FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] worm?

To: "Firewall Wizards Security Mailing List" <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] worm?
From: "Francois Yang" <francois.y@gmail.com>
Date: Thu, 1 Feb 2007 15:55:29 -0600
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <Pine.LNX.4.44.0702011622480.28771-100000@bat.clueby4.org>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <3c4611bc0702011045q66c03488wf608861119ecbd2d@mail.gmail.com> <Pine.LNX.4.44.0702011622480.28771-100000@bat.clueby4.org>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
You could use FakeDNS and MailPot to maybe capture what happens after
the connection is created.  here is the link to the tools.  I haven't
used them, but I know they can be used for things like this.
http://labs.idefense.com/files/labs/releases/previews/map/



On 2/1/07, Paul D. Robertson <paul@compuwar.net> wrote:
> On Thu, 1 Feb 2007, Brian Loe wrote:
>
> > One of our support technician's machines is attempting to connect to
> > random IP addresses on port 25 - in a pretty needy fashion. He says
> > he's scanned the box with the latest updates from McAffee and it
> > hasn't found anything.
> >
> > We discovered it because one of my basic (meaning I got it off the
> > 'Net) rules for SEC flagged it as a possible PHEL trojan.
> >
> > Any thoughts?
>
> See what process keeps opening sockets?
>
> Paul
> -----------------------------------------------------------------------------
> Paul D. Robertson      "My statements in this message are personal opinions
> paul@compuwar.net       which may have no basis whatsoever in fact."
>
> _______________________________________________
> firewall-wizards mailing list
> firewall-wizards@listserv.icsalabs.com
> https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
>


-- 
If you think technology can solve your security problems, then you
don't understand the problems and you don't understand the technology.
Bruce Schneier
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>