Login Register






Development of a Linux Botnet Coded in Python filter_list
Author
Message
Development of a Linux Botnet Coded in Python #1
Alright guys, so I've decided to start on a project.
Basically, what this will do will scan Linux boxes for the default SSH port and try logging in as root with no password.
It will keep a log of all vulnerable boxes and allow you to control them all at once.
I'm pretty sure I can do this, as I already have everything implemented in my head.
I will be using Fabric as a module to do this.
If I can create this, it will be the "endall" of all botnets.
Imagine controlling millions (hypothetically) of rooted Linux servers.
The possibilities are endless...
I'm having a nerdgasm thinking about this!
What are your thoughts, guys?

Reply

RE: Development of a Linux Botnet Coded in Python #2
(01-07-2014, 01:20 AM)Necrosis Wrote: Alright guys, so I've decided to start on a project.
Basically, what this will do will scan Linux boxes for the default SSH port and try logging in as root with no password.
It will keep a log of all vulnerable boxes and allow you to control them all at once.
I'm pretty sure I can do this, as I already have everything implemented in my head.
I will be using Fabric as a module to do this.
If I can create this, it will be the "endall" of all botnets.
Imagine controlling millions (hypothetically) of rooted Linux servers.
The possibilities are endless...
I'm having a nerdgasm thinking about this!
What are your thoughts, guys?
Are you adding a built in IP Scraper, and I could be wrong, but I don't think that SSH can have no password.
#MakeSinisterlySexyAgain

Reply

RE: Development of a Linux Botnet Coded in Python #3
(01-07-2014, 01:49 AM)Adorapuff Wrote: Are you adding a built in IP Scraper, and how will you be testing for vulnerabilites?
I'm not necessarily looking for vulns, I'm just searching for root accounts with no password and then executing a command on one machine to all of them.
I'll probably just modify a port scanner and then output all of the IPs to a text file, then call of them when the command is executed.

Reply

RE: Development of a Linux Botnet Coded in Python #4
(01-07-2014, 01:54 AM)Necrosis Wrote: I'm not necessarily looking for vulns, I'm just searching for root accounts with no password and then executing a command on one machine to all of them.
I'll probably just modify a port scanner and then output all of the IPs to a text file, then call of them when the command is executed.
Yeah, makes sense, you could import an auto-pwn for servers running say ColdFusion, Tomcat with no security, etc
#MakeSinisterlySexyAgain

Reply

RE: Development of a Linux Botnet Coded in Python #5
Oh my god, I should have remembered that SSH can't have no password...
I'll probably just use root and password, or root and root.
I'll have to do more research.

(01-07-2014, 01:55 AM)Adorapuff Wrote: Yeah, makes sense, you could import an auto-pwn for servers running say ColdFusion, Tomcat with no security, etc
Hmmmm... Maybe a Metasploit plugin would be more efficient.
I hadn't even thought of that.
(This post was last modified: 01-07-2014, 01:58 AM by Hellborn.)

Reply

RE: Development of a Linux Botnet Coded in Python #6
Someone already did this, he used it to make heat maps of computers, as he compromised a huge amount of computers, with china having the highest density of vulnerable servers.

http://arstechnica.com/security/2013/03/...addresses/

Unfortunately for you, my impression isn't that you know enough programming to make this feasible, not to mention that the computers you would compromise aren't likely to have high power or bandwidth.

Reply

RE: Development of a Linux Botnet Coded in Python #7
You lost me on the second line :O
But good luck completing this man! Biggrin

Oh and have fun Tongue

Reply