Re: NT Compromise

From: H C (keydet89@yahoo.com)
Date: 12/20/01


Date: Thu, 20 Dec 2001 04:57:08 -0800 (PST)
From: H C <keydet89@yahoo.com>
To: Eric Hines <eric3+@pitt.edu>, incidents@securityfocus.com


> I am responding to several compromised NT boxes and
> am trying to find a
> utility that will allow you to see what program is
> bound to a particular
> port.

I saw several references to inzider and tools
available from SysInternals, but of all the responses
that showed up in my inbox, I did not see a single
response that mentioned FoundStone's fport.exe.

The reason I mention this tool isn't b/c it's
necessarily 'better' than than the others, but b/c I
also teach an NT/2K incident response course...and in
order to get volatile data (like network connections,
etc) off of the box, the best way to do so w/o making
a lot of changes to the victim system itself is to use
CLI tools and pipe the output through a socket to
another system. Netcat and cryptcat are good for
this, but neither one returns when the app itself has
finished executing. I've been working on another tool
for this purpose.

> I think I've seen one that shows what ports
> are bound to
> command.com, but need something similar for other
> programs/trojans/etc.

Eric, I have to admit...this makes no sense to me.
But I could simply be misunderstanding...could you
elaborate on this a bit?

> Is there something available? Has anyone seen a
> compromised NT box with
> port 6667 open that does not seem to be running an
> IRCD? Check out the
> below snippit from netstat. I've tried connecting to
> the 6667 port with
> MiRC.. Nothing at all!

Did you try telnet or netcat?

> On this note, can anyone recommend
> a good forensics
> toolkit for Windows to be used on compromised
> machines?

Are you looking for an incident response toolkit? Or
do you want forensics? Making an image w/ SafeBack is
a good idea, then copy that image or make another w/
EnCase, if you want to do full forensics. However, if
you just want to collect volatile data from the
system, plus get some other things, send me an email
and I'll compile a list of tools and procedures...I
don't want to inundate the list w/ info that no one
else wants.

__________________________________________________
Do You Yahoo!?
Check out Yahoo! Shopping and Yahoo! Auctions for all of
your unique holiday gifts! Buy at http://shopping.yahoo.com
or bid at http://auctions.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Best Plan of action for 2 forest.......
    ... PortQry reports the status of a port in one of the following ways: ... ..LISTENING This response indicates that a process is listening on the target ...
    (microsoft.public.windows.server.active_directory)
  • RE: MBSA and MSs attempts at "security"
    ... >the port status of TCP and UDP ports on a computer you choose. ... you can also query an LDAP service. ... LDAP query and interpret an LDAP server's response to ...
    (Focus-Microsoft)
  • RE: Using a dynamic request - response port
    ... Saravana Kumar ... I don't have any direct experience working with WSS adapter, ... You need to make sure, you are getting some response back from Sharepoint ... May be its worth investigating using a static solict-response send port ...
    (microsoft.public.biztalk.general)
  • Re: Cant connect to Mailserver
    ... chance yet to dig into the server and find out why. ... When I telnet to port 25 I should get a response from your exchange ... Are the correct ports open in the router? ...
    (microsoft.public.windows.server.sbs)
  • Re: how to set timeout for read command
    ... >> The shell will attempt to connect to that TCP port, get an error response, ... The desired behavior of the program is to ... in response to the refusal to open the connection. ... The remote machine has something listening on the port, ...
    (comp.unix.shell)