RE: Think I've got trouble

From: Andrew Blevins (ABlevins@arrowheadgrp.com)
Date: 01/09/02


From: Andrew Blevins <ABlevins@arrowheadgrp.com>
To: 'Katherine Ogden' <kogden@4cd.net>, incidents@securityfocus.com
Date: Wed, 9 Jan 2002 13:48:23 -0800 

In my unexperienced opinion, I wouldn't rebuild quite yet. Is OWA running on
a box all by itself? It's possible that it is conflicting in some way with
other services on the same box. Also, a scanner like Retina will assign
exloit/trojan names to open ports it finds on a box whether or not the box
is truly compromised. I would do some research on OWA exploits on Bugtraq
and Technet, and take a hard look at the machine for these known exploits
before abandoning it.

That is, unless it takes less time, and is easier for you to just rebuild!
Good luck, and listen to the infinitly more experienced people on this list
before my advice, just my two cents! :-)

Blevins

-----Original Message-----
From: Katherine Ogden [mailto:kogden@4cd.net]
Sent: Wednesday, January 09, 2002 9:01 AM
To: incidents@securityfocus.com
Subject: Think I've got trouble

We began having trouble with our exchange server.
For no reason we could pin down the OWA would
throw up an error and stop the www service. Being
the slightly paranoid sort I downloaded Retina and ran
it against the email server. It showed the usual things
but it also showed
Port 1058 - Nim
Port 1090 - Xtreme

Two other exchange servers show these ports open.
Port 1042 - Bla
Port 1059 - Nimreg

Two questions. Does anybody know what these
are? And am I right in assuming that these machines
have been compromised and will need to be rebuilt?

Thank you for the help.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Think Ive got trouble
    ... We began having trouble with our exchange server. ... For no reason we could pin down the OWA would ... Port 1090 - Xtreme ... This list is provided by the SecurityFocus ARIS analyzer service. ...
    (Incidents)
  • RE: OWA access and security
    ... What I first like to know is what portdoes OWA needs to ... reports Enables internal access to Exchange by OWA and OMA clients. ... - Port 4125 enable external OWA ... 'Outlook Web Access' Web site service from the Internet in the 'Web ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange + Entourage
    ... But the main problem remains the LDAP related 3268 port. ... And yes I believe if OWA works fine then Entourage ... >> I'd like the Exchange server to be accessible over the Internet, ... >> client is in US and the server is in Europe. ...
    (microsoft.public.exchange.admin)
  • Re: Exchange + Entourage
    ... But the main problem remains the LDAP related 3268 port. ... And yes I believe if OWA works fine then Entourage ... >> I'd like the Exchange server to be accessible over the Internet, ... >> client is in US and the server is in Europe. ...
    (microsoft.public.mac.office.entourage)
  • Re: Exchange + Entourage
    ... But the main problem remains the LDAP related 3268 port. ... And yes I believe if OWA works fine then Entourage ... >> I'd like the Exchange server to be accessible over the Internet, ... >> client is in US and the server is in Europe. ...
    (microsoft.public.exchange.clients)

Quantcast