[00:00.520 --> 00:10.200] There's a folder that extra MIRC INI files in, because you should only have one copy for each version of IRC that you've installed. [00:12.680 --> 00:21.140] And you can do hex editing, which is like, you don't even need to know how to program, you just need to know how to do search and replace and have it start off a different file than MIRC INI. [00:21.320 --> 00:26.780] So it really is easy to change it, so that's why it's not a good way to spot these things, is just to look for that. [00:29.140 --> 00:39.800] You can kill the process and delete the files, and the problem is finding the process and making sure that it's stopped and there isn't anything else that you haven't caught that's still related to the bot. [00:42.060 --> 00:49.560] Don't type anything into the bot, because you never know what people have added as a Trojan, hey, I've been discovered, I must destroy everything kind of routine. [00:50.400 --> 00:53.120] Don't use a bot for chat, even though it's right there and it's really easy. [00:53.660 --> 00:55.880] It's bad, so you don't want to use it for chatting. [00:55.880 --> 00:59.720] Of course, people have done this all before, and it's done horrible things to their machines. [01:01.980 --> 01:03.940] And then, so that was GTBot. [01:04.040 --> 01:07.440] The other big oldie but giddy is SDBot, which is more or less the same thing. [01:08.240 --> 01:11.720] It does pretty much the same stuff. [01:19.090 --> 01:27.330] It's a problem if your IRC server goes away, then that bot is sort of open out in the way, when you can't have that stuff. [01:30.130 --> 01:32.910] People have figured out how to get around that, so now they're empty and open. [01:35.210 --> 01:58.410] It also is so old that if you use something like Macafone, you can get all the old rules about GTBot apply to SDBot, and this is the demonstration portion where I had this cool demonstration with three victim machines that would get infected and then join my Linux IRC server. [01:59.090 --> 02:00.630] Oh, it is responding. [02:02.970 --> 02:08.410] But for some reason, even though it was working before, it wasn't working now. [02:09.470 --> 02:17.610] So I can go with you into an imagination journey where you can pretend like you're seeing this demonstration work. [02:17.610 --> 02:26.580] And what you'd see is, on this screen here, there would be an IRC channel. [02:27.100 --> 02:30.800] And it would be called like, I like hacking or something. [02:35.030 --> 02:36.150] And, okay. [02:36.430 --> 02:51.390] Anyway, and then over here on this window, you would see an average looking Windows 2000 desktop, which looks perfectly normal except there would be a file on the desktop called like GTBot or something like that. [02:52.910 --> 02:55.150] And, let's see if I can get out of this. [02:55.410 --> 02:56.970] I think I have a copy on this desktop. [02:57.190 --> 03:02.470] But you, ah, you basically, you would click on the GTBot application. [03:02.610 --> 03:03.610] You would do the thing I mentioned before. [03:03.730 --> 03:05.430] A window would flash up and then nothing would happen. [03:05.550 --> 03:07.590] You'd look on the system manager. [03:07.590 --> 03:08.730] You wouldn't see anything. [03:08.730 --> 03:19.710] And then if you had to speed up running, you would see a bunch of traffic going from that victim to port 667 on the IRC server, which would be the Linux machine. [03:23.230 --> 03:28.510] And then you'd use some of the commands that I highlighted earlier, like the scan and whatever command. [03:29.230 --> 03:31.110] And you'd see the bots do stuff. [03:31.270 --> 03:32.670] And you'd be like, oh, that was really cool. [03:32.730 --> 03:33.670] I got to do this at home. [03:33.670 --> 03:40.410] And then you'd be thoroughly convinced that this is a big problem. [03:40.750 --> 03:41.890] And you should pay attention to it. [03:42.030 --> 03:42.750] And just, like... [03:42.750 --> 03:44.050] So that was the demonstration. [03:45.090 --> 03:47.090] The