160;<br />
<strong>Lets Begin :</strong></p>
<p>1) Assuming you have already downloaded Warbot, lets unzip it.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/1.jpg" /><br />
&#160;<br />
2) Next sign up for a free web hosting server that allows mysql and php.</p>
<p>3) Upload the entire PHP folder onto the web server.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/2.jpg" /><br />
&#160;<br />
4) On your web server cpanel, locate: MySql.</p>
<p>5) Locate a screen similar to the one shown below.</p>
<p>a) MySQL database name : Fill in any name you would like to use.</p>
<p>b) MySQL username : Fill in any name you would like to use.</p>
<p>c) Password for MySQL user: Fill in a password that you would like to use. Repeat it for next column.</p>
<p>6) You are done setting up your MySQL, save this information as you will need it for the later stages.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/3.jpg" /><br />
&#160;<br />
7)  Direct yourselves to <a href="http://www.example.com/PHP/install/index.php" rel="nofollow">http://www.example.com/PHP/install/index.php</a>.</p>
<p>8) Fill in the information we just saved from our MySQL database section.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/4.jpg" /><br />
&#160;<br />
9) Click on the install button and if everything went well, you will see the screen shown below.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/5.jpg" /><br />
&#160;<br />
10) Return to your web cpanel and delete the INSTALL folder.</p>
<p>11) Next click on your PHP folder and locate the chmod option. Change the folder and all its content to Chmod value : 777.</p>
<p>12) Return to your warbot folder on your computer and locate the folder Builder &#38; Bot.</p>
<p>13) You should have two files :</p>
<p>a) Redtube.exe : This is the server creator.</p>
<p>b) Original.exe  : This is the file used to infect victims.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/6.jpg" /><br />
&#160;<br />
14) Double click on Redtube.exe and follow the instructions shown below.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/7.jpg" /><br />
&#160;<br />
15) As you can see in the date modified below, Original.exe was created today.  This is the file that will be used to infect the victims computer through social engineering or other innovative methods.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/6.jpg" /><br />
&#160;<br />
16) Return to your web cpanel and look for phpMyadmin option.</p>
<p>17) Locate fix.sql within your warbot folder(computer) and import it onto the webservers phpMyadmin.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/8.jpg" /><br />
&#160;<br />
18) Direct yourselves to <a href="http://www.example.com/php/index.php?p=Login" rel="nofollow">http://www.example.com/php/index.php?p=Login</a>.</p>
<p>19) Log in with the credentials you chose in the earlier steps.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/9.jpg" /></p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/10.jpg" /><br />
&#160;<br />
20) Congratulations, you have successfully set up warbot.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/11.jpg" /><br />
&#160;<br />
21) This is a simple program that allows HTTP, TCP, UDP flooding.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/12.png" /><br />
&#160;<br />
22) Do you guys remember the <a href="http://jameslovecomputers.wordpress.com/2013/02/14/windows-realvnc-remote-authentication-bypass-vulnerability/" target="_blank">Realvnc vulnerability</a> we went through ? Such machines usually end up turning into drones.</p>
<p><img alt="" src="http://zyphyto1.host56.com/botnet/warbot/13.jpg" /><br />
<img alt="" src="http://zyphyto1.host56.com/botnet/warbot/14.jpg" /><br />
&#160;<br />
23) When Original.exe gets executed on a target computer, the system will turn into a drone and log onto your warbot panel. Sometimes it only works after the target reboots.<br />
<img alt="" src="http://zyphyto1.host56.com/botnet/warbot/15.jpg" /><br />
&#160;<br />
<strong>Authors Note :</strong></p>
<p>1) The use of a bot net is illegal and i will not be responsible for your actions.</p>
<p>2) This is for educational purposes only.</p>
<p>3) Do NOT harm the innocent.<br />
&#160;</p>
<blockquote><p>&#8220;I&#8217;m gonna make him an offer he can&#8217;t refuse.&#8221; <strong>- Don Corleone</strong></p></blockquote>
