← Back to context

Comment by croes

6 months ago

A C&C controls a botnet, where is the botnet?

The browsers of their site visitors.

  • If you need to be on the site it’s not a botnet and there is no C&C server coordinating the attack. It‘s just the JS on the site that makes the attack.

    • > If you need to be on the site it’s not a botnet

      Why? I did not visit the site to participate in a DoS attack; yet my machine was coaxed into participating against my will. Whether this is happening in JS or a drive-by download or a browser 0-day is irrelevant.

      1 reply →