<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; web-based botnets</title>
	<atom:link href="http://krebsonsecurity.com/tag/web-based-botnets/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 09 Feb 2012 22:39:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The Rise of Point-and-Click Botnets</title>
		<link>http://krebsonsecurity.com/2010/01/the-rise-of-the-point-and-click-botnets/</link>
		<comments>http://krebsonsecurity.com/2010/01/the-rise-of-the-point-and-click-botnets/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 14:10:58 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Web Fraud 2.0]]></category>
		<category><![CDATA[point and click botnets]]></category>
		<category><![CDATA[team cymru]]></category>
		<category><![CDATA[web-based botnets]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=775</guid>
		<description><![CDATA[The graphic above is from a report out today by Team Cymru, a group that monitors studies online attacks and other badness in the underground economy. It suggests an increasing divergence in the way criminals are managing botnets, those large amalgamations of hacked PCs that are used for everything from snarfing up passwords to relaying [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F01%252Fthe-rise-of-the-point-and-click-botnets%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22The%20Rise%20of%20Point-and-Click%20Botnets%22%20%7D);"></div>
<p><a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/rwbbb.jpg"><img class="aligncenter size-full wp-image-777" title="rwbbb" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/rwbbb.jpg" alt="" width="574" height="321" /></a>The graphic above is from a report out today by <a href="http://www.team-cymru.org/" target="_blank">Team Cymru</a>, a group that monitors studies online attacks and other badness in the underground economy. It suggests an increasing divergence in the way criminals are managing botnets, those large amalgamations of hacked PCs that are used for everything from snarfing up passwords to relaying spam and anonymizing traffic for the bad guys, to knocking the targeted host or Web site offline.</p>
<p>The bottom line in the graphic shows the prevalence of botnets that are managed using Internet relay chat (IRC) control channels (think really basic text-based instant message communications). The blue line trending upward depicts the number of Web-based botnets, those that the botmaster can control with point-and-click ease using a regular Web browser.</p>
<p><span id="more-775"></span></p>
<p>According to Team Cymru, the number of Web-based botnets has continued to climb, doubling in number over the last six months. &#8220;This trend could be explained by the low cost of entry into the HTTP based botnet field: the kits are becoming more accessible and the easier user interface for HTTP botnets means that they are generally favored over more traditional control mechanisms.&#8221;</p>
<p>Read more of the Team Cymru report <a href="http://www.team-cymru.org/ReadingRoom/Whitepapers/2010/developing-botnets.pdf" target="_blank">here</a> (.PDF).</p>
<p>Last month, I <a href="http://www.krebsonsecurity.com/2009/12/virus-scanners-for-virus-authors/" target="_blank">profiled Virtest and AV-Check</a>, a couple of services being marketed to malware writers who want to quickly scan their creations to see how widely they are detected by commercial anti-virus tools.  The graphic above is another great example of the <a href="http://www.csoonline.com/article/521619/Botnets_The_Democratization_of_Espionage_" target="_blank">democratization of espionage</a>, and what I&#8217;ve called <a href="http://www.krebsonsecurity.com/category/web-fraud-2-0/" target="_blank">Web Fraud 2.0</a>: Web-based services and tools that make it simple for virtually anyone to profit from online crime.</p>
<p>Here are a few examples of Web Fraud 2.0 I&#8217;ve written about:</p>
<p><a href="http://voices.washingtonpost.com/securityfix/2009/06/web_fraud_20_franchising_cyber.html" target="_blank">Franchising Cybercrime</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2009/03/web_fraud_20_data_search_tools.html" target="_blank">Data Search Tools for ID Thieves</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2008/11/web_fraud_20_faking_your_inter.html" target="_blank">Faking Your Internet Address</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2008/08/web_fraud_20_defeating_anti-sp.html" target="_blank">Thwarting Anti-Spam Defenses</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2008/08/web_fraud_20_distributing_your.html" target="_blank">Distributing Your Malware</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2008/08/web_fraud_20_digital_forgeries.html" target="_blank">Digital Forgeries</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2008/08/web_fraud_20_try_before_you_bu.html" target="_blank">Validating Your Stolen Goods</a><br />
<a href="http://voices.washingtonpost.com/securityfix/2008/08/web_fraud_20_tools.html" target="_blank">Cloaking Connections</a></p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/01/the-rise-of-the-point-and-click-botnets/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 2/12 queries in 0.006 seconds using memcached
Object Caching 354/369 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 21:57:11 -->