<p>&#160;<br />
<strong>Contributed By</strong><br />
<strong>Un Prophete</strong><br />
<a href="http://www.paypal.com/" target="_blank"><img class="aligncenter" alt="Make me rich!" src="http://zyphyto1.host56.com/donate.jpg" /></a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Deteksi Serangan Denial of Service Pada Mesin Virtual Dengan Memanfaatkan Kelemahan Pada Transport Layer Protocol]]></title>
<link>http://mfirdausagung.wordpress.com/2012/04/17/deteksi-serangan-denial-of-service-pada-mesin-virtual-dengan-memanfaatkan-kelemahan-pada-transport-layer-protocol/</link>
<pubDate>Tue, 17 Apr 2012 00:45:48 +0000</pubDate>
<dc:creator>Mochammad Firdaus Agung</dc:creator>
<guid>http://mfirdausagung.wordpress.com/2012/04/17/deteksi-serangan-denial-of-service-pada-mesin-virtual-dengan-memanfaatkan-kelemahan-pada-transport-layer-protocol/</guid>
<description><![CDATA[Deteksi Serangan Denial of Service Pada Mesin Virtual DenganMemanfaatkan Kelemahan Pada Transport La]]></description>
<content:encoded><![CDATA[<p>Deteksi Serangan Denial of Service Pada Mesin Virtual DenganMemanfaatkan Kelemahan Pada Transport Layer Protocol</p>
<div> Oleh : Mochammad Firdaus Agung</div>
<p><!--more--></p>
<p><a href="https://mfirdausagung.files.wordpress.com/2012/04/presentasi-deteksi-serangan-denial-of-service-pada-mesin-virtual-dengan-memanfaatkan-kelemahan-pada-transport-layer-protocol.pdf">Deteksi Serangan Denial of Service Pada Mesin Virtual Dengan Memanfaatkan Kelemahan Pada Transport Layer Protocol</a></p>
<iframe class="scribd_iframe_embed" src="http://www.scribd.com/embeds/89664805/content?start_page=1&view_mode=list&access_key=key-15y9c4plkub6twr148gz" data-auto-height="true" scrolling="no" id="scribd_89664805" width="100%" height="500" frameborder="0"></iframe>
<div style="font-size:10px;text-align:center;width:100%"><a href="http://www.scribd.com/doc/89664805">View this document on Scribd</a></div>
]]></content:encoded>
</item>
<item>
<title><![CDATA[What is DDOS attack? Is there any way defense?]]></title>
<link>http://computerites.wordpress.com/2011/12/30/what-is-ddos-attack-is-there-any-way-defense/</link>
<pubDate>Fri, 30 Dec 2011 17:27:00 +0000</pubDate>
<dc:creator>good2good</dc:creator>
<guid>http://computerites.wordpress.com/2011/12/30/what-is-ddos-attack-is-there-any-way-defense/</guid>
<description><![CDATA[What is DDOS attack? Is there any way defense? forever2skyInternet skills DDOS is an acronym of Dist]]></description>
<content:encoded><![CDATA[<h2><a title="What is DDOS attack? Is there any way defense?" href="http://www.computerites.com/internet-skills/2011/12/what-is-ddos-attack-20.html" rel="bookmark">What is DDOS attack? Is there any way defense?</a></h2>
<div><a title="Posts by forever2sky" href="http://www.computerites.com/author/admin" rel="author">forever2sky</a><a title="View all posts in Internet skills" href="http://www.computerites.com/category/internet-skills" rel="category tag">Internet skills</a></div>
<div>
<p><img src="http://www.clshack.it/wp-content/uploads/2010/04/ddos_attack1.gif" alt="what is ddos attacks" /></p>
<p>DDOS is an acronym of Distributed Denial of Service . And what is the denial of service ? Can be understood, all can lead to legitimate users don&#8217;t access the normal behavior of network services are considered denial of service attacks. The purpose of denial of service attack is very clear, that is normal to prevent legitimate users access to network resources, so as to achieve the attacker&#8217;s ulterior motives. It is also a denial of service attack, DDOS and DOS is different, DDOS attack strategies focused on by many zombie hosts (the host the attacker hacked or indirect use of )sends to the victim host a large number of seemingly legitimate network packets, resulting in network congestion or server resource exhaustion denial of service, distributed denial of service attack, once implemented, will attack like a flood of network packets flock to the victim host, thus bring the legitimate users of network packet flooding, leading to legal user can not access the network resources on severs. Therefore, denial of service attack has been called the &#8220;flood attacks,&#8221; there is a common means of DDOS