imagination demonstration. [03:48.310 --> 03:52.150] Which is, we were working at DEFCON last year, so I didn't realize that's not working now. [03:52.350 --> 03:54.990] But that's what computers do, is they... [03:58.370 --> 03:59.670] And then we'll on to the next part. [03:59.930 --> 04:01.670] We detect a botnet on your network. [04:02.310 --> 04:03.530] So if you're... [04:03.530 --> 04:08.590] Average Joe six-pack sitting at home with your Windows machine, you can revire a scanner. [04:08.910 --> 04:16.930] If you're a network admin person, and you've got cool, expensive Cisco equipment, and you know how to use flows, which isn't a cool log. [04:17.250 --> 04:19.610] People don't know about Cisco flows. [04:19.990 --> 04:23.430] I think it's basically like traffic logs, one or less. [04:23.870 --> 04:27.830] You look for flows to port 667, which is the IRC server port. [04:28.030 --> 04:32.730] And you look for timing correlations between different traffic, because flows won't give you the contents of the packet. [04:32.930 --> 04:39.130] It will give you the time that it was sent, where it was from, where it was to, the packet size. [04:39.510 --> 04:43.050] But it's not strictly a per-packet kind of log thing either. [04:43.730 --> 04:50.590] But since you won't see the content of the packet, you need to look for timing and patterns between the port numbers, and things like that. [04:50.590 --> 05:00.090] So you'd look for incoming scan to port 445, which for the purposes of this talk, you can say easy to hack Windows machine port. [05:00.710 --> 05:08.570] And going to machine A, you can assume it's been compromised if, right after that, machine A starts sending out IRC traffic. [05:11.030 --> 05:12.790] It's easy to spot correlations like that. [05:13.210 --> 05:27.310] You can use a, if you have a lot of time in your hands, you can use an IDS like Snort, which has like 3 billion signatures, and can give you a lot of logs that are too time consuming to look through, especially if you have a paying job, and you want you to do stupid things like good news. [05:30.950 --> 05:36.290] Snort will look at the packet contents, but bots can get around this by either changing the commands. [05:36.530 --> 05:41.290] Like, there's standard commands that will, like, bang scan and say, oh, look for bang scan. [05:41.510 --> 05:48.210] If there's anything coming from a machine, it says bang scan and it must be infected, but you can always change the bang scan command to go get him. [05:48.610 --> 05:54.670] It's not going to look for go get him, it's going to look for scan, and then Snort will just completely gloss over that machine. [05:54.970 --> 06:01.730] Also, some bot variations can encrypt their traffic, which makes it harder to inspect, and look for them. [06:02.810 --> 06:08.870] Otherwise, the laziest way by far is to subscribe to the English and they'll tell you that you're infected, and you need to look for machines themselves. [06:10.270 --> 06:17.050] Which, unfortunately, we've had to stoop to at the university because there's just so many infected machines. [06:17.870 --> 06:28.510] You have people that will look full time for these kind of, for these bot herds, and they'll hang out on channels, they'll look for hidden channels on IRC servers, and stuff like that. [06:29.190 --> 06:36.910] And then they'll try to get a list of all the IP addresses of the clients that are on that channel, but a lot of times the IPs are hidden. [06:37.210 --> 06:43.330] So either they'll send you a list of IPs and say, hey, you idiot, you've got this hacked machine on it, or do something about it. [06:43.610 --> 06:45.970] Or they'll say, this is the IRC server. [06:46.110 --> 06:48.490] Everybody look for the flows going to this IRC server. [06:48.490 --> 06:51.530] If you're connecting this IRC server, you've probably been infected. [06:52.490 --> 06:54.330] And that's another way to track it down. [06:55.570 --> 06:58.530] The only problem with things like FIRST, which is