Infiltrating a Botnet - A Conversation With a Botmaster
cisco.com
cisco.com
too bad the article devolved into an ad for cisco products at the very end. i was really digging it up to that point.
I got to write half of it in Scheme, which probably means that I deployed more Scheme runtime than anybody else on the planet.
One way to observe worm behavior: http://www.honeynet.org/
SRI writeup on their dissection of Storm: http://www.cyber-ta.org/pubs/StormWorm/report/
the researcher suggested a TOR audio conference
Audio over TOR? I thought it was too slow for that.in his position, i certainly wouldn't have talked. but it's probably a lonely occupation, and who else are you going to talk to.
The researcher now knows a forum which contains up-to-date exploits of this scene, transactions of this scene. That is a boatload of knowledge, especially if one finds currently unknown exploits in there, or starts tracking the money by the transactions made on this forum.
Furthermore, the botmaster gave out a lot of information about his illegal activities, so he pretty surely was very, very confident (I'd go as far as calling this overconfident) about his security.
Sorry, but coming from this, this guy does not look like a real serious botmaster to me. I mean, if you make lots of money with bots, why whould you give out information about your exploits and your trades, making it easy for the government and security firms to stop you? That's just dumb.