当前位置:网站首页>Internet of things botnet gafgyt family and backdoor vulnerability exploitation of Internet of things devices
Internet of things botnet gafgyt family and backdoor vulnerability exploitation of Internet of things devices
2022-06-30 21:11:00 【Qianli ZLP】
One 、 Virus introduction
Gafgyt( also called BASHLITE,Qbot,Lizkebab,LizardStresser) It's based on IRC Internet of things botnet program , Mainly used to initiate DDoS attack . It can take advantage of the built-in user name 、 Password dictionary telnet Blasting and righting IOT equipment RCE( Remote command execution ) Exploit vulnerabilities to spread themselves . On 2015 The source code was leaked and uploaded to github, Since then, many varieties have been derived , The next year on the Internet IOT The total number of infections on the equipment reached 100W.Gafgyt The family has initiated a peak 400Gbps Of DDoS attack . By 2019 end of the year ,Gafgyt The family is still apart from Mirai The largest active IOT botnet family outside the family .
Two 、 Function module
Gafgyt family bot The main functions of the program are divided into 3 A module :
1、Downloader modular . Hard coded by samples url download shell Scripts and other accompanying samples , Then execute the downloaded scripts and samples , Realization bot Program propagation ;
2、Scanner modular .bot After the program runs , First, the first packet will be sent to the control end , And this first package and the usual botnet There is a big difference in the first package of the virus family , common botnet The first package of the virus family contains information such as system configuration , and Gafgyt The first packet of data is “BUILD RAZER.”, The control end usually replies “!* SCANNER ON”, Command the controlled end to follow
边栏推荐
- oprator-1初识oprator
- B_QuRT_User_Guide(31)
- .netcore redis GEO类型
- SqlServer 获取字符串中数字,中文及字符部分数据
- Introduction of 3D Max fine model obj model into ArcGIS pro (II) key points supplement
- Adobe Photoshop (PS) - script development - remove file bloated script
- 电子方案开发——智能跳绳方案
- FreeRTOS记录(九、一个裸机工程转FreeRTOS的实例)
- MySQL简介、详细安装步骤及使用 | 黑马程序员
- centos——开启/关闭oracle
猜你喜欢

Study on lumiprobe modified triphosphate biotin-11-utp

3Ds Max 精模obj模型导入ArcGIS Pro (二)要点补充

B_QuRT_User_Guide(32)

stacking集成模型预测回归问题

凤凰架构——架构师的视角

Introduction of 3D Max fine model obj model into ArcGIS pro (II) key points supplement

RP原型资源分享-购物类App

银行集体下架的智能投顾产品,为何成了“鸡肋”?

Lvalue reference and lvalue reference

关于,奇安信检测代码漏洞,XSS系列解决
随机推荐
Open source internship experience sharing: openeuler software package reinforcement test
uniapp-路由uni-simple-router
mysql-批量更新
Lumiprobe生物素亚磷酰胺(羟脯氨酸)说明书
注册设备监理师难考吗,和监理工程师有什么关系?
Iclr'22 spotlight | how to measure the amount of information in neural network weights?
Understanding polymorphism
Peking University ACM problems 1001:exposition
Lumiprobe copper free click chemical solution
将博客搬至CSDN
k个一组反转链表
多表操作-外键约束
MySQL简介、详细安装步骤及使用 | 黑马程序员
Digital currency: far-reaching innovation
雷达数据处理技术
Adobe Photoshop (PS) - script development - remove file bloated script
Peking University ACM problems 1003:hangover
SQL必需掌握的100个重要知识点:创建和操纵表
B_QuRT_User_Guide(32)
【微服务~Nacos】Nacos之配置中心