like the... [06:58.530 --> 07:14.290] I always get this wrong, it's like the forensic and incident response team or something, is that you need to pay them to be part of them, which is good for old people that work for corporations, but not so good for people that don't have a lot of money or young. [07:14.290 --> 07:17.610] And they're mostly like an older group of people, like all in their 40s. [07:17.790 --> 07:20.210] So if you're into that kind of thing, you should definitely check them out. [07:21.470 --> 07:29.810] Also, there's UNISOG, which is kind of... it's got a funny name, but it's a university security officers group, I think. [07:30.050 --> 07:34.910] And sometimes you get botnet reports on there, but mostly they're university people, so we can assume that they're lazy. [07:35.150 --> 07:37.330] And so they aren't going to look for bots a lot. [07:37.690 --> 07:41.890] But they still occasionally come through and tell you that you've been hacked. [07:44.610 --> 07:47.810] Also, they'll tell you things like, hey, there's this new kind of bot, you should check it out. [07:47.950 --> 07:49.670] It can be a case on this port or whatever. [07:50.210 --> 07:57.970] You can use a really expensive piece of equipment called a packeteer, which looks at all the packets on your network and will do sort of... [07:58.710 --> 08:07.630] not exactly trend analysis, but it will do things like tell you who's been sending the most files on IRC, or they call them the top DCC talkers. [08:08.490 --> 08:09.450] And usually if you've... [08:09.450 --> 08:11.690] I found on the university network, the people who... [08:11.690 --> 08:16.230] there's like a big difference between hacked people sending DCC traffic and regular people. [08:16.470 --> 08:18.370] So they stick out like a store of thumb. [08:20.970 --> 08:23.570] And high traffic usually indicates an IRC bot. [08:23.750 --> 08:28.530] And it may or may not be a DDoS bot herd bot. [08:28.650 --> 08:31.430] It could also be people trading movies and things like that. [08:31.810 --> 08:38.790] For our purposes at the university, they're both the same thing more or less, but it's not necessarily going to be a botnet if that's what you're looking for. [08:39.630 --> 08:48.270] Also, you can look for machines with lots of IRC traffic and lots of UDP or ICMP traffic which indicates they're attacking with UDP or ICMP attacks. [08:48.890 --> 08:51.110] That's only really noticeable when the botnet is attacking. [08:51.370 --> 09:00.390] So I mean, you can either say like all people who use IRC are bad and just look for all those people and then sniff their traffic and see who they're talking to and what embarrassing secrets they're sharing with people. [09:00.530 --> 09:07.570] Or you can just ignore IRC altogether and wait for your network to fall over, which is what we've adopted as our policy. [09:09.070 --> 09:10.890] So I say, take my network, please. [09:15.730 --> 09:20.110] So yeah, and there's different ways depending on how you want to manage your network. [09:21.090 --> 09:25.010] You can use those two different ways of finding IRC bots in general. [09:25.630 --> 09:30.190] Also, if you're on IRC, you can tell if there's an IRC bot in your presence. [09:30.190 --> 09:34.030] It'll have usually some weird character combination name. [09:34.030 --> 09:38.110] It'll be like XWZ 50967. [09:38.650 --> 09:40.050] And then you'll go, that's a bot. [09:40.150 --> 09:40.770] And you'll kick it off. [09:40.890 --> 09:41.690] And then it will join again. [09:41.830 --> 09:44.290] And only its name will be XWZ 50968. [09:45.090 --> 09:46.550] And then you'll keep kicking it off. [09:46.610 --> 09:48.410] And it'll keep iterating its number by one. [09:48.510 --> 09:50.450] And it's really annoying. [09:50.630 --> 09:54.350] And then you usually have to, like, ban the IP address it's coming from. [09:54.510 --> 09:56.610] But since they're everywhere, they'll probably join again. [09:57.210 --> 10:02.850] Usually they're not as much of