Book Image

Wireshark Network Security

By : Piyush Verma
Book Image

Wireshark Network Security

By: Piyush Verma

Overview of this book

Table of Contents (14 chapters)
Wireshark Network Security
Credits
About the Author
Acknowledgment
About the Reviewers
www.PacktPub.com
Preface
Index

IRC botnet(s)


Internet Relay Chat (IRC), is a chat system used to communicate over the Internet, while a botnet is a network of compromised machines (bots), which is remotely controlled by an attacker using a command and control (C&C) server. IRC is the most popular C&C channel used by botnets.

Note

The presence of IRC on a corporate network should raise a red alert!

Simply put, once a machine is compromised, it is programmed to connect to a preset IRC channel and wait for further instructions from the server. An attacker can then remotely control the compromised bot to perform actions on his or her behalf, and in the worst case scenario, an attacker can use multiple bots together and perform a catastrophic attack such as a Distributed Denial of Service (DDoS)(an attack against the availability of information under the umbrella of the popular CIA triad) against the target of choice.

Note

Refer to the following, for a better understanding of:

IRC communications: https://tools.ietf.org...