<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">telnet someserver.tpg.com<br>
ping tpgdns.tpg.com -f -l 1000 -p 436865636b204175736e6f67 -s 1450<br>
<br>
MUWHAHAHAHAH!<br>
They may be a little less receptive to the idea of you being white
hat however ;-><br>
<br>
(for the lazy hex 43:68:65:63:6b:20:41:75:73:6e:6f:67 = "Check
Ausnog" in the ascii realm)<br>
<br>
On 29/05/13 11:05, Parth Shukla wrote:<br>
</div>
<blockquote
cite="mid:045501ce5c08$99a11e90$cce35bb0$@auscert.org.au"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0cm;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";
mso-fareast-language:EN-US;}
span.EmailStyle17
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle18
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle19
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";
mso-fareast-language:EN-US;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Hey all,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I am still
looking for contacts for: TPG, Optus and iiNet! <o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Someone did
kindly forward my email to iiNet security team so I’ll wait
a day or two more to hear from them still…<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Anyone?
Anything?!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Cheers,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Parth<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><b><span
style="color:#002060;mso-fareast-language:EN-AU">Parth
Shukla</span></b><span
style="color:#00B050;mso-fareast-language:EN-AU"> </span><span
style="color:#002060;mso-fareast-language:EN-AU">|<b> </b>Information
Security Analyst</span><span
style="color:gray;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">AusCERT
| Australia’s premier computer emergency response team <o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">The
University of Queensland | Brisbane QLD 4072 | Australia<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">t:
(07) 334 64537 |e: </span><span
style="font-size:9.0pt;color:#1F497D;mso-fareast-language:EN-AU"><a
moz-do-not-send="true"
href="mailto:pparth@auscert.org.au">pparth@auscert.org.au</a></span><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU"> w: <a
moz-do-not-send="true" href="http://www.auscert.org.au/">www.auscert.org.au</a>
<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">
<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:green;mso-fareast-language:EN-AU">Save
a tree. Don't print this e-mail unless it's really
necessary </span><span
style="color:#1F497D;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
lang="EN-US">From:</span></b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
lang="EN-US"> Parth Shukla
[<a class="moz-txt-link-freetext" href="mailto:pparth@auscert.org.au">mailto:pparth@auscert.org.au</a>] <br>
<b>Sent:</b> Tuesday, 28 May 2013 12:39 PM<br>
<b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:ausnog@lists.ausnog.net">ausnog@lists.ausnog.net</a><br>
<b>Subject:</b> Re: Analysis of the Carna Botnet
(Internet Census 2012)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="color:#1F497D">Hi All,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I’m hoping most
of you have had a chance to at least have a quick look at my
presentation by now. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I’m now after
technical contacts for three of the four most prominent
Telco’s that are present in the Australian data (slide 44 of
my presentation). I am hoping to work with someone fairly
technical in helping deal with the problem of vulnerable
devices through default logins on telnet on their
infrastructure.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I’m after
(generic and/or non-generic) technical and security focused
contact details for:<b> TPG, Optus and iiNet</b>. <o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">The IP ranges
for these three and Telstra represent 75% of compromised
devices in Australia. I already have generic email for
Telstra which I’ll use but if someone here form Telstra
wants to contact me directly please feel free.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Could someone
from these three please contact me off-list? If someone has
good contacts in any of them, could you either a) forward my
email to them asking them to contact me or b) email me their
contact details off-list?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I will be
providing them with the part of the data that is relevant to
their network.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Cheers,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Parth<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><b><span
style="color:#002060;mso-fareast-language:EN-AU">Parth
Shukla</span></b><span
style="color:#00B050;mso-fareast-language:EN-AU"> </span><span
style="color:#002060;mso-fareast-language:EN-AU">|<b> </b>Information
Security Analyst</span><span
style="color:gray;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">AusCERT
| Australia’s premier computer emergency response team <o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">The
University of Queensland | Brisbane QLD 4072 | Australia<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">t:
(07) 334 64537 |e: </span><span
style="font-size:9.0pt;color:#1F497D;mso-fareast-language:EN-AU"><a
moz-do-not-send="true"
href="mailto:pparth@auscert.org.au">pparth@auscert.org.au</a></span><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU"> w: <a
moz-do-not-send="true" href="http://www.auscert.org.au/">www.auscert.org.au</a>
<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">
<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:green;mso-fareast-language:EN-AU">Save
a tree. Don't print this e-mail unless it's really
necessary </span><span
style="color:#1F497D;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
lang="EN-US">From:</span></b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
lang="EN-US"> Parth Shukla
[<a class="moz-txt-link-freetext" href="mailto:pparth@auscert.org.au">mailto:pparth@auscert.org.au</a>] <br>
<b>Sent:</b> Friday, 24 May 2013 7:45 PM<br>
<b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:ausnog@lists.ausnog.net">ausnog@lists.ausnog.net</a><br>
<b>Subject:</b> Analysis of the Carna Botnet (Internet
Census 2012)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Dear All,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I have made my presentation on the Carna
Botnet freely available for view and/or download: <a
moz-do-not-send="true" href="http://bit.ly/auscertcarna">http://bit.ly/auscertcarna</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This presentation is on the Compromised
Devices of the Carna Botnet (also known as Internet Census
2012). This analysis is done from data obtained directly from
the researcher. The data used is NOT publicly available for
download.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This was recently presented at the AusCERT
Conference 2013. Info: <a moz-do-not-send="true"
href="http://conference.auscert.org.au/conf2013/speaker_Parth_Shukla.html">http://conference.auscert.org.au/conf2013/speaker_Parth_Shukla.html</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">This presentation is freely available for
viewing and downloading as I wish to spread awareness of the
issues raised as a result of the Carna Botnet.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am sending this email as I suspect many
of you will find the contents of this presentation
interesting. Apologies to those who are subscribed to multiple
mailing lists and are receiving this email multiple times as a
result. Please forward this onto any mailing list or any
individual who you think may appreciate the contents of the
presentation.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Regards,<o:p></o:p></p>
<p class="MsoNormal">Parth<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b><span
style="color:#002060;mso-fareast-language:EN-AU">Parth
Shukla</span></b><span
style="color:#00B050;mso-fareast-language:EN-AU"> </span><span
style="color:#002060;mso-fareast-language:EN-AU">|<b> </b>Information
Security Analyst</span><span
style="color:gray;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">AusCERT
| Australia’s premier computer emergency response team <o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">The
University of Queensland | Brisbane QLD 4072 | Australia<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">t:
(07) 334 64537 |e: </span><span
style="font-size:9.0pt;color:#1F497D;mso-fareast-language:EN-AU"><a
moz-do-not-send="true" href="mailto:pparth@auscert.org.au">pparth@auscert.org.au</a></span><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU"> w: <a
moz-do-not-send="true" href="http://www.auscert.org.au/">www.auscert.org.au</a>
<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">
<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:9.0pt;color:green;mso-fareast-language:EN-AU">Save
a tree. Don't print this e-mail unless it's really
necessary </span><span style="mso-fareast-language:EN-AU"><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">_______________________________________________
AusNOG mailing list
<a class="moz-txt-link-abbreviated" href="mailto:AusNOG@lists.ausnog.net">AusNOG@lists.ausnog.net</a>
<a class="moz-txt-link-freetext" href="http://lists.ausnog.net/mailman/listinfo/ausnog">http://lists.ausnog.net/mailman/listinfo/ausnog</a>
</pre>
</blockquote>
<br>
</body>
</html>