a public nuisance anymore, because people have figured out they can set up their own IRC servers pretty easily. [10:03.030 --> 10:06.630] So you don't have people hanging out as much on Dallnet and Fnet. [10:06.810 --> 10:07.790] Although that does happen a lot. [10:07.950 --> 10:09.330] But then it makes it easier to get caught. [10:12.930 --> 10:16.410] Also, I saw this Ouija board online. [10:16.590 --> 10:18.150] It's like an internet Ouija board. [10:18.230 --> 10:22.070] Where you've got, like, basically a number pad. [10:22.070 --> 10:23.950] Where you can select an IP address. [10:24.190 --> 10:25.790] And then there's things like worm virus and whatever. [10:26.670 --> 10:30.730] I haven't seen it, like, made, manufactured in mass amounts. [10:30.930 --> 10:37.830] But if you're into Ouija boards and the paranormal and helping you psychically find hacked machines, you could always use that. [10:39.050 --> 10:41.090] Probably a regular Ouija board would work fine too. [10:41.230 --> 10:43.310] But the numbers aren't optimized in their layout. [10:44.150 --> 10:45.510] So it might take a little longer. [10:48.190 --> 10:50.250] Actually, I don't know if there's any, like, really dead... [10:50.250 --> 10:52.630] There's dead, really famous hackers that could help you with that. [10:52.790 --> 10:54.370] Because, I guess, Kevin Mitnick's still alive. [10:54.510 --> 10:56.490] But then would he really help you for good or for evil? [10:57.130 --> 10:57.890] So, yeah. [10:58.010 --> 10:59.150] That's another discussion generally. [11:00.190 --> 11:02.110] Also, you can look for DNS traffic. [11:02.330 --> 11:06.770] Which, now, when I was talking about the problem of orphaned machines, people have gotten... [11:07.590 --> 11:10.750] They've fixed that by using DynDNS. [11:10.930 --> 11:12.990] Or I always call it DinDins, because that's what it looks like to me. [11:14.230 --> 11:20.190] And you look for traffic going to DynDNS hostnames. [11:20.190 --> 11:22.530] That have suspicious, really obvious names. [11:22.770 --> 11:25.350] Like, haxor.dyndns.org. [11:25.970 --> 11:28.590] Or evil.dyndns.org. [11:28.850 --> 11:31.390] And the reason for that is with the... [11:31.390 --> 11:32.970] They call it the CNC methodology. [11:33.310 --> 11:35.610] Which is another military term, meaning command and control. [11:37.710 --> 11:40.770] I don't know where all these, like, military people come into the hacking world. [11:40.810 --> 11:42.030] People like Lance Spitzner. [11:42.250 --> 11:44.370] But I'm not sure about anybody other than that. [11:45.150 --> 11:47.530] I guess there's, like, Eliot Spitzer, too. [11:47.530 --> 11:49.550] And Greg Shipley and things like that. [11:49.890 --> 11:53.350] But these people have decided to define a vocabulary for us. [11:53.470 --> 11:56.210] And what they've decided to call this is a command and control methodology. [11:57.390 --> 11:59.830] And what that is is your... [12:00.650 --> 12:04.650] IRC server is your command and control machine. [12:04.990 --> 12:09.270] And so that's where everyone goes to to get commands and where you control it from. [12:09.270 --> 12:13.570] And normally you configure your bot software. [12:13.670 --> 12:15.450] Before you ever deploy it, you... [12:15.450 --> 12:16.390] There's, like, options. [12:16.830 --> 12:17.270] You can, like... [12:17.270 --> 12:20.250] I guess there's probably a menu option, too, that says, like, preferences options. [12:20.670 --> 12:28.190] And you go there and you say, I want everything to connect to evil.dyndns.org as my IRC server. [12:28.510 --> 12:33.570] And the great thing about DynDNS is it's dynamic DNS. [12:33.570 --> 12:35.790] So you can update the IP address any time you want to. [12:36.450 --> 12:39.870] You go out and you infect a lot of machines. [12:39.870 --> 12:40.650] You make them... [12:40.650 --> 12:46.910] You tell them to connect to the host name instead of an IP address of, like, evil.dyndns.org. [12:48.010 --> 12:55.230] And then if your