Re: Trojan? DDOS Bot?

From: Mike Parkin (mparkin@cisco.com)
Date: 08/27/02


Date: Tue, 27 Aug 2002 11:56:53 -0700 (PDT)
From: Mike Parkin <mparkin@cisco.com>
To: Janus@etoast.com

You appear to have been infected with one of a variety of Trojans - like
BO, NetBus, Sub7, etc. Can't tell from the ports you show, since many of
the trojans are configurable for responses, U@H values when connecting to
IRC, listening ports, etc.

I've seen that same thing from the IRCAdmin side of the equation many
times. We used to set up in the "target" channel and wait for the organic
to show up and claim it's bots. Unfortunately, even when we'd dealt with
him, we'd often see stragglers from his botnet for weeks to come.

Advice - get some scanning software appropriate for your OS (Sorry, no
recommendation - I'm an *IX guy) and find the trojan.

Mike Parkin
Cisco Systems, Inc.
Information Security
SysAdmin/NetAdmin

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: help with SyGate needed
    ... >> After I installed Sygate and the computer restarted, ... a message window popped up asking me ... > those trojans use this port for communication. ... >> We have determined that you have a firewall blocking UDP ports! ...
    (comp.security.firewalls)
  • Re: Think Ive got trouble
    ... Some Trojans can be "adjusted" to listen on practically ANY port, ... rely on lists of known ports used by known Trojans. ... > You might wanna download the free LANGUARD Network scanner from GFI ... >>We began having trouble with our exchange server. ...
    (Focus-Microsoft)
  • RE: rooted NT/2K boxen?
    ... Hrmm, netstat -an comes to my mind quickly, as it lists all ports in use but ... > It is completely possible to take over a Windows NT/2K box... ... > control there are a bunch of remote administration trojans, ...
    (Focus-Microsoft)
  • Re: Windows XP firewall against all others: whats wrong with it?
    ... I always use Active Ports (I look at it each ... minutes;-) and I'm quite secure I don't have trojans installed. ... >> Sygate Personal Firewall block my connection when modem adsl ...
    (comp.security.firewalls)
  • Re: Firewalls VS MS TCP/IP filtering
    ... On Fri, 08 Aug 2003 13:29:20 GMT, Lars M. Hansen ... trojans that actually come in thru the ... >RAT will probe systems to see if the server piece ... >You have to differentiate between inbound open ports and outbound open ...
    (comp.security.firewalls)