8 ms·
Doesn't using your botnet expose your botnet IP addresses/devices?
by endergen 3y ago
Doesn't using your botnet expose your botnet IP addresses/devices?
- mrweasel 3y agoYes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.
- jrockway 3y agoAre you positive that "tell nobody" is the mitigation strategy that Google used here? They could have easily asked router vendors to patch their devices, asked ISPs to blackhole those customers until they're patched, etc.
- soperj 3y agoPatch what though? They know that they're getting hit with unprecedented traffic, not how those computers were infected.
- menscher 3y agoIt's mostly not infected computers, but rather poorly configured proxies that are open for anyone to bounce malicious traffic through. Convincing everyone to clean up their open proxies is a long-term, hard problem. But I plan to tackle it soon....
- superjan 3y agoHow? I suppose the most effective way is to have those proxies attack each other. But don’t, it’s likely illegal.
- soperj 3y agothe most efficient way would be to write a script that gains root on those open proxies and then fixes the issue.
- wsintra2022 3y agoEffective or efficient? Would seem rather inefficient to spend time researching all the possible ways to gain route on x number of servers, finding an exploit, crafting some plan to execute it, keeping your prints clean etc etc
- soperj 3y agoWhat way would be more efficient?
- menscher 3y agoGet a few companies to agree that open proxies are a scourge that needs to be stopped. They each apply some action to open proxies (user-facing messaging, loss of functionality, captcha, or complete block), and the users of those proxies will get the problem fixed. The hard part (and it truly is hard!) is convincing a few companies to do this. It risks user complaints in the short term, to solve a problem that may not be very acute for the largest companies (who can simply absorb these attacks).
- superjan 3y agoHow about downgrading all connections from said proxies to http 1.1? This can be done in coordination, but it ought not to be too hard to embed such ‘graylisting’ functionality in a webserver. (No I don’t expect any response but I am just leaving this thought for those who stumble on this thread in the future).
- deleted 3y ago[deleted]
- ExoticPearTree 3y agoSo you're saying Google and Cloudflare, just as an example, should block consumers of other ISPs because they run "unpatched" software or they have malware running on their devices? Lol, this is a very absurd and narrow minded view how the internet works. You deal with the traffic, you don't randomly block eyeball networks because they're attacking you.
- c0pium 3y ago> you don't randomly block eyeball networks because they're attacking you. ISPs do this literally all the time. They sell services that do this.
- KomoD 3y ago> the owners of those devices isn't going to be informed, nor is their ISPs not necessarily true
- WelcomeShorty 3y agoBut these ISPs that give something and inform and even isolate their infected customers are few and far between. Shout out to Dutch ISP XS4ALL who was (is?) very very strict and active in this space.
- mensetmanusman 3y agoGoogle should start using their ad network to silently update people’s security!