command and control machine is ever found, it's not a big deal because you just compromise another machine. [12:55.430 --> 12:56.930] Make that the command and control machine. [12:57.030 --> 12:58.990] And then you update your DNS record. [12:59.430 --> 13:02.970] Which, I think, updates within a matter of, like, one or two minutes or something. [13:03.230 --> 13:04.110] So it's pretty easy. [13:04.490 --> 13:12.270] Everything has become such a commodity nowadays in terms of the zombie and the hacked machines and the command and control machines. [13:12.450 --> 13:13.970] That everything is very mobile operation. [13:14.410 --> 13:16.210] This is a very desert storm kind of thing. [13:17.870 --> 13:20.030] And there's more military things. [13:20.590 --> 13:25.310] So, yeah, I try to get tickets to the Daily Show, but they're backed up for, like, six months. [13:25.450 --> 13:26.890] So instead I have a picture of Jon Stewart. [13:28.390 --> 13:37.870] But what's new in the last year is Agobot and Fatbot were two bots written by this German guy. [13:38.450 --> 13:41.910] I don't know if anybody here knows what his name was because I forget what it is. [13:42.370 --> 13:47.430] And he wrote these, like, super efficient evil network killing machines. [13:47.670 --> 13:48.950] And then he got arrested. [13:49.470 --> 13:52.190] And when he got arrested, he stopped doing tech support. [13:52.270 --> 13:54.570] And when he stopped doing tech support, people were really lazy. [13:54.630 --> 13:56.210] And they're like, I don't know if I want to use this. [13:56.210 --> 14:04.610] So they went back to the old goodies that have... goodies but oldies, which have documentation and usage statements like GDpot and SDbot. [14:05.730 --> 14:08.190] And at the time, though, Agobot was, like, the shit. [14:08.390 --> 14:10.350] Because people thought it was, like, slammer. [14:10.450 --> 14:11.230] But then it wasn't. [14:11.390 --> 14:15.510] And it was really hard to figure out what was going on with Agobot. [14:15.850 --> 14:20.390] But it's basically an IRC bot like any other IRC bot. [14:20.390 --> 14:23.010] And it comes for you with a scan and compromise engine. [14:23.230 --> 14:24.530] So it spreads in a worm-like fashion. [14:24.690 --> 14:26.750] So you don't need to... [14:28.630 --> 14:29.830] I got a yellow card. [14:30.050 --> 14:30.810] It's like a soccer thing. [14:31.770 --> 14:32.930] I think it's a soccer thing. [14:33.230 --> 14:33.530] Anyway. [14:34.030 --> 14:38.210] So you don't have to go through the trouble of installing your own module to compromise... [14:38.210 --> 14:40.670] To do scanning and compromise because it comes with it. [14:40.810 --> 14:44.990] So it's very much more appealing to the AOL user who wants to be a hacker kind of thing. [14:46.770 --> 14:51.730] Fatbot used peer-to-peer to talk to other machines instead of IRC. [14:51.990 --> 14:55.190] Which is another thing that confused people who looked for this sort of thing. [14:55.250 --> 14:56.670] They're like, but it doesn't use IRC. [14:56.790 --> 14:57.930] How can it be an IRC bot? [14:58.390 --> 14:59.190] It uses peer-to-peer. [14:59.290 --> 15:00.730] We don't know how to regulate that sort of thing. [15:01.770 --> 15:05.310] But then all that stopped when he got arrested. [15:05.470 --> 15:06.710] And I'm sure there's people using it. [15:06.930 --> 15:08.930] People who, like, want to go through the trouble of figuring it out. [15:09.030 --> 15:09.830] But most people don't. [15:11.290 --> 15:12.750] So they use the old stuff. [15:12.750 --> 15:14.670] There's another sexy picture of Jon Stewart. [15:15.210 --> 15:15.630] And... [15:16.210 --> 15:16.990] Which is... [15:16.990 --> 15:18.570] Have you ever seen Rainforest Puppies talks? [15:18.570 --> 15:19.590] He's got naked women. [15:19.750 --> 15:20.930] So that's sort of my answer to that. [15:21.650 --> 15:24.750] But you've got also RXBot or RBot. [15:25.070 --> 15:27.050] Which was another, like, brand new bot. [15:27.210 --> 