Detecting trojans on random ports with encrypted traffic...

From: Clint Byrum (cbyrum@spamaps.org)
Date: 10/23/02


From: Clint Byrum <cbyrum@spamaps.org>
To: focus-ids@securityfocus.com
Date: 23 Oct 2002 13:55:07 -0700

Ok so, we can obviously see sub7 on port 27374 with its known signature
patterns. But then they go and run it on a different port. And then they
go and encrypt things(I don't know if sub7 can do this, but for instance
BO or something else).

The scenario is, a user brings a floppy disk with a trojan on it to the
location, and puts the trojan on another user's computer. They then sit
back and watch the keylogging/passwords/etc.etc.

So, is this what SPADE is supposed to handle? I mean.. currently the
only solution I have come up with is to designate subnets that are not
supposed to be talking to eachother, and alert on peer to peer traffic.
But this isn't always possible, and this doesn't cover traffic where the
trojan is on a server.

Is there any hope to detect this situation?



Relevant Pages

  • RE: Detecting trojans on random ports with encrypted traffic...
    ... One of the things I have noticed is that for any encryption the initial phase ... you can't tell bad (Trojan) traffic from good traffic. ... we can obviously see sub7 on port 27374 with its known signature ... But then they go and run it on a different port. ...
    (Focus-IDS)
  • Re: My Game Needs a Port Listed as Trojan Port
    ... > my games uses this port. ... The trojan has to be installed on your machine, ... > that my virus scan knows that this game is ok to use this port although it ... Antivirus shouldn't have anything to do with it: but for a firewall it will. ...
    (comp.security.firewalls)
  • Re: netstat finds something strange?
    ... I dunno about heuristics or viruses or trojans, ... should have your PC name as the name listening on each different port. ... > The free pest patrol scanner just looks for port numbers that are open ... >> What the heck kind of virus or trojan does this. ...
    (microsoft.public.win2000.security)
  • Re: What does this log file mean- Intrusion, Noise, or ISP?
    ... NAV2002 with updates and just scanned with ANTS trojan scanner (from ... but I may contact Charter and let them know about the IP of concern. ... >>NIS 2002 constantly blocks the remote IP below trying to connect to Port ... > other machines to infect. ...
    (comp.security.firewalls)
  • Re: svchost.exe
    ... Svchost.exe is tied in with RPC somehow and win2k needs it. ... If you did a netstat -an in the DOS command prompt, ... the process list and port 135 is closed and it no longer shows up on ... The trojan was listening on port ...
    (microsoft.public.windowsxp.security_admin)