Technology news and Jobs arrow VIRTUALISATION arrow Srizbi down but not quite out
Srizbi down but not quite out E-mail
by Stephen Withers   
Tuesday, 02 December 2008
The Srizbi botnet has proved sufficiently robust to partially recover from the isolation of its command and control servers. So much for claims that it was 'completely defunct'.

When hosting provider McColo was taken down on November 11, email filtering  operators noted a drop in spam volumes of between two-thirds and three-quarters.

Later that month, a statement from MessageLabs attributed to senior anti-spam technologist at Matt Sergeant said "Srizbi, having once been responsible for 50 per cent of all spam, is now completely defunct. Without this botnet, spam levels won't return to what they had been."

That statement appears to have been premature.

It seems that the Srizbi code had been developed with an eye to recovering from such a situation.

If a Srizbi bot loses contact with the server, it uses an algorithm to generate a seemingly random (but time-dependent) domain name, at which it attempts to contact a server.

So all that was necessary was to register one of those names in time for the bots to attempt to contact it.

While security firm FireEye spent at least $1500 registering names that the botnet would attempt to use, "as money is not infinite, soon the new domains will be available for registration by anyone, including the Botnet owner, or someone who wishes to be a Botnet owner."

And that, it appears, is what happened. Someone registered a set of domain names and used them to regain control over the Srizbi botnet.

According to the Washington Post, VeriSign, Microsoft and the US Computer Emergency Readiness Team (US-CERT) had been asked to assist in either buying up (or tying up) the domains ahead of time, with no apparent response.

The new Srizbi servers located in Estonia were subsequently shut down before much spam could be pumped out, according to The Register, although one  server located in Germany was still active at the time of the report.

According to FireEye, the most active botnets are currently Pushdo/Cutwail and Bobax/Kraken.

Powered By Joomla Tags

Please enable JavaScript in your browser to post your comment!

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
694,279
Subscribers 15,210
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

- Advertisement -

Featured Whitepapers

Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter