Re: [Full-disclosure] Exploiting a Worm

From: Frank Knobbe (frank_at_knobbe.us)
Date: 09/14/05

  • Next message: n3td3v: "[Full-disclosure] Fwd: SF new mailing list announcement: BS 7799 Security"
    To: Ian Gizak <iangizak@hotmail.com>
    Date: Wed, 14 Sep 2005 11:39:06 -0500
    
    
    
    

    On Tue, 2005-09-13 at 22:29 +0000, Ian Gizak wrote:
    > I'm pentesting a client's network and I have found a Windows NT4 machine
    > with ports 620 and 621 TCP ports open.
    >
    > When I netcat this port, it returns garbage binary strings. When I connect
    > to port 113 (auth), it replies with random USERIDs.
    > [...]
    > I have checked the open ports and no-one seems to be the worm ftp server or
    > something useful related to the worm. Some ports allow input but don't reply
    > anything...

    Could it be that you are buzzing around a honeypot like a moth around a
    porch light? Or have to followed up with the client and can you rule it
    out as a honeypot? Otherwise it's a very interesting port fingerprint
    for an NT4 box :)

    Cheers,
    Frank

    -- 
    Ciscogate: Shame on Cisco. Double-Shame on ISS.
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: n3td3v: "[Full-disclosure] Fwd: SF new mailing list announcement: BS 7799 Security"

    Relevant Pages

    • Re: I want more spam
      ... >> nat OUTPUT table to redirect them to my honeypot. ... > You could set up squid as a front end for apache and enable the CONNECT ... are more traffic on port 3128 and 8080. ...
      (comp.os.linux.security)
    • Re: Logging passwords of SSH attacks
      ... No legitimate users will try connecting via SSH on ... port 22, and certainly not over the big bad internet. ... sending the packets to a honeypot sshd and then log the passwords ...
      (Debian-User)