[Full-Disclosure] Re: looking for a tool

From: Schmehl, Paul L (pauls_at_utdallas.edu)
Date: 03/02/04

  • Next message: mark-security_at_hush.com: "[Full-Disclosure] Nortel Networks Wireless LAN Access Point 2200 DoS + PoC"
    To: <full-disclosure@lists.netsys.com>
    Date: Tue, 2 Mar 2004 09:52:42 -0600
    
    

    First of all, I'd like to thank all the people who offered to help.
    There were quite a few of them, and so I am not able to respond to all
    of the emails personally. For future reference, you may assume that
    when I post something like this, I've already gone through all the
    standard troubleshooting steps. In fact, the techs had before I ever
    got there. I was called in because the standard steps didn't resolve
    the problem.

    These include (but are not limited to):
    1) Running a full scan using up to date antivirus software (in our case,
    McAfee)
    2) Running McAfee's Stinger, latest version
    3) Booting in Safe Mode and removing files and registry entries
    4) Killing processes and resetting permissions so they can't be
    restarted
    5) Checking for open ports using Fport (as well as netstat, but it isn't
    to be trusted in a case like this)
    6) Monitoring the machine's network activity using various tools
    7) Etc., etc.

    (Of course tools used were on a CD and other machines, not on the
    suspect computer's hard drive.)

    My recommendation yesterday (to tech support) was to format the machine,
    because we can't afford to spend inordinate amounts of time trying to
    track down the origins of malicious software. (Besides it's kind of a
    lesson learned for the end user that way anyway.) My real concern, and
    the reason for posting to the list, was to find out why tools that I've
    depended on to give me the information I needed were unable to point to
    the cause of this problem and to see if there were other tools that
    would have been useful.

    I *did* learn about some tools that I was not aware of, which I will be
    adding to my arsenal:
    1) Gregh told me about Essential Net Tools and Procmon
    2) Robert Cowles told me about PORTqry v2
    3) On another list I was told about Bart, a bootable Windows PE CD,
    HijackThis and CWSshredder

    I received a number of suggestions, almost all of which I had already
    done. The most useful was that this was "CWS.Loadbat - Dastardly",
    which I think it may well have been.

    For the purists among you, I apologize for mixing up Foundstone's and
    Sysinternals' tools in my original post. Mea culpa.

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    The University of Texas at Dallas
    AVIEN Founding Member
    http://www.utdallas.edu/~pauls/

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: mark-security_at_hush.com: "[Full-Disclosure] Nortel Networks Wireless LAN Access Point 2200 DoS + PoC"

    Relevant Pages

    • Re: Skype on client PCs
      ... I have good antivirus software, ... and users don't generally have admin rights, ... AVG is next to worthless in any environment. ... IM is a large threat to unsecured machines where people can't grasp the ...
      (microsoft.public.windows.server.sbs)
    • Re: Is there any point to full host names in /etc/hosts ?
      ... www and ftp of rikishi42.net defined in the DNS, not my home machines. ... use when he visits and connects it to my LAN." ... in your home connecting wires to your router. ... Please, please read the original post, and grep it. ...
      (comp.os.linux.networking)
    • FS/FT: HUO TSPP in Columbus, Ohio area - $3,300 (repost from earlier today)
      ... my original post has gotten confusing with the chain of replies as I ... the machines that have been offered to me in trade for my TSPP. ... here is the info on my TSPP again. ... There are no chips or wear at the front of the hole ...
      (rec.games.pinball)
    • VC 6.0 system hangs in debug mode
      ... This problem has been wasting so much of my time and I really couldn't ... I even installed SP 6 and the problem still persists. ... since one of the machines doesn't have the antivirus software. ...
      (microsoft.public.vsnet.general)
    • VC 6.0 hangs the system during debugging mode
      ... This problem has been wasting so much of my time and I really couldn't ... I even installed SP 6 and the problem still persists. ... since one of the machines doesn't have the antivirus software. ...
      (microsoft.public.vsnet.debugging)