4 ms·
I mean they could just write some net code that sends packets to whatever port, but launching IE and doing everything over HTTPS or whatever is much more stealt
by 65827 10y ago
I mean they could just write some net code that sends packets to whatever port, but launching IE and doing everything over HTTPS or whatever is much more stealthy when it comes to network monitoring and system logs.
- josefdlange 10y agoBut why not spend ten minutes and make their net code use SSL and then avoid it altogether? I guess one could argue that the footprint of adding SSL client behavior to a sneaky hidden tracker might be shitty to do and make it more identifiable. But also SSL libraries are typically linkable on the host system anyway, no compilation past the headers needed. It's just a weird "workaround" on their part if that's the intention.
- foota 10y agoConsider perhaps Windows firewall. I believe it can be configured to block connection by opening program.
- Alupis 10y agoPerhaps bots are more easily discernible from a human user who's using a real browser. If the goal is to be stealthy, then they'd want to appear as human-like as possible.
- josteink 10y agoWindows has very sophisticated firewalling and network access can be filtered on a per-process, per-network basis. Restrictive companies will only allow pre-approved applications, for specific ports, like I.E. doing HTTP/S over ports 80 and 443, and only on approved/trusted networks.
- josefdlange 10y agoYeah, realized the folly in my logic -- see my edit on my top-level comment. This strategy is pretty much how LS works on macOS as well.
- rasz_pl 10y agoand DNSCache at 53, same DNSCache that listens on localhost and will relay any request from anybody, _non filterable_ localhost