<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Cutting down botnet efficiency</title>
	<link>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Fri, 21 Nov 2008 00:42:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: Paulo</title>
		<link>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1570</link>
		<pubDate>Tue, 11 Oct 2005 13:41:41 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1570</guid>
					<description>This might be of some interest: &lt;a href="http://slashdot.org/article.pl?sid=05/10/11/1153204" rel="nofollow"&gt;Creators of Massive Botnet Arrested&lt;/a&gt; [Slashdot].</description>
		<content:encoded><![CDATA[<p>This might be of some interest: <a href="http://slashdot.org/article.pl?sid=05/10/11/1153204" rel="nofollow">Creators of Massive Botnet Arrested</a> [Slashdot].
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1567</link>
		<pubDate>Tue, 11 Oct 2005 11:43:46 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1567</guid>
					<description>Manni:
That could be an option in the future. But it's not really designed for a firewall blacklist. It's designed as a mailserver blacklist.</description>
		<content:encoded><![CDATA[<p>Manni:<br />
That could be an option in the future. But it&#8217;s not really designed for a firewall blacklist. It&#8217;s designed as a mailserver blacklist.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Manni</title>
		<link>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1566</link>
		<pubDate>Tue, 11 Oct 2005 08:50:55 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1566</guid>
					<description>Well, the Spamhaus XBL is just the database you want to have: http://www.spamhaus.org/xbl/index.lasso</description>
		<content:encoded><![CDATA[<p>Well, the Spamhaus XBL is just the database you want to have: <a href="http://www.spamhaus.org/xbl/index.lasso" rel="nofollow">http://www.spamhaus.org/xbl/index.lasso</a>
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1565</link>
		<pubDate>Tue, 11 Oct 2005 07:17:49 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1565</guid>
					<description>This type of blacklist will only be totally effective for as long as the bad guys haven't figured out P2P completely yet. I'd really like to see this thing work, but I know I'm not the person to do it.

I'm sure the blacklist would be huge. And hopefully there's a technical way to implement it, without slowing down web access?

Actually, I'd like to see something different than null routing. I'd like to see users redirected to some internal webpage. The log for that webpage could be used to find infected machines, and then (hopefully) alerting users.</description>
		<content:encoded><![CDATA[<p>This type of blacklist will only be totally effective for as long as the bad guys haven&#8217;t figured out P2P completely yet. I&#8217;d really like to see this thing work, but I know I&#8217;m not the person to do it.</p>
<p>I&#8217;m sure the blacklist would be huge. And hopefully there&#8217;s a technical way to implement it, without slowing down web access?</p>
<p>Actually, I&#8217;d like to see something different than null routing. I&#8217;d like to see users redirected to some internal webpage. The log for that webpage could be used to find infected machines, and then (hopefully) alerting users.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: RichardP</title>
		<link>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1563</link>
		<pubDate>Tue, 11 Oct 2005 02:43:53 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/10/10/cutting-down-botnet-efficiency/#comment-1563</guid>
					<description>I've heard that suggestion before.  I don't think a master central list is practical.  Reliable estimates suggest that more than a million machines belong to botnets at any particular moment.  A list that large is too large and too dynamic to load into router access control lists.  I suppose one could publish a BGP feed of the addresses and configure routers to null route those addresses, but that would cause a great deal of route table bloat.  In addition, I suspect the administration of such a list would be nightmare.  There are a number of mailing lists that spend a great deal of time with this issue, but they generally restrict list membership.  In particular, I am thinking of the drone armies/botnets research and mitigation mailing list, etc.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve heard that suggestion before.  I don&#8217;t think a master central list is practical.  Reliable estimates suggest that more than a million machines belong to botnets at any particular moment.  A list that large is too large and too dynamic to load into router access control lists.  I suppose one could publish a BGP feed of the addresses and configure routers to null route those addresses, but that would cause a great deal of route table bloat.  In addition, I suspect the administration of such a list would be nightmare.  There are a number of mailing lists that spend a great deal of time with this issue, but they generally restrict list membership.  In particular, I am thinking of the drone armies/botnets research and mitigation mailing list, etc.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
