RE: Scanning for trojans

From: Discussion Lists (discussions_at_lagraphico.com)
Date: 04/29/03

  • Next message: Pete Herzog: "RE: Port Scanners / Sniffers Review"
    Date: Mon, 28 Apr 2003 15:05:49 -0700
    To: "Eric" <ews@tellurian.net>, <pen-test@securityfocus.com>
    

    Thanks, but in my case I don't have local access to the machine, so it
    would be helpful to find a way to identify it remotely. I am beginning
    if such an animal actually exists?

    Thanks

    > -----Original Message-----
    > From: Eric [mailto:ews@tellurian.net]
    > Sent: Monday, April 28, 2003 2:26 PM
    > To: Discussion Lists; pen-test@securityfocus.com
    > Subject: Re: Scanning for trojans
    >
    >
    > map the open port back to the executable that launched it.
    >
    > ...Microsoft specific advice...
    > If on Win2K, use fport from foundstone. If XP, try fport, or
    > do netstat
    > -on and map the PID back to the executable.
    >
    > At 10:19 AM 4/27/2003 -0700, Discussion Lists wrote:
    > >Hi all,
    > >I have discovered what I believe is a trojan on a port that is a
    > >non-standard port for that particular trojan, but I want to
    > narrow down
    > >the possibilities of what it could be. Can anyone suggest a trojan
    > >scanner that can detect a trojan by simply scanning for open
    > ports, and
    > >connecting?
    > >
    > >Thanks
    > >
    > >-------------------------------------------------------------
    > ----------
    > >----
    > >Attend Black Hat Briefings & Training Europe, May 12-15 in
    > Amsterdam, the
    > >world's premier event for IT and network security experts.
    > The two-day
    > >Training features 6 hand-on courses on May 12-13 taught by
    > professionals.
    > >The two-day Briefings on May 14-15 features 24 top speakers
    > with no vendor
    > >sales pitches. Deadline for the best rates is April 25.
    > Register today to
    > >ensure your place. http://www.securityfocus.com/BlackHat-pen-test
    > >-------------------------------------------------------------
    > ---------------
    >
    >
    >

    ---------------------------------------------------------------------------
    Did you know that you have VNC running on your network?
    Your hacker does.
    Plug your security holes.
    Download a free 15-day trial of VAM:
    http://www.securityfocus.com/StillSecure-pen-test
    ----------------------------------------------------------------------------


  • Next message: Pete Herzog: "RE: Port Scanners / Sniffers Review"

    Relevant Pages

    • Re: My Game Needs a Port Listed as Trojan Port
      ... > my games uses this port. ... The trojan has to be installed on your machine, ... > that my virus scan knows that this game is ok to use this port although it ... Antivirus shouldn't have anything to do with it: but for a firewall it will. ...
      (comp.security.firewalls)
    • Re: netstat finds something strange?
      ... I dunno about heuristics or viruses or trojans, ... should have your PC name as the name listening on each different port. ... > The free pest patrol scanner just looks for port numbers that are open ... >> What the heck kind of virus or trojan does this. ...
      (microsoft.public.win2000.security)
    • Re: What does this log file mean- Intrusion, Noise, or ISP?
      ... NAV2002 with updates and just scanned with ANTS trojan scanner (from ... but I may contact Charter and let them know about the IP of concern. ... >>NIS 2002 constantly blocks the remote IP below trying to connect to Port ... > other machines to infect. ...
      (comp.security.firewalls)
    • Re: svchost.exe
      ... Svchost.exe is tied in with RPC somehow and win2k needs it. ... If you did a netstat -an in the DOS command prompt, ... the process list and port 135 is closed and it no longer shows up on ... The trojan was listening on port ...
      (microsoft.public.windowsxp.security_admin)
    • RE: SYN_SENT to port 8081
      ... I received many responses to my ... fport only seems to be available for NT based OS's. ... You could narrow it down to the application utilizing the outgoing port ... I have a Windows 98 Second Edition machine that's consistently ...
      (Focus-Microsoft)