<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The IPS Guy &#187; IRC</title>
	<atom:link href="http://theipsguy.com/tag/irc/feed/" rel="self" type="application/rss+xml" />
	<link>http://theipsguy.com</link>
	<description>Intrusion Prevention/Detection technologies.</description>
	<lastBuildDate>Sat, 10 Dec 2011 21:25:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Detecting bot-nets</title>
		<link>http://theipsguy.com/detecting-bot-nets/</link>
		<comments>http://theipsguy.com/detecting-bot-nets/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 10:52:00 +0000</pubDate>
		<dc:creator>theipsguy</dc:creator>
				<category><![CDATA[IPS]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[IRC]]></category>

		<guid isPermaLink="false">http://theipsguy.com/?p=4</guid>
		<description><![CDATA[We here a lot about the rise of organized crime and the sophistication of the attackers. While this is true, in many cases I still see amateurish type attacks. While reviewing an IPS I found the following messages. IPS still provides a great way to detect bot-nets and while there is an obvious problem on [...]]]></description>
			<content:encoded><![CDATA[<p></p><div>
<p style="margin-bottom: 0in;"><script type="text/javascript"><!--
google_ad_client = "pub-8740217182751408";
/* 336x280, created 12/11/09 */
google_ad_slot = "0906882638";
google_ad_width = 336;
google_ad_height = 280;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></p>
<p style="margin-bottom: 0in;">We here a lot about the rise of organized crime and the sophistication of the attackers. While this is true, in many cases I still see amateurish type attacks.</p>
<p style="margin-bottom: 0in;">While reviewing an IPS I found the following messages. IPS still provides a great way to detect bot-nets and while there is an obvious problem on this network these IRC connections are being blocked by the IPS.</p>
<p style="margin-bottom: 0in;">An interesting article related to this can be found  <a href="http://www.networkworld.com/newsletters/techexec/2009/082409bestpractices.html?hpg1=bn">here.</a></p>
<p style="margin-bottom: 0in;">IRC Messages</p>
<table style="width: 192px; height: 58px;" border="0" cellspacing="0" cellpadding="0">
<col width="36"></col>
<col width="139"></col>
<tbody>
<tr>
<td width="36" height="20">:nick</td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td width="139">:msg</td>
</tr>
<tr>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
</tr>
<tr>
<td height="20">#usb</td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td style="vertical-align: top;"></td>
<td>Infected usb drive: E:</td>
</tr>
</tbody>
</table>
<p style="margin-bottom: 0in;">Interesting Nicknames to an IRC channel</p>
<p>VirUs-rigvgunl<br />
VirUs-rflkbvny<br />
VirUs-rexehaxz<br />
VirUs-rcpcmobp<br />
VirUs-rboinhcv<br />
VirUs-raquheuv<br />
VirUs-raozodkn<br />
VirUs-racgucrn<br />
VirUs-quyozuoc<br />
VirUs-qufnunld<br />
VirUs-msubtplz<br />
[03|MEX|XP|981734]<br />
[03|MEX|XP|444546]</p>
<p style="margin-bottom: 0in;">
</div>
<p></p>]]></content:encoded>
			<wfw:commentRss>http://theipsguy.com/detecting-bot-nets/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

