Re: Trojans that use LDAP

From: Hugo van der Kooij (hvdkooij@vanderkooij.org)
Date: 01/16/02


Date: Wed, 16 Jan 2002 00:30:14 +0100 (CET)
From: Hugo van der Kooij <hvdkooij@vanderkooij.org>
To: INCIDENTS <INCIDENTS@securityfocus.com>

On Tue, 15 Jan 2002, Gary Porter wrote:

> Are there any Trojans that communicate using LDAP? A machine on our
> internal network is trying to connect to
> "email-ds-3.c3pki.ch" on destination Port 389? That port (blocked by the
> firewall) is ostensibly used for the Lightweight Directory Access Protocol,
> but I know nothing about this service and I've been unsuccessful (using Sam
> Spade) in locating any information about the destination address. Is this
> the sign of a compromise or something more benign?

Given the host name "email-ds-3.c3pki.ch" containing the three magic
letters PKI and the LDAP attempts this might very well be a server with an
addressbook in the LDAP database.

Hugo.

-- 
All email send to me is bound to the rules described on my homepage.
    hvdkooij@vanderkooij.org		http://hvdkooij.xs4all.nl/
	    Don't meddle in the affairs of sysadmins,
	    for they are subtle and quick to anger.

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Trojans that use LDAP
    ... normally designated for LDAP doesnt mean that this is LDAP traffic, ... >> Spade) in locating any information about the destination address. ... >> This list is provided by the SecurityFocus ARIS analyzer service. ... >> For more information on this free incident handling, management ...
    (Incidents)
  • Trojans that use LDAP
    ... Are there any Trojans that communicate using LDAP? ... internal network is trying to connect to ... "email-ds-3.c3pki.ch" on destination Port 389? ... This list is provided by the SecurityFocus ARIS analyzer service. ...
    (Incidents)
  • running ISA on DC
    ... one for the internal network & one for the router. ... authenticate & replicate with another DC and host a global catalog. ... LDAP GC ... NetBios Name Service -- necessary? ...
    (microsoft.public.isaserver)
  • Re: automount problem
    ... >> server when it searches for the automount map. ... >> It seems that solaris doesn't even TRY to communicate with the LDAP ...
    (comp.unix.solaris)
  • Re: Cant close port 389
    ... > Where $IFACE holds the name of your external interface. ... > That way you can conitue to use LDAP on your internal network and keep the ... Or, even better, if you really need ldap (which it sounds like you dont ...
    (comp.os.linux.networking)