FYI: NIS & XP firewall [Re: XP and Norton Firewalls]

From: Distendo (distendo_at_yahoo.co.uk)
Date: 06/25/03


Date: Wed, 25 Jun 2003 14:43:19 +0100

I was looking round this NG for posts about NIS (2001), as my ftp
programs (Dreamweaver & ws_ftp) had suddenly begun triggering a
'Default block Soket de Trois v1 trojan' alert, and were unable to
receive data from (some) ftp servers.

Disabling NIS demonstrated that it was a local fault, and a virus scan
& review indicated my system was clean, so I concluded that there was
something about the ftp incoming data at the 'List directory contents'
request, that was triggering the trojan alert.

My Internet connection is via a router [Netgear DG814], which has its
own built-in firewall. I can't find any info on it for this posting,
but as I recall, it's somewhat limited. However, since installing
that arrangement, I'd never had a trojan alert, whereas previously
when using a cable modem I switched off the trojan 7 alert, as it was
going off many times an hour and clogging the log, so I guess the
DG814 is doing its job.

It was another posting (XP and Norton Firewalls) which reminded me I'd
activated XP's firewall. I deactivated it, and it looks like that's
cured the problem. Ftp access restored, and [it seems] no more trojan
alerts.

Curious, though, that the over-walled arrangement would cause incoming
data from an ftp server to be mistaken as a trojan 'enquiry'.

I expect that some will say that with NIS, anything [bad] is possible,
but I would like to mention that I've found it a satisfactory product,
integrating well, for instance, with my Pegasus email client, where
it's intercepted various viral attachments over the years.



Relevant Pages

  • Re: Query - password expiry alert
    ... Is there a way to get alert when password expires ... My users were not alerted when they used ftp service in solaris 10. ... How to check whether the service is using PAM module and how to ...
    (comp.unix.solaris)
  • Re: ServU-deamon trojan warning with McAfee
    ... 'Nothing other then finding a FTP trojan on my system has occured.' ... Your ISA, according to the port report you posted, is letting through a lot ... My logs and my ISP's logs don't ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: SUMMARY: Ftp error
    ... Hal Huntley, Matthew Stier, Edward Scown, jim, Matthew Stier, Douglas Palmer ... I manually change the password for NIS user account who were not able to login and pushed the map. ... complaninng that they can not ftp. ...
    (SunManagers)
  • Re: Backdoor.OptixPro.13
    ... experience removing the servu ftp. ... Look around those folders because someone probably copied ... > I know nothing of that particular trojan, but you should probably flatten> the server and rebuild it. ...
    (microsoft.public.win2000.security)
  • RH9, Vsftp & NIS
    ... I can only get local users to ... login through ftp. ... NIS users aren't allowed. ... Jamie Crawford, MCSE Network Analyst I ...
    (RedHat)

Quantcast