attacks SYN Flood, ACK Flood, UDP Flood, ICMP Flood, TCP Flood, Connections Flood, Script Flood, Proxy Flood, etc.; and DOS will focus on attack through the specific vulnerabilities lead to failure of the host network stack , system crash, crash the host network can not provide normal services, resulting in a denial of service, DOS attacks are common TearDrop , Land, Jolt, IGMP Nuker, Boink, Smurf, Bonk, OOB and so on. Denial of service attacks on these two terms, mainly against the larger DDOS attack, because it is difficult to prevent, as DOS attacks, through to the host server patch or install a good firewall software can prevent, will be detailed later describes how to deal with DDOS attacks. There are currently three popular DDOS attacks: 1.SYN / ACK Flood Attack: This attack is most effective DDOS classical method can kill a variety of systems through web services, mainly through the victim host sends a large number of forged source IP and source port of the SYN or ACK packet, lead host cache resources are exhausted or busy sending packets caused by denial of service response, because the forged source is more difficult to track, there is a certain drawback is the difficulty to implement, requiring a high bandwidth zombie hosts support. A small amount of this attack will lead to host server can not access, but it can Ping the pass, on the server using Netstat-na command to Observe that there are a lot of SYN_RECEIVED state, a large number of such attacks will lead to Ping fails, TCP / IP stack failure, and the system will be freezing phenomenon that does not respond to keyboard and mouse. Most common firewall such attacks can not resist. 2.TCP full-connect attack: This attack is to bypass the firewall inspection routine designed, under normal circumstances, most conventional firewall with filtering TearDrop, Land and other DOS attacks, but for normal TCP connection is let pass , does not know a lot of network service (such as: IIS, Apache Web server, etc.) can accept a limited number of TCP connections, once a large number of TCP connections, even normal, can lead to very slow or unable to access the site access, TCP all connected through a number of zombie hosts attack is continuous with the host server to establish a large number of affected TCP connections until the server&#8217;s memory and other resources are exhausted and are drag you down to cause a denial of service.Attack is characterized by a general firewall bypass protection to achieve the attack purpose disadvantage is the need to find a lot of zombie hosts, and because the zombie host&#8217;s IP is exposed, so easily traced. 3. Brush Script scripting attack: This attack is mainly directed against the existence ASP, JSP, PHP, CGI and other scripts, and call MSSQLServer, MySQLServer, Oracle and other database systems and web site design.Features and server establish a normal TCP connection and constantly submit queries to the script, the list takes a lot of database resources such calls. In general, submit a GET or POST command to the client&#8217;s cost and bandwidth usage is almost negligible, while the server processes the request, but may have to go on a million records to identify a record, this process cost of resources is great, very few common database server can support hundreds of simultaneous query command, which is for the client, it is easy, so the attacker simply by Proxy proxy server to host a large number of submitted query command, only a few minutes to server resources will be consumed and cause denial of service, a common phenomenon is the site slow as a snail, ASP program failure, PHP connect to the database fails, the database main CPU-high. This attack can be characterized completely bypass the normal firewall protection, you can easily find some Proxy agent attack, only drawback is that static page site to deal with the effect will be greatly reduced, and some of Proxy will be exposed to the attacker&#8217;s IP address.</p>
<p>This article address is <a title="What is DDOS attack? Is there any way defense?" href="http://www.computerites.com/internet-skills/2011/12/what-is-ddos-attack-20.html">http://www.computerites.com/internet-skills/2011/12/what-is-ddos-attack-20.html</a></p>
</div>
]]></content:encoded>
</item>

</channel>
</rss>
