Re: [funsec] Fight! Fight!

2011-08-22 Thread michael.blanchard
Hmmm it would appear that our good friends at McAfee have forgotten the 
definition of botnet...  let me help them out a bit  :-)


bot·net

noun /ˈbätˌnet/ 
botnets, plural

   1. A network of private computers infected with malicious software and 
controlled as a group without the owners' knowledge

Michael P. Blanchard
Senior Security Engineer, CISSP, GCIH, CCSA-NGX, MCSE
Office of Information Security  Risk Management
EMC ² Corporation
32 Coslin Drive
Southboro, MA 01772

-Original Message-
From: funsec-boun...@linuxbox.org [mailto:funsec-boun...@linuxbox.org] On 
Behalf Of valdis.kletni...@vt.edu
Sent: Friday, August 19, 2011 3:45 PM
To: rmsl...@shaw.ca
Cc: funsec@linuxbox.org
Subject: Re: [funsec] Fight! Fight!

On Fri, 19 Aug 2011 12:20:39 PDT, Rob, grandpa of Ryan, Trevor, Devon  
Hannah said:
 http://blogs.mcafee.com/mcafee-labs/shady-rat-is-not-a-botnet

Well.. she says:

Speaking of technical arguments, apparently Mr. Kaspersky has gotten it in his 
head that Shady RAT is a botnet.

And then continues with:

that we only know of 72 companies/organizations victimized through one command 
 control server, out of hundreds or more used by this adversary.

OK, I'll bite, if it was a CC server, *what do we call the thing being 
controlled* if it wasn't a botnet?

___
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

[funsec] Fight! Fight!

2011-08-19 Thread Rob, grandpa of Ryan, Trevor, Devon Hannah
http://blogs.mcafee.com/mcafee-labs/shady-rat-is-not-a-botnet

==  (quote inserted randomly by Pegasus Mailer)
rsl...@vcn.bc.ca sl...@victoria.tc.ca rsl...@computercrime.org
More computing sins are committed in the name of efficiency than
for any other single reason--including blind stupidity.
   - William A. Wulf
victoria.tc.ca/techrev/rms.htm http://www.infosecbc.org/links
http://blogs.securiteam.com/index.php/archives/author/p1/
http://twitter.com/rslade
___
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Re: [funsec] Fight! Fight!

2011-08-19 Thread Valdis . Kletnieks
On Fri, 19 Aug 2011 12:20:39 PDT, Rob, grandpa of Ryan, Trevor, Devon  
Hannah said:
 http://blogs.mcafee.com/mcafee-labs/shady-rat-is-not-a-botnet

Well.. she says:

Speaking of technical arguments, apparently Mr. Kaspersky has gotten it in his
head that Shady RAT is a botnet.

And then continues with:

that we only know of 72 companies/organizations victimized through one command
 control server, out of hundreds or more used by this adversary.

OK, I'll bite, if it was a CC server, *what do we call the thing being 
controlled* if
it wasn't a botnet?


pgpnOvxNlTrhw.pgp
Description: PGP signature
___
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.