Re: ICMP - What the hell are these log files telling me.....
From: Gary Brett (globalg2001_at_yahoo.co.uk)
Date: 10/31/03
- Next message: Gary Brett: "Sockets De Trois V1"
- Previous message: CBP: "Re: BlackICE Uninstall/Install problems!!!"
- In reply to: Maxime Ducharme: "Re: ICMP - What the hell are these log files telling me....."
- Next in thread: Maxime Ducharme: "Re: ICMP - What the hell are these log files telling me....."
- Reply: Maxime Ducharme: "Re: ICMP - What the hell are these log files telling me....."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 31 Oct 2003 02:02:26 -0800
Thanx for the response.
Will check the sugggestion out. Is it a good idea to turn off logging
of ICMP on the SonicWALL, to reduce the log files do you think?
Also after I wrote the original message I discovered I had a "Sockets
De Trois V1" trojan on all my LAN XP Pro machines. I have since closed
port 5000 on the Firewall and have disabled "SSDP Discovery Service"
in WinXP Services. This seems to have stopped the Trojan, but do you
know how it entered the LAN and what it actaully does when inside.
Again thanx for your time..
Gary
> The worm Welchia do ping scans (ICMP type 8) before trying
> to infect foreign hosts.
>
> There are surely lots of these, and manual scans too.
>
> I get 250 hits per day for this worm.
>
> You may confirm this by sniffing packets & looking at the ping payload,
> Welchia sends 64 bytes of 'a' char.
>
> ref :
> http://securityresponse.symantec.com/avcenter/venc/data/detecting.traffic.due.to.rpc.worms.html
>
> Ciao
>
> ---------------------------------------------------------------
> Maxime Ducharme
> Administrateur reseau, Programmeur
>
- Next message: Gary Brett: "Sockets De Trois V1"
- Previous message: CBP: "Re: BlackICE Uninstall/Install problems!!!"
- In reply to: Maxime Ducharme: "Re: ICMP - What the hell are these log files telling me....."
- Next in thread: Maxime Ducharme: "Re: ICMP - What the hell are these log files telling me....."
- Reply: Maxime Ducharme: "Re: ICMP - What the hell are these log files telling me....."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|