How do you know that last friend request or Twitter follower was an actual live human being? The truth is...you don't! Bots and bot manufacturers have become rampant in social networks such as MySpace, Facebook and Twitter exploiting the trust relationships that make social media work. Why are bots taking control of social networks? It's simple. Social networks are the fastest growing phenomenon of our time. For example, Facebook alone recently reached 150 million potential targets for spammers, malware authors, and other undesirables in 2008. Social networks are only getting bigger and bots will be part of this trend.
This presentation will take you on a journey into the thriving bot underground where bots are manufactured for every purpose imaginable. We will talk about good bots, bad bots, really evil bots, how to identify bots, terminating bots and the future possibility of social network botnets to rule them all.
This was presented at Notacon 6 in Cleveland Ohio.
Rise of the Autobots: Into the Underground of Social Network Bots
1. Rise of the Autobots
Into the Underground of Social Network Bots
2. Hi! I’m not a bot
• Tom Eston
• Social Media Security
Researcher
• Pentester
• Bot lover
• Blog: spylogic.net
• Podcast: securityjustice.com
• Tweet me: agent0x0
3. WARNING!
What you are about to see violates
the Terms of Service (TOS) and
acceptable use policies of social
networks!
Accounts used in these tests have
been deleted or “removed” (not by
me...)
Don't try this at home!
KTHKSBAI
17. Why is trust
important?
• It’s how social networks
work!
• Trust EVERYONE!
• Share as much as
possible...the social networks
don’t mind!
• Social networks are mining
your data!
48. What’s the point?
• Trust is easy to exploit!
• People will trust bots...
• Accounts were created and
used with tools we will talk
about
• Rick Astley is EVIL!
50. What are bots?
“...perform tasks that are
both simple and structurally
repetitive at a much higher
rate than a human alone.”
“Applications that run
automated tasks”
55. The Underground
Business Model
• Create and Sell accounts
• Buy and Use accounts
• Custom bot scripts and
software (Freelancing)
56. It’s all about
Blackhat SEO...
• Not just for search engine
rankings!
• Evil Search Engine
Optimization techniques...
• PPC (Pay Per Click)
• PPI (Pay Per Install)
• Cookie Stuffing
How money is made on the “net”
67. Phone SMS
Verification?
• Great idea! But...can be
broken..
68. It kind of works,
but...
• Prepaid cell phones
• Overseas virtual
SMS Services (SMS
Receive)
• SMS back to ICQ
and Yahoo
Messenger (works
with some socnets)
69. How about rate
Limits?
• Easy to bypass...just test it,
modify your code and/or slow
down!
84. Realboy
• Project to make Twitter bots as
human as possible!
• Real interactions with your
Twitter network
• Source code available...
85. Social Network
Botnets?
• Malware distribution for C&C
• Koobface!
• DDos botnet via third-party
applications
• Facebot!
• Control a botnet via Twitter?
86. Twitter for Botnet C&C
• Bot looks for commands on
legitimate Twitter accounts
• Takes action based on the
command
• Commands are obfuscated
• Proof of Concept code
released today at Notacon!
• “TwitterBot” created by Robin
Wood aka: @digininja
88. TwitterBot
Enhancements
• add a hash (or part of) to the
command to stop fake
requests
• encrypt the whole command
(obfuscation)
• get the bot to talk back
Get it now at:
http://www.digininja.org/twitterbot/
90. Bot detection
• Look carefully!
• Lots of
clues..spammer
s are doing it
wrong!
• Programs/API’s
to detect
(Twitter
specific)
91. Some possible
solutions...
• Account creation/message
throttling
• Why can you still create
multiple accounts from the
same IP?? WTF?
• No more opt-in developer
models!
• Education of users? We can
try...the socnets won’t!
92. But wait...there’s
more!
• socialnetworkbots.com
• open source project
• Twitter and other bots
(n0tab0t)....
• get the code...don’t use your
real account!
• Twitterbot Command & Control
POC Code:
www.digininja.org/twitterbot
Everyone knows what social networks are right? Heck..I was recently told by my mother that she has a Facebook account! Noooo....
I have to keep changing this slide because it keeps getting bigger!
Ummm, yeah..it still exists. The scourge of the Internet still has...
Poor LinkedIn...still...
However, Twitter...the fastest growing social network today...
This shouldnt shock you but social networks are more popular then email! It’s only getting bigger....
With socnets so popular, it’s no surprise its where the attackers are going...
First, lets talk about the culture of trust that makes socnets work.
Socnets want you to share as much as possible, trust everyone..they are mining your data...they are not making money yet...but they have ways to sell bits and pieces of your info.
Why would bot’s exploit trust? Is this possible?
How about Jennifer? Cute..single...
and Tommy...college guy...seems friendly...
Poor Sarah. [READ IT]. Too bad she confirmed the bot as a friend at 8am and at noon, sent this message. Must be because she has 700 friends...
Poor Sarah. [READ IT]. Too bad she confirmed the bot as a friend at 8am and at noon, sent this message. Must be because she has 700 friends...
Poor Sarah. [READ IT]. Too bad she confirmed the bot as a friend at 8am and at noon, sent this message. Must be because she has 700 friends...
Poor Sarah. [READ IT]. Too bad she confirmed the bot as a friend at 8am and at noon, sent this message. Must be because she has 700 friends...
How about 0EPb4a...She likes meeting people and selling “lapto’s”
Now Haley...crappy profile..must be a bot right?
Not a bot! but with 4,974 friends...lots of FAIL
Not a bot! but with 4,974 friends...lots of FAIL
Ok, no way Rick Astley is bot...
It’s amazing the response you get when you are a celebrity..people love u.
It’s amazing the response you get when you are a celebrity..people love u.
It’s amazing the response you get when you are a celebrity..people love u.
It’s amazing the response you get when you are a celebrity..people love u.
It’s amazing the response you get when you are a celebrity..people love u.
It’s amazing the response you get when you are a celebrity..people love u.
This could have been the biggest Rick Roll ever...except that I decided to stop once I hit 666 followers. Bad omen. Not good.
This could have been the biggest Rick Roll ever...except that I decided to stop once I hit 666 followers. Bad omen. Not good.
This could have been the biggest Rick Roll ever...except that I decided to stop once I hit 666 followers. Bad omen. Not good.
The point is that trust is easy to exploit...people want to trust..all these accounts were created or used with bots we will talk about. Rick is EVIL.
Lets talk about the rise of the bots on social networks...