DoS worm

From: David Gillett (gillettdavid_at_fhda.edu)
Date: 10/20/04

  • Next message: Nick FitzGerald: "Re: DoS worm"
    To: <incidents@securityfocus.com>
    Date: Wed, 20 Oct 2004 13:48:02 -0700
    
    

      Yesterday, someone (we believe it was one of our students)
    unplugged a lab Mac from the campus network and plugged in a
    PC (laptop, we assume). Besides whatever the user wanted, it
    apparently did three things:

    1. Attempt to open a lot of connections (port 22, SSH) to
    shaman.exodus.ro (62.80.109.128), then

    2. Send a SYN flood, spoofing the source address as 0.0.0.0,
    to ports 22 and 80 of weed.powered.at (195.149.115.18), and

    3. Probe random addresses in our Class B space (port 445, CIFS);
    if it got a connection, it tried various SMB-type things amongst
    which I was able to pick out the string "IPC". Five other machines
    in our space eventually demonstrated similar symptoms.

      I don't know what this beast is. I infer that #2 is a DoS attack
    which is perhaps the purpose of the worm, and that #3 is its spread
    vector via the IPC$ share.

      Anybody recognize this?

    Dave Gillett


  • Next message: Nick FitzGerald: "Re: DoS worm"

    Relevant Pages

    • Re: Laptop and TV connections
      ... my laptop will not come with any S-Video slot. ... Maybe I can get it at the local computer store that carries many advanced connections. ... Some desktop computer video cards feature 15 pin VGA AND DVI outputs and include adaptors to run 15 pin VGA monitors off the DVI port. ... Be aware that content publishers are lobbying for US government rules that would degrade video resolution for devices that don't make provisions to enforce Digital Rights Management. ...
      (microsoft.public.windowsxp.hardware)
    • Re: Checking ports on a laptop
      ... Blocked and stealth are basicly the same thing. ... scan reveals that a port even exist. ... It's hidden and no connections are ... > I have a single laptop behind a Netgear router connected to an ADSL ...
      (microsoft.public.windowsxp.general)
    • Re: Checking ports on a laptop
      ... In the case of 'Closed' ports, if the port is something like ... It's hidden and no connections are ... >> I have a single laptop behind a Netgear router connected to an ADSL ...
      (microsoft.public.windowsxp.general)
    • Weird connection to ads.forbes.com:8081
      ... I was using an old laptop to configure a firewall and noticed that the ... laptop tried to connect to port 8081 on ads.forbes.com. ... that would log all connections including information about what ...
      (comp.security.firewalls)
    • Re: Need help with bandwidth management . . .
      ... also be a good time to separate the wired from the wireless parts of ... wired connections. ... QoS lan port settings, and I cannot get anything consistent. ... switch ports and limit the bandwidth per port (the settings are ...
      (alt.internet.wireless)