Hacker News new | past | comments | ask | show | jobs | submit login

I would like to understand the significance of each bullet point under "Specific features of Mēris botnet".



SOCKS proxy: the botnet allows tunneling non-WWW traffic through it so users of the botnet can route say BitTorrent or other P2P traffic through it.

HTTP Pipelining: instead of simplistic one-request-one-resource requests to a server the botnet supports HTTP 1.1 pipelined requests. A single request can ask for multiple files meaning even more demand on target servers. Request resources not cached in memory can see the server eat up its IOPS trying to read files.


The main point of this article seems to be to highlight the 20 million requests per second arbitrary metric.

Otherwise the bullet points are about the functionality in place in the infected clients. The port is likely a detection metric for infected clients.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: