Re: Compromised Win2000 machine.

From: Mark Newby (mark@dranton.com)
Date: 05/29/02


Date: Wed, 29 May 2002 21:38:00 +0100
From: Mark Newby <mark@dranton.com>
To: H C <keydet89@yahoo.com>

H C wrote:
> [...]
> Danny took the typical action seen of most
> admins...port scanning the system from the outside,
> and comparing the open ports to lists of known trojans
> and services. This is inconclusive at best, and leads
> to a lot of speculation and time-wasting. Better to
> run fport on the system (if NT/2K...if the system is
> XP, run netstat w/ the '-o' switch) instead, to see
> the process to port mapping.
> [...]

...but I thought the advice for a (possibly) compromised box was *not*
to run executable programs that resided on that host, as they can't be
trusted?

mark

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Compromised Win2000 machine.
    ... >> and comparing the open ports to lists of known ... Do You Yahoo!? ... This list is provided by the SecurityFocus ARIS analyzer service. ...
    (Incidents)
  • Re: Compromised Win2000 machine.
    ... >Danny took the typical action seen of most ... >and comparing the open ports to lists of known trojans ... This list is provided by the SecurityFocus ARIS analyzer service. ...
    (Incidents)
  • RE: Compromised Win2000 machine.
    ... Running tools like fport, netstat, handle, listdlls, ... and comparing the open ports to lists of known trojans ... Do You Yahoo!? ...
    (Incidents)
  • Re: Does anyone have a list....
    ... > and comment - I just want a list of ports or a pointer to ... Don't work that away around - only open ports you need. ... lists of ports so you can see what would need to be open for each service ... Anyone decent enough at having a go at ...
    (comp.security.firewalls)