How to detect a trojan on a Unix server?

From: Ryo Furue (furufuru@ccsr.u-tokyo.ac.jp)
Date: 05/30/02


From: furufuru@ccsr.u-tokyo.ac.jp (Ryo Furue)
Date: 29 May 2002 21:50:04 -0700

Hi there,

A user reported that when she connected to our FTP server, the Norton
security software on her PC said that the PC got a Trojan attack from,
say, 1.11.11.111 (This is a fictious IP address), which is the FTP
server's IP address. I'm worried because I'm an admin of the server.
Does this mean that the server has some malicious software installed
which scans the ports of hosts connecting to it? How can I examine
what's going on? Could some kind soul refer me to some information
sources? The server is a Sun Ultra 1 with Solaris 2.5.1.

Thank you for your attention,
Ryo



Relevant Pages

  • FTP and router issue
    ... when i try to connect to the ftp server from another machine in the network using the internal IP it works just fine. ... 230 User administrator logged in. ... connecting to i.i.i.i:8001 ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Please help with my lack of understanding
    ... If he's connecting from a Windows box, it would be far more secure to shut down the FTP server and have him connect via VPN connection. ... instead of two switches, or one switch and a lot of cabling. ...
    (microsoft.public.windows.server.sbs)
  • How to detect a trojan on a Unix server?
    ... A user reported that when she connected to our FTP server, ... security software on her PC said that the PC got a Trojan attack from, ... which scans the ports of hosts connecting to it? ...
    (comp.security.unix)
  • Re: Forms authentication - change password
    ... Contact the server administrator. ... I think your authentication validation method needs to be set to ... the change password feature within ISA ... | | meant not connecting to a Global Catalog. ...
    (microsoft.public.isa)
  • Re: SBS Slow user logons problem
    ... Microsoft MVPs ... Are the workstations and Server all connecting their nics to a router? ...
    (microsoft.public.windows.server.sbs)