<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">telnet someserver.tpg.com<br>
      ping tpgdns.tpg.com -f -l 1000 -p 436865636b204175736e6f67 -s 1450<br>
      <br>
      MUWHAHAHAHAH!<br>
      They may be a little less receptive to the idea of you being white
      hat however ;-><br>
      <br>
      (for the lazy hex 43:68:65:63:6b:20:41:75:73:6e:6f:67 = "Check
      Ausnog" in the ascii realm)<br>
      <br>
      On 29/05/13 11:05, Parth Shukla wrote:<br>
    </div>
    <blockquote
      cite="mid:045501ce5c08$99a11e90$cce35bb0$@auscert.org.au"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0cm;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";
        mso-fareast-language:EN-US;}
span.EmailStyle17
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle18
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle19
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";
        mso-fareast-language:EN-US;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span style="color:#1F497D">Hey all,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">I am still
            looking for contacts for: TPG, Optus and iiNet! <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Someone did
            kindly forward my email to iiNet security team so I’ll wait
            a day or two more to hear from them still…<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Anyone?
            Anything?!<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Cheers,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Parth<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <div>
          <p class="MsoNormal"><b><span
                style="color:#002060;mso-fareast-language:EN-AU">Parth
                Shukla</span></b><span
              style="color:#00B050;mso-fareast-language:EN-AU"> </span><span
              style="color:#002060;mso-fareast-language:EN-AU">|<b> </b>Information
              Security Analyst</span><span
              style="color:gray;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">AusCERT
              | Australia’s premier computer emergency response team <o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">The
              University of Queensland | Brisbane QLD 4072 | Australia<o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">t:
              (07) 334 64537 |e: </span><span
              style="font-size:9.0pt;color:#1F497D;mso-fareast-language:EN-AU"><a
                moz-do-not-send="true"
                href="mailto:pparth@auscert.org.au">pparth@auscert.org.au</a></span><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU"> w: <a
                moz-do-not-send="true" href="http://www.auscert.org.au/">www.auscert.org.au</a>
                 <o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">                                                                                                                                               
              <o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:green;mso-fareast-language:EN-AU">Save
              a tree. Don't print this e-mail unless it's really
              necessary  </span><span
              style="color:#1F497D;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
        </div>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <div>
          <div style="border:none;border-top:solid #B5C4DF
            1.0pt;padding:3.0pt 0cm 0cm 0cm">
            <p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
                  lang="EN-US">From:</span></b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
                lang="EN-US"> Parth Shukla
                [<a class="moz-txt-link-freetext" href="mailto:pparth@auscert.org.au">mailto:pparth@auscert.org.au</a>] <br>
                <b>Sent:</b> Tuesday, 28 May 2013 12:39 PM<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:ausnog@lists.ausnog.net">ausnog@lists.ausnog.net</a><br>
                <b>Subject:</b> Re: Analysis of the Carna Botnet
                (Internet Census 2012)<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><span style="color:#1F497D">Hi All,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">I’m hoping most
            of you have had a chance to at least have a quick look at my
            presentation by now. <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">I’m now after
            technical contacts for three of the four most prominent
            Telco’s that are present in the Australian data (slide 44 of
            my presentation). I am hoping to work with someone fairly
            technical in helping deal with the problem of vulnerable
            devices through default logins on telnet on their
            infrastructure.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">I’m after
            (generic and/or non-generic) technical and security focused
            contact details for:<b> TPG, Optus and iiNet</b>. <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">The IP ranges
            for these three and Telstra represent 75% of compromised
            devices in Australia. I already have generic email for
            Telstra which I’ll use but if someone here form Telstra
            wants to contact me directly please feel free.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Could someone
            from these three please contact me off-list? If someone has
            good contacts in any of them, could you either a) forward my
            email to them asking them to contact me or b) email me their
            contact details off-list?<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">I will be
            providing them with the part of the data that is relevant to
            their network.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Cheers,<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D">Parth<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <div>
          <p class="MsoNormal"><b><span
                style="color:#002060;mso-fareast-language:EN-AU">Parth
                Shukla</span></b><span
              style="color:#00B050;mso-fareast-language:EN-AU"> </span><span
