Tuesday, November 16, 2010

Koobface, down but not out

Computerworld reported today a blow to the Koobface botnet. Of course, its interesting to note that the owner had multiple botnet severs all on the same IP space. Botnet 'best practices' (I use that term loosely) say the servers should be spread out all over the place, this way if one gets taken down it is still hard to take down the rest. This was also a detrimental blow to the Bredolab botnet, resulting in its televised (albeit staged) take-down. Koobface is interesting because it used almost entirely Social Networking Sites as its method of infection. And people get angry when they can't access Facebook at work...