Re: [fw-wiz] worm?



You could use FakeDNS and MailPot to maybe capture what happens after
the connection is created. here is the link to the tools. I haven't
used them, but I know they can be used for things like this.
http://labs.idefense.com/files/labs/releases/previews/map/



On 2/1/07, Paul D. Robertson <paul@xxxxxxxxxxxx> wrote:
On Thu, 1 Feb 2007, Brian Loe wrote:

One of our support technician's machines is attempting to connect to
random IP addresses on port 25 - in a pretty needy fashion. He says
he's scanned the box with the latest updates from McAffee and it
hasn't found anything.

We discovered it because one of my basic (meaning I got it off the
'Net) rules for SEC flagged it as a possible PHEL trojan.

Any thoughts?

See what process keeps opening sockets?

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
paul@xxxxxxxxxxxx which may have no basis whatsoever in fact."

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



--
If you think technology can solve your security problems, then you
don't understand the problems and you don't understand the technology.
Bruce Schneier
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Just want to keep the crap out!!
    ... cheap hardware solution. ... connection for your sepcific OS correctly for whatever connection ... "If you think technology can solve your security problems, ...
    (comp.security.firewalls)
  • =?windows-1252?Q?http=3A=2F=2Fwww=2Eelectronicsbestseller=2Ecom__Olympus_Stylus?= =?windows-
    ... Model: Stylus 790SW Orange ... 790SW captures amazing 7.1-megapixel images in any situation -- ... absorption technology that minimizes the impact delivered to the lens ... Bright Capture Technology for easy low-light photography Low-light ...
    (rec.photo.digital)
  • Re: Theyre horses being HORSES!
    ... | talked to the inventor of Cyclepath a 3D Bike Fitting System. ... So the product would be used at a horse arena to capture the ... technology for another sport and apply it to riding, ... ride to a bad ride. ...
    (rec.equestrian)
  • Everyday Gadgets Getting Smarter
    ... A lot of technology companies focus on making computers more powerful ... -- it allows that product to become part of a network. ... satellite (GPS) technology and a database of star and planet ... a Bluetooth wireless connection for an iPod or cellphone. ...
    (comp.dcom.telecom)
  • Re: Vulnerability - Tracking and Remediation
    ... Are you using SPI, Watchfire or WhiteHat? ... Consider getting clear vision with Cenzic ... If you think technology can solve your security problems, ... don't understand the problems and you don't understand the technology. ...
    (Pen-Test)