FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] OT? New compromise.

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Subject: Re: [fw-wiz] OT? New compromise.
From: "Paul D. Robertson" <probertson@FluidITGroup.com>
Date: Thu, 29 Mar 2007 16:07:15 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <460ADFF2.8060502@infiltrated.net>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <1897E92A96C47648A6574CB9A51C64070229BAB8@SEBEV1PW.graybar.com> <460AB2FA.7010400@infiltrated.net> <bf6826070703281308m5611cbdendda26dcd2166bef4@mail.gmail.com> <460ADFF2.8060502@infiltrated.net>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Thunderbird 1.5.0.10 (Macintosh/20070221)
J. Oquendo wrote:
[Pine doesn't like the encoding, so I'm replying from this account]
> Stian Øvrevåge wrote:
>
>>> On Windows
>>> /