Hacker News new | ask | show | jobs
by noobermin 3745 days ago
>From my past experience

I'm curious how you know this for sure.

1 comments

I plead the fifth. CFAA/RICO/Patriot Act.

My hint would be: before decentralized worms, there were IRC hubs. The 'owners' would typically use their native language for the various commands (I know English is used in more than the US, but..). Most of the time, they wouldn't even hide their host name on the IRC server.

I guess from a 'being legal' POV: anyone could infect themselves with the same root kit that's on a honeypot and find out quite a bit about the organizers.

Or just read any botnet takedown report, this is exactly what botnets do. Why bother looking for 0day when root:toor or cisco:cisco works?