ZangoCash with a botnet.

Discussion in 'Security' started by BALDRICK, Feb 10, 2008.

  1. #1
    I apologize if i posted this in the wrong place.

    Let us assume, that an individual has a botnet. How could she make a buck using that botnet with a pay-per-install program like ZangoCash?

    Does one have to "tweak" the ZangoCash binary in order to have the bot download and run it? Please tell me how this works. You may also give me the address of a site using Zango.

    :eek:

    Thanks.
     
    BALDRICK, Feb 10, 2008 IP
  2. andheresjohnny

    andheresjohnny Well-Known Member

    Messages:
    964
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    120
    #2
    It's easy enough to make good money promoting Zango legitimately without having to force installs on compromised computers. Plus, Zango pays you monthly .... when they figure out what you're doing they will cancel your account and you will lose all your accrued earnings.

    Not worth it, especially when you can make a long-term killing with this program.
     
    andheresjohnny, Feb 10, 2008 IP
  3. BALDRICK

    BALDRICK Peon

    Messages:
    42
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I seeee....

    It is of course morally wrong to "force install". I agree.

    But do people really install Zango? In my country the antivirus-hysteria has
    won over common sence (call it indoctrination). Say "Zango" and everybody starts screaming and waving their arms in panic, something which may explain why my country is in the "tier 3" category.

    Another thing. What if i have a website with 10000 daily unique visitors. Even if each and everyone of those would install Zango, that would pay only one time, or am i wrong here? Won't i "run out" of people to install my app then? How can that generate so much doe?

    Hahahaha.... i am a little tired, and i don't speak English very well either.

    :eek:
    Thanks.
     
    BALDRICK, Feb 10, 2008 IP
  4. xmcp123

    xmcp123 Peon

    Messages:
    876
    Likes Received:
    49
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Zango's had issues with this and REALLY tightened up already. You hit one honeypot(which you will) and not only is your account toasted, but they'll follow the money trail back to you
     
    xmcp123, Feb 10, 2008 IP
  5. BALDRICK

    BALDRICK Peon

    Messages:
    42
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Off topic:

    What was said about the honeypot is very interesting.

    Framing somebody sounds like a piece of cake. Just take someone elses Zango binary from the net, and manipulate it to spread like a worm, or drop it on a number of compromized hosts (even honeypots). Then have the cops analyze the code, and associate the binarys embedded ID with the identity of the innocent account owner.

    That is really insane.
     
    BALDRICK, Feb 10, 2008 IP
  6. xmcp123

    xmcp123 Peon

    Messages:
    876
    Likes Received:
    49
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Heh you could get them dropped from the aff program, but it'd take more than money trails to definitely convict. Most likely IM conversations and such(those are all logged by the major companies)...but yeah, e-framing is wayyyy to easy.
     
    xmcp123, Feb 10, 2008 IP
  7. andheresjohnny

    andheresjohnny Well-Known Member

    Messages:
    964
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    120
    #7
    Well, the last estimates that I've seen is that there are over 1 billion worldwide Internet users, with millions of new users added each day. Certainly some of these people are from the same families ... using the same computer. So as far as Zango is concerned, we should only count the individual computers.

    Lets say that of that 1 billion Internet users, every 4 belong to the same family, thus every 4 use the same machine. So if we ignore the fact that many more families now have multiple PCs in their house, that would mean there are 250 million possible computers that can have the zango toolbar installed, with at least 250,000 coming on each day.

    I wouldn't worry about saturating the market. :D
     
    andheresjohnny, Feb 10, 2008 IP
  8. BALDRICK

    BALDRICK Peon

    Messages:
    42
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Neat! :cool:

    That gave me some hope.

    Thanks. :)
     
    BALDRICK, Feb 12, 2008 IP
  9. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #9
    I just had a look at the logs for my site (roughly 5000 uniques a month) and it seems that over a 3 month period I have 12,000 unique IP addresses. Adding up the Unique IP addresses for each of those three months gives about 15,000 which means that 2,000 people across three months are return visitors who visit every month.

    So even though I get 5,000 unique IP addresses in a month, about 1,000 of them I have seen before in previous months and only 4,000 are truly unique. I didn't bother filtering this data at all so this includes all the bots that a typical website gets.

    I suspect your site will see similar patterns for your 10,000 per day. Probably about 8,000 of those have never been seen by you before and are good for promoting whatever you want.
     
    Ladadadada, Feb 15, 2008 IP
  10. xmcp123

    xmcp123 Peon

    Messages:
    876
    Likes Received:
    49
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Heh. And better still, that new 250k a day have no idea what the hell they're doing.
     
    xmcp123, Feb 15, 2008 IP
  11. andheresjohnny

    andheresjohnny Well-Known Member

    Messages:
    964
    Likes Received:
    31
    Best Answers:
    0
    Trophy Points:
    120
    #11
    You got it friend ... all those new MSN surfers just iching to use their credit card or download the latest freebie. :D

    There's a reason why MSN folks convert so well.
     
    andheresjohnny, Feb 15, 2008 IP
  12. BALDRICK

    BALDRICK Peon

    Messages:
    42
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #12
    The replies are getting nicer by the day. :eek:

    Me like! :D
     
    BALDRICK, Feb 16, 2008 IP
  13. BALDRICK

    BALDRICK Peon

    Messages:
    42
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #13
    By the way.

    Can anyone give me a Zango-binary?. When i get some spare time it would be interesting to decompile/disassemble the code and see what's going on during the "phone home" process, and how it determines what is a "valid" installation. :rolleyes:

    If you have a binary, i would like to get it.

    Thanks.
     
    BALDRICK, Feb 16, 2008 IP