PDA

View Full Version : Bot-Nets



utnubuuser
April 27th, 2009, 12:29 AM
Hi -- I was reading an article about Spam-bots and bot-nets, and it made me wonder if gnu/linux boxes are to be found among the millions of spam-bots and bot-networks out there, or if gnu/linux is immune to that particular scourge? (And I'm only interested in very general terms, as regards out-of-the-box installations).


Any general facts/opinions are appreciated.

Thanks

SunnyRabbiera
April 27th, 2009, 12:55 AM
actually there is a rather nasty botnet virus that effects linux powered modems and could compromise a whole system.
Ubuntu was Vulnerable to it, but it only effects people with certain kinds of routers and people with careless router passwords.

MadCow108
April 27th, 2009, 01:11 AM
There have been (and probably still are) a few botnets consisting of linux and mac machines.
old source: http://voices.washingtonpost.com/securityfix/2006/03/when_macs_attack.html
But because of the lower spread of badly configured linux pcs they aren't such a big problem compared to the millions of windows pcs which are part of botnets.

Also the chance of getting infected is lower because most malware is still written for windows.
But it's not zero.

cariboo
April 27th, 2009, 01:14 AM
If you check through the Security Discussions Forum (http://ubuntuforums.org/forumdisplay.php?f=338) you will find many instances of people having their computers cracked and made a member of a bot-net. This usually happens because of lax security, for instance having a guest account with admin privileges with a password of guest.

Make sure you have a strong password and don't run any services you don't need.

MaxIBoy
April 27th, 2009, 01:16 AM
actually there is a rather nasty botnet virus that effects linux powered modems and could compromise a whole system.
Ubuntu was Vulnerable to it, but it only effects people with certain kinds of routers and people with careless router passwords.It's been deactivated by its creator (who was only trying to figure out how many he could get, he didn't plan on actually doing anything with it. You could clear your router by unplugging it, then replugging it, as there's no writable storage.)


This has been the only major Linux botnet I know of (besides voluntary things like Folding@Home, SETI@Home, etc.)

utnubuuser
April 27th, 2009, 02:44 AM
Thanks Guys -- Pretty much what I expected to hear.