Re: Back Orifice - RedHat 7 [Update]

From: Mike (noone@foo.bar.com)
Date: 06/27/02


From: noone@foo.bar.com (Mike)
Date: Thu, 27 Jun 2002 14:35:34 GMT

neophyte@news.snel.net (Neophyte) wrote in
<1025162183.346818@news.knoware.nl>:

>Hello Again,
>
>I once again installed RedHat 7X on another box to make sure that I
>wasn't delusional. The procedure I followed was to first install RedHat
>7.1 without X.What I did choose was the Networked Workstation and DialUp
>Workstation. I also went in and purged the installation of programs I
>didn't want and added a couple that I did. After installation, I ran
>nmap and it revealed nothing unusual (as far as I know), just: ssh,
>smtp....in other words, nothing more than I would expect. Afterwards, I
>installed other peripheral packages (all included with the RH
>distribution), including portsentry, hostsentry, sniffit, snort,
>aide...etc.
>
>I then proceeded to upgrade that installation to RH7.2 and telling it to
>upgrade the existing installation. I did go in and purge a lot of the
>programs from this installation as well, but the bloat is ever present
>in some regards (grrrr). In any event, I went with what was acceptable
>for now and proceeded with the upgrade. I once again ran portsentry
>against the tcp and udp protocols to which I received no alarm. I then
>ran nmap again, and "sure as shootin' " there it was:
>port 54320 -tcp open bo2k!!!
>
>Concomitant to this is the fact that after the upgrade to 7.2 nmap
>showed a lot of other ports that were open which I can only conclude,
>resulted from said upgrade. These include:
>1 - tcpmux
>587 - unknown
>1080 - socks
>6667 - irc
>12345/6 - NetBus
>31337 - elite
>32771/2/3/4 - sometimes-rpc5/7/9/11
>54320 - bo2k
>
>some of which I'd have never chosen to put on a box I'd use as a
>firewall unless I was totally out of my gord. Again, if this is all
>legitimate, I can accept it, but I can't understand why bo2k client or
>server would be included in this installation and secondly how such a
>barebones installation with RH 7.1 turns into this with 7.2.
>
>If anyone can enlighten me on this subject, I'd appreciate it, but until
>then, I'll just try another distribution. I'm willing to admit that
>maybe some of this has to do with my incomplete understanding of Linux
>(if such a state of complete understanding exists), but I do know a
>thing or two, and this strikes me as odd. So, before I go online with
>Linux, via the cable, I want to make sure that I'm using and have
>configured as secure a system as I'm capable of and I'm in no rush to do
>so.
>
>I hope I've been sufficiently informative. Your help is greatly
>appreciated.
>
>Gabriel
>
>P.S. I also ran netstat -aplt which also failed to display the bo2k
>entry, but did include all of the above stated and then some...go
>figure.
>
>

Ever tried to read Portsentry's documentation?
Portsentry is a host-based IDS (Intrusion Detection System), that LISTENS
on several ports, and logs access attempts.
RTFM please.
Cheers,

Mike



Relevant Pages

  • Re: Purchase XP, where and which version?
    ... previous Windows installation (onto a newly formatted hard drive in this ... are not stand alone Windows 98 install disks AFSIK.) ... Then run the XP upgrade CD ... then there may be little downside to a clean installation for you. ...
    (microsoft.public.windowsxp.general)
  • Re: How to Repair Office Installation w/o Program Launch?
    ... If your current product is an upgrade version you ... are REQUIRED to retain the qualifying product as a part of your upgrade ... The only way to complete the installation ... I need to detect and repair my Office ...
    (microsoft.public.office.setup)
  • Re: need to upgrade from Office 2001 for Mac
    ... need to upgrade from Office 2001 for Mac ... disk drive and the installer will usually recognise it and just work. ... I'm guessing that the installation files on the floppies are all ...
    (microsoft.public.mac.office)
  • Re: upgrade to Windows XP professional
    ... First the problem The install makes it through the "collecting information" and Dynamic Upgrade" sections. ... If you turn off all of WinXP GUI eye-candy, it will still be very slow, but it might be usable for simple word processing, email, web-browsing, etc. ... But I'm not sure how easy that would be to do with an upgrade CD rather than a new installation CD. ... This information will be found at the PC's manufacturer's web site, and on Microsoft's Windows Catalog: ...
    (microsoft.public.windowsxp.basics)
  • Re: Upgrading to XP w/SP2 from 98SE, via boot of CD
    ... They, or equivalent XP versions, can be reinstalled once the upgrade is ... If you've decided to bite the bullet and go with a clean installation of XP, ... To let you know more of what I use on my comp, and do, I figured I'd give you ... off everything, including the antivirus program, while upgrading. ...
    (microsoft.public.windowsxp.setup_deployment)

Quantcast