              style="color:#002060;mso-fareast-language:EN-AU">|<b> </b>Information
              Security Analyst</span><span
              style="color:gray;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">AusCERT
              | Australia’s premier computer emergency response team <o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">The
              University of Queensland | Brisbane QLD 4072 | Australia<o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">t:
              (07) 334 64537 |e: </span><span
              style="font-size:9.0pt;color:#1F497D;mso-fareast-language:EN-AU"><a
                moz-do-not-send="true"
                href="mailto:pparth@auscert.org.au">pparth@auscert.org.au</a></span><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU"> w: <a
                moz-do-not-send="true" href="http://www.auscert.org.au/">www.auscert.org.au</a>
                 <o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">                                                                                                                                               
              <o:p></o:p></span></p>
          <p class="MsoNormal"><span
              style="font-size:9.0pt;color:green;mso-fareast-language:EN-AU">Save
              a tree. Don't print this e-mail unless it's really
              necessary  </span><span
              style="color:#1F497D;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
        </div>
        <p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
        <div>
          <div style="border:none;border-top:solid #B5C4DF
            1.0pt;padding:3.0pt 0cm 0cm 0cm">
            <p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
                  lang="EN-US">From:</span></b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-AU"
                lang="EN-US"> Parth Shukla
                [<a class="moz-txt-link-freetext" href="mailto:pparth@auscert.org.au">mailto:pparth@auscert.org.au</a>] <br>
                <b>Sent:</b> Friday, 24 May 2013 7:45 PM<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:ausnog@lists.ausnog.net">ausnog@lists.ausnog.net</a><br>
                <b>Subject:</b> Analysis of the Carna Botnet (Internet
                Census 2012)<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Dear All,<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">I have made my presentation on the Carna
          Botnet freely available for view and/or download: <a
            moz-do-not-send="true" href="http://bit.ly/auscertcarna">http://bit.ly/auscertcarna</a><o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">This presentation is on the Compromised
          Devices of the Carna Botnet (also known as Internet Census
          2012). This analysis is done from data obtained directly from
          the researcher. The data used is NOT publicly available for
          download.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">This was recently presented at the AusCERT
          Conference 2013. Info: <a moz-do-not-send="true"
href="http://conference.auscert.org.au/conf2013/speaker_Parth_Shukla.html">http://conference.auscert.org.au/conf2013/speaker_Parth_Shukla.html</a><o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">This presentation is freely available for
          viewing and downloading as I wish to spread awareness of the
          issues raised as a result of the Carna Botnet.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">I am sending this email as I suspect many
          of you will find the contents of this presentation
          interesting. Apologies to those who are subscribed to multiple
          mailing lists and are receiving this email multiple times as a
          result. Please forward this onto any mailing list or any
          individual who you think may appreciate the contents of the
          presentation.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Regards,<o:p></o:p></p>
        <p class="MsoNormal">Parth<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><b><span
              style="color:#002060;mso-fareast-language:EN-AU">Parth
              Shukla</span></b><span
            style="color:#00B050;mso-fareast-language:EN-AU"> </span><span
            style="color:#002060;mso-fareast-language:EN-AU">|<b> </b>Information
            Security Analyst</span><span
            style="color:gray;mso-fareast-language:EN-AU"><o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">AusCERT
            | Australia’s premier computer emergency response team <o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">The
            University of Queensland | Brisbane QLD 4072 | Australia<o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">t:
            (07) 334 64537 |e: </span><span
            style="font-size:9.0pt;color:#1F497D;mso-fareast-language:EN-AU"><a
              moz-do-not-send="true" href="mailto:pparth@auscert.org.au">pparth@auscert.org.au</a></span><span
style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU"> w: <a
              moz-do-not-send="true" href="http://www.auscert.org.au/">www.auscert.org.au</a>
               <o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:9.0pt;color:gray;mso-fareast-language:EN-AU">                                                                                                                                               
            <o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:9.0pt;color:green;mso-fareast-language:EN-AU">Save
            a tree. Don't print this e-mail unless it's really
            necessary  </span><span style="mso-fareast-language:EN-AU"><o:p></o:p></span></p>
        <p class="MsoNormal"><o:p> </o:p></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
AusNOG mailing list
<a class="moz-txt-link-abbreviated" href="mailto:AusNOG@lists.ausnog.net">AusNOG@lists.ausnog.net</a>
<a class="moz-txt-link-freetext" href="http://lists.ausnog.net/mailman/listinfo/ausnog">http://lists.ausnog.net/mailman/listinfo/ausnog</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>