15:31.390] Which is a variant of Agobots that probably also is not as popular anymore. [15:31.390 --> 15:32.850] Just because it's a variant of Agobot. [15:33.050 --> 15:36.250] Because the guy who wrote Agobot really was a good text part guy. [15:36.370 --> 15:37.330] He fixed a lot of problems. [15:37.350 --> 15:41.370] He was always taking new suggestions for features and things like that. [15:41.370 --> 15:42.470] And coding them up. [15:43.610 --> 15:46.310] The cool thing about RBot is that it scans really quickly. [15:46.670 --> 15:49.630] Fast enough to deny a live service machine just by scanning it. [15:50.370 --> 15:52.330] And also there's this program out there called Librea. [15:52.650 --> 15:54.250] Which is like the Librea tar pits. [15:54.430 --> 15:57.170] Where it will keep all the connections open once you've connected to it. [15:57.550 --> 16:00.410] It's kind of like a honey pot with, like, really sticky honey, sort of. [16:00.410 --> 16:05.430] And so if you're trying to scan a machine or scan, like, thousands of machines at once. [16:05.590 --> 16:07.790] You're counting on the connections close. [16:07.970 --> 16:10.210] You have enough memory in every bandwidth. [16:10.530 --> 16:13.550] Or actually memory in CPU cycles. [16:14.130 --> 16:17.070] And network stack space that you can keep scanning more stuff. [16:17.210 --> 16:18.890] What Librea does is it keeps everything open. [16:19.190 --> 16:20.550] And then your scan takes forever. [16:20.870 --> 16:22.210] And you're like, why isn't this returning? [16:22.210 --> 16:24.430] So this foils Librea by... [16:24.850 --> 16:27.830] If it takes too long to get a response, it will kill the threads. [16:29.570 --> 16:32.090] And so I guess that's kind of cool. [16:32.730 --> 16:34.930] Although I don't know anybody who uses Librea. [16:35.210 --> 16:36.310] I'm sure people do. [16:36.510 --> 16:38.950] And if you do, then it will foil you. [16:39.490 --> 16:39.750] Ha, ha. [16:40.450 --> 16:43.550] Also, spam is another really irritating trend. [16:43.730 --> 16:45.510] You see a lot of people paying... [16:45.510 --> 16:47.550] Spammers will pay hackers to break into machines. [16:47.550 --> 16:50.550] Which now is really easy with Microsoft being everywhere. [16:50.550 --> 16:52.630] Well, I guess it's always been easy. [16:52.890 --> 16:54.250] Because Microsoft being everywhere. [16:54.470 --> 16:57.730] But you have spammers paying hackers to break into machines. [16:58.030 --> 17:01.730] And then saying, here, send three million copies of my Viagra ad out to everybody. [17:01.970 --> 17:06.550] And then the hackers will use their botnets for profit. [17:07.450 --> 17:08.490] Not necessarily good. [17:08.710 --> 17:10.510] And just send spam to people. [17:10.750 --> 17:18.030] So now when we see spam bots on our network, it's generally probably going to be something that's compromised with an IRC bot too. [17:18.030 --> 17:26.970] So if you're looking at people that are sending lots of port 25 traffic, that's sometimes a way now to find IRC bot clients. [17:27.270 --> 17:30.370] And we have URLs for further reading. [17:31.030 --> 17:34.430] Where you can download things like GT bot, SD bot. [17:35.790 --> 17:36.350] The... [17:36.350 --> 17:38.030] I think it's the link at the bottom. [17:38.250 --> 17:41.810] Which is like web linksource.com slash bots slash bots dot html. [17:41.810 --> 17:45.510] Has like 3,000 different kinds of bots. [17:45.690 --> 17:46.830] Probably more like 300. [17:47.470 --> 17:50.810] But it's sort of like an archive where it goes back a while. [17:51.110 --> 17:52.990] And you got your different variants. [17:53.190 --> 17:55.910] And people are always fucking with things and uploading it. [17:55.990 --> 17:57.490] And so it does more cool stuff. [18:00.930 --> 18:02.730] And then there's egg drop. [18:03.010 --> 18:04.730] Which is pretty easy to find because it's not evil. [18:04.730 --> 18:06.150] And BNC. [18:07.870 --> 18:11.010] And I can bring up that URL