Re: [fw-wiz] worm?



You could use FakeDNS and MailPot to maybe capture what happens after
the connection is created. here is the link to the tools. I haven't
used them, but I know they can be used for things like this.
http://labs.idefense.com/files/labs/releases/previews/map/



On 2/1/07, Paul D. Robertson <paul@xxxxxxxxxxxx> wrote:
On Thu, 1 Feb 2007, Brian Loe wrote:

One of our support technician's machines is attempting to connect to
random IP addresses on port 25 - in a pretty needy fashion. He says
he's scanned the box with the latest updates from McAffee and it
hasn't found anything.

We discovered it because one of my basic (meaning I got it off the
'Net) rules for SEC flagged it as a possible PHEL trojan.

Any thoughts?

See what process keeps opening sockets?

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
paul@xxxxxxxxxxxx which may have no basis whatsoever in fact."

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



--
If you think technology can solve your security problems, then you
don't understand the problems and you don't understand the technology.
Bruce Schneier
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Just want to keep the crap out!!
    ... cheap hardware solution. ... connection for your sepcific OS correctly for whatever connection ... "If you think technology can solve your security problems, ...
    (comp.security.firewalls)
  • =?windows-1252?Q?http=3A=2F=2Fwww=2Eelectronicsbestseller=2Ecom__Olympus_Stylus?= =?windows-
    ... Model: Stylus 790SW Orange ... 790SW captures amazing 7.1-megapixel images in any situation -- ... absorption technology that minimizes the impact delivered to the lens ... Bright Capture Technology for easy low-light photography Low-light ...
    (rec.photo.digital)
  • Re: Theyre horses being HORSES!
    ... | talked to the inventor of Cyclepath a 3D Bike Fitting System. ... So the product would be used at a horse arena to capture the ... technology for another sport and apply it to riding, ... ride to a bad ride. ...
    (rec.equestrian)
  • Re: D3 Connectivity Demos Download
    ... The definition of my problem is simple - The connection of MV to HTML pages ... The decision may come down to the technology you ... message format support, ... all over multiple transports (HTTP, UDP, SMTP, raw TCP, named pipes/ ...
    (comp.databases.pick)
  • Re: Irans Captured RQ-170: How Bad Is the Damage?
    ... stealthy jet's top-secret technology. ... high-altitude reconnaissance aircraft built by Lockheed Martin. ... The capture of a mostly intact RQ-170 by a hostile power like Iran is "the ...
    (soc.retirement)