<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Mirai on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/mirai/</link>
    <description>Recent content in Mirai on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 08 Dec 2016 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/mirai/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A short Addendum on the Mirai Botnet Blog Post</title>
      <link>https://insinuator.net/2016/12/a-short-addendum-on-the-mirai-botnet-blog-post/</link>
      <pubDate>Thu, 08 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/a-short-addendum-on-the-mirai-botnet-blog-post/</guid>
      <description>&lt;p&gt;While doing heap research on Linux processes (results are going to be published soon), I came across the bot from the Mirai Botnet. As already mentioned in the blog post by &lt;a href=&#34;https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/&#34;&gt;Brian&lt;/a&gt;, the Mirai bot uses obfuscated configuration data which contains e.g. the CnC server. When now confronted only with a bot (e.g. in the context of a running task or the ELF binary), but without the according source code, the decryption of this configuration data for e.g. incident analysis purposes might not be easily possible (with the python script from the blog post), if the key has been changed.&lt;br&gt;&#xA;But in this case that is not a problem at all, because&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Quick Insight Into the Mirai Botnet</title>
      <link>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</guid>
      <description>&lt;p&gt;As you might have read, &lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;I recently had a closer look at how easy it actually is to become part of an IoT Botnet&lt;/a&gt;. To start a further discussion and share some of my findings I gave a quick overview at the recent &lt;a href=&#34;http://day-con.org/&#34;&gt;Dayton Security Summit&lt;/a&gt;. The Mirai Botnet was supposed to be one of the case studies here. But the way things go if one starts diving into code…I eventually gave an overview of how the Mirai Bot actually works and what it does. As such: Here a quick summary of the Mirai Botnet bot.&lt;br&gt;&#xA;As described in my previous post, &lt;a href=&#34;https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/&#34;&gt;KrebsonSecurity.com was attacked by a major DDoS attack&lt;/a&gt;. Reaching between 620Gbps and 660Gbps it was the largest documented DDoS attack so far. The attack seemingly resulted from a Botnet called Mirai. Shortly after the attack, a &lt;a href=&#34;https://krebsonsecurity.com/2016/10/source-code-for-iot-botnet-mirai-released/&#34;&gt;post on hackforums&lt;/a&gt; claimed to contain the actual source code of just this botnet.&lt;br&gt;&#xA;The &lt;a href=&#34;https://github.com/jgamblin/Mirai-Source-Code&#34;&gt;source code&lt;/a&gt; consists of three projects: The bot itself with its CnC server and a loader component.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
