Forgot your password?

typodupeerror
Botnet

+ - Hackers Buying IPV4 Blocks to Evade Detection->

Submitted by Trailrunner7
Trailrunner7 writes "One of the consequences of the exhaustion of the IPV4 address space is that not only are legitimate companies having a hard time finding IP blocks to use, so are the attackers. The number of IP addresses required for large scale botnets to operate effectively can be considerable, and finding large IP blocks to use for them can be difficult. And if they do find them, the IP addresses often are blacklisted quickly by reputation systems and are then useless for the attackers.

Now, in one effort to get around these systems, some attackers are taking advantage of the lack of IPV4 space by either purchasing or renting blocks of IP space with good reputations that have been built up over the course of several years. A number of legitimate trading and auction sites have appeared as the IPV4 space became scarcer, and the attackers have gotten involved as well, getting their hands on known good IP blocks and using them for C&C or hosting malware.

"The bad guys can buy or rent these as well, getting inside known good IP blocks so that the reputation systems don't blacklist them as quickly," Gunter Ollmann, VP of research at Damballa, said."

Link to Original Source
This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Hackers Buying IPV4 Blocks to Evade Detection

Comments Filter:

One of the most overlooked advantages to computers is... If they do foul up, there's no law against whacking them around a little. -- Joe Martin

Working...