Zee got his net taken away from him numerous times hitting the wrong people.
But yes in a nutshell, the digital world is mostly unprotected open and unlocked houses, with little pockets of protected castles here and there, and some locked houses too.
It also makes me wonder if optimized command and control networks have been developed. Most of the code I see floating around public drops goes to very little effort to conceal data exfil, if it even makes an effort to identify data to exfil at all. This seems like a real waste given that some large percentage of machines you steal are likely worth more than just their cpu time and bandwidth. Obviously the more code you run, the higher your chances of detection, but it seems like a huge creative space. How do I find interesting files without tripping all the alarms? How do I efficiently take over someone else's LSM hooks?
So for example remote command injection vulns:
http://en.1337day.com/exploit/description/20598
http://en.1337day.com/exploit/description/20602
http://en.1337day.com/exploit/description/20671
Then it is just a matter of figuring out where these routers are, and then writing a few scripts to exploit and command them in mass. I don't think CSRF/XSS would net him the vast numbers he'd need to make a significant ddos.
And to more specifically answer your question, by "incoming connections", I mean like monitoring the ddos via netstat on a box zee was actively attacking.
For cases where they're remotely exposed, just about anyone can scan the Internet and try to exploit these routers. I'm sure he was doing that, but I'm sure hundreds or thousands of other people were as well.
When combined with something like a CSRF, you can use those exploits against a victim even if their router is locked down (only listening on LAN, strong admin password). All they need to do is visit a site you control, without something like NoScript. If the admin password is not guessable, then they'd need to have an active login session. That can be circumvented if the router has an auth bypass vuln, which has been found in at least a few models.
Also, I believe a lot of routers can be used for DDoSing without exploiting or compromising them at all if they're exposing SSDP (UPnP). SSDP reflection, possibly combined with NTP reflection, is likely how Lizard Squad launched their DDoS attacks.
P.S. I know you and have talked to you (and Zee and some others), briefly, on some IRC networks long ago.
If that's not the case, mind giving any hints?
We are using actual 0days to compromise the (about 100k-150k) servers we have.
I'm actually rather excited for the eventual technical analysis of our net by someone with actual technical competence. It might end up causing quite a bit of noise.
I seem to recall you guys (I think it was you guys, may be mixing up with another group; I also know you were supposedly kicked out of HTP at some point, which adds to my confusion) using one of the Rails YAML handling 0-days to acquire bots a while ago. I think someone was logging the IRC channel where they were being joined to.
Would it be fair to say the other bots are mostly a result of other web app vulns, or are you guys actually finding 0-days in native applications as well?
Do you actually have a full vulnerability research team, or is it just like 1-2 guys finding vulns? HTP's stuff like Coldfusion and MoinMoin was definitely pretty impressive.
A large chunk of the boxes we control do not have any sort of web apps running on them.
I understand you may not want to reveal much for opsec purposes, but just one question: the Lizard Squad guys seem like very run of the mill script kiddies. Why would you help them, if you are? Kind of seems like a skill and motive mismatch. Forgive my ignorance if the situation is more complicated than that; I'm just going off of what Krebs wrote.
Krebs seems to be pretty lost, especially considering that he thinks we've been attacking his site for past 40 days or so. That's just not true (and anyway, if Prolexic couldn't keep PSN up why would they be able to keep his site up?), only thing linking us to attacks against him was a joke in the topic of our fake recruitment channel telling people to take his site down for an hour or so.
Anyway, as for my motives (besides money, of course)? You don't get access to this many boxes without stumbling on at least something interesting.
I'm guessing part of the plan is to continue gaining infamy and notoriety to sell services, starting with the stresser. I also wouldn't be too surprised if perhaps the stresser is a sting op or honeytrap on your part, with the money as just an added bonus.
Now, on the other hand we have our corporate clients. These corporate clients usually contact us via email or over forums and either make us a fixed offer or request a quote for a given target and time-frame. Now, these types of clients are usually willing to pay tens, if not hundreds of thousands of dollars to disrupt their competition for a couple of days.
The second type of customer is obviously our main source of income, and what better way to find those clients than worldwide media publicity?
It'd be funny if this ended up being a sting op, wouldn't it?