Re: Possible Compromise - Need Suggestions

From: Jim Richardson (warlock_at_eskimo.com)
Date: 02/15/05

  • Next message: jurij_at_device-image.de: "ANOUNCEMENT: zsplit, unzsplit: free linux tools to make a full drive image backup!"
    Date: Tue, 15 Feb 2005 02:08:13 -0800
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    On Tue, 15 Feb 2005 14:58:59 +1300,
     Jon <wiseguy@ihug.co.nz> wrote:
    > Hi all,
    >
    > I recently (2-3 days ago) reinstalled my Linux Workstation. About a day
    > after setting it up I noticed some weird outbound traffic in my firewall
    > logs. I've set up my firewall to log but accept outbound traffic to
    > non-standard ports. The destination ports for this traffic were in the
    > 4000-5000 range. After noticing this I started logging everything to and
    > from this ip. I've been busy at work so haven't had time to have a good look
    > at this but a quick browse through the logs showed my box was also trying
    > port 21 (telnet) on this IP. This certainly isn't me and nobody else has a
    > shell.
    >

    port 21 is ftp, not telnet. Without more info, it would be hard to say.
    But I'd suspect it was the update process, if you can catch the traffic
    in the act so to speak, you can use netstat to find what process is
    making the connection, and go from there.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.5 (GNU/Linux)

    iD8DBQFCEcoNd90bcYOAWPYRArl5AJ9p6ufPb2Tcq8BKKK7NJ2+tLQlNgACfYmCB
    vqemxXI+KtvOoGjHBa8cbVc=
    =akWq
    -----END PGP SIGNATURE-----

    -- 
    Jim Richardson     http://www.eskimo.com/~warlock
    Honesty may be the best policy, but insanity is a better defense.
    

  • Next message: jurij_at_device-image.de: "ANOUNCEMENT: zsplit, unzsplit: free linux tools to make a full drive image backup!"

    Relevant Pages

    • Re: Opening port on workstation
      ... Our firewall is from Cisco and is specific for our industry as the FBI and NCIC require a specific level of encryption. ... It only works if the Administrator logs onto the computer, then logs out and the user logs in and starts the program. ... It will stay that way no matter the number of logins till the computer gets shut down, and then the administrator has to log in again to restore the ports. ...
      (microsoft.public.windows.server.sbs)
    • Re: Server being hacked!
      ... > I ma getting on my security event log mutiple failures to ... > that I can block them from TCPIP or from a firewall. ... It's far more important to block the right ports than to run around trying ... logs to that computer. ...
      (microsoft.public.win2000.security)
    • Re: Firewall / Network Monitoring
      ... >I am using several different programs for monitoring my Firewall & Network. ... >All of these programs allow for SMTP messages to be sent when certain ... >common virus ports, devices failing to ping, etc.) when they occur, they ... If you have already reviewed the logs on a regular basis, ...
      (comp.security.firewalls)
    • Re: IIS FTP and WWW through router firewall
      ... Whenever troubleshooting a possible firewall problem, ... check is always your firewall logs for which ports are being blocked and by ... Both HTTP and FTP also generally require DNS, which uses TCP and UDP ports ...
      (microsoft.public.inetserver.iis.security)
    • Re: Strange WAN Activity
      ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ...
      (microsoft.public.win2000.security)