IRC botnet(s)

Internet Relay Chat (IRC), is a chat system used to communicate over the Internet, while a botnet is a network of compromised machines (bots), which is remotely controlled by an attacker using a command and control (C&C) server. IRC is the most popular C&C channel used by botnets.

Note

The presence of IRC on a corporate network should raise a red alert!

Simply put, once a machine is compromised, it is programmed to connect to a preset IRC channel and wait for further instructions from the server. An attacker can then remotely control the compromised bot to perform actions on his or her behalf, and in the worst case scenario, an attacker can use multiple bots together and perform a catastrophic attack such as a Distributed Denial of ...

Get Wireshark Network Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.