Snort mailing list archives
got signatures for instant messaging?
From: Abe Usher <abe.usher () sharp-ideas net>
Date: Tue, 05 Oct 2004 01:09:39 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Let's revisit the security risks of instant messaging. I've created a small proof of concept named "nmapbot" that shows it is possible to use instant messaging as a platform for remote command and control of computer systems. Purpose: - -------- To create a semi-intelligent security bot that uses instant messaging as a platform for receiving commands and returning results. Method: - ------- Using Python, the AOL TOC protocol, Bayesian language processing, and nmap 3.70, I hacked together a little bot that can run nmap and ping. Future editions will include additional commands =) Security pundits have been promoting the idea that IM is unsafe for several years... nmapbot provides some new considerations to an old idea -- using ordinarily legitimate communication channels for unintended purposes. The nmapbot rests squarely on the shoulders of python and projects such as Py-AIML, AIMLBayes, GrokItBot, and Reverend. Many thanks to fyodor et al. for the excellent tool suite in nmap 3.70. If you are interested, you can find source code and documentation for nmap bot at: http://www.sharp-ideas.net Cheers, Abe Usher, CISSP -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFBYiyTT3X9miqOcSQRAm63AJ4sX6sYxClorye4+LcYJobPTvMKZgCfZwoO gYApzfOgYNbhOKAZ9xs8py4= =dpMf -----END PGP SIGNATURE----- ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- got signatures for instant messaging? Abe Usher (Oct 14)