thing. [18:11.170 --> 18:11.430] But yeah. [18:11.670 --> 18:15.190] So I for one welcome our new robot masters in the spirit of Jamie Zawinski. [18:15.810 --> 18:18.810] So that's the talk. [18:19.690 --> 18:21.450] So any questions or comments? [18:23.630 --> 18:24.110] Oh. [18:29.280 --> 18:30.360] Just done the silence. [18:31.980 --> 18:34.440] Do you guys use egress writing at the university? [18:34.780 --> 18:35.460] Yeah, we do. [18:36.220 --> 18:36.720] Do you help at all? [18:39.080 --> 18:43.180] It helps just the spoofed stuff not take down the network. [18:43.320 --> 18:45.720] But people managed to take down our network even without that. [18:46.440 --> 18:48.920] But now it's like such a branded thing if you don't have it. [18:49.080 --> 18:52.480] And finally embarrassed our networking guys into installing it. [19:00.160 --> 19:02.940] I know it's enough to live off of from what I hear. [19:03.440 --> 19:04.320] I mean it's probably... [19:05.640 --> 19:12.340] Yeah, I mean there's probably some like free market thing where the spammers need to be paid less than what... [19:12.340 --> 19:16.140] Spammers need to pay the hackers less than what they're making from the spam. [19:16.320 --> 19:18.600] But it's probably like a couple hundred dollars or something like that. [19:18.820 --> 19:22.040] I know there's people that do make a living off of it though if you've got enough contacts. [19:25.160 --> 19:28.460] Which network segments have the worst botnet activity? [19:28.580 --> 19:30.140] The CS or the liberal arts? [19:32.380 --> 19:32.900] Huh. [19:33.280 --> 19:35.820] It's definitely liberal arts because there's more windows machines. [19:36.380 --> 19:41.600] The CS people have like now it's considered a sophisticated tax which is just root kits. [19:41.900 --> 19:45.840] Because those are so much more sophisticated than the brain dead stuff that the liberal arts people are doing. [19:47.700 --> 19:48.220] Yeah. [19:50.100 --> 19:50.620] Okay. [19:50.820 --> 19:52.080] What's the largest botnet you've seen? [19:52.580 --> 19:58.720] And then have you, in tracing some of these botnets, found any instances of connections to organized problems? [19:58.880 --> 20:00.180] There's been several articles about that lately. [20:00.180 --> 20:00.680] Huh. [20:00.680 --> 20:05.920] Not only connections to spam that little, you know, trade off that economy on the spammers and hackers. [20:06.100 --> 20:06.880] But also a little . [20:07.460 --> 20:08.160] Oh, okay. [20:08.460 --> 20:10.960] I think the largest botnet I've seen was... [20:10.960 --> 20:12.820] I haven't seen it but I've heard of it. [20:12.980 --> 20:15.960] It was something like maybe 100,000 bots or something like that. [20:17.000 --> 20:18.960] I don't know about the connection to organized crime. [20:18.960 --> 20:23.400] It wouldn't surprise me if there was some kind of connection since they're always... [20:23.400 --> 20:29.480] Organized crime is big on using encryption and other evil technologies that the government doesn't want you to use. [20:29.700 --> 20:31.140] But that'd be... [20:31.140 --> 20:31.620] Do they... [20:31.620 --> 20:33.780] What do the organized crime people do with the botnets? [20:34.000 --> 20:41.400] Well, it was kind of, you know, the article that I was reading recently talked about Eastern European organized crime and stuff like that. [20:41.800 --> 20:45.120] But it's kind of, you know, the same protection that I get. [20:45.700 --> 20:50.120] If you don't pay me to protect your online store, I'll unleash the denial of service. [20:50.360 --> 20:51.220] I'll take it back. [20:52.360 --> 20:54.660] Yeah, that's another good business model. [20:57.760 --> 21:01.960] Either people pay you to spam people or people pay you not to attack them. [21:02.840 --> 21:03.040] But yeah. [21:04.160 --> 21:05.440] Oh, that sounds like a good racket. [21:07.520 --> 21:07.940] Okay. [21:08.800 --> 21:09.600] Well, thank you. [21:09.760 --> 21:11.120] Thank you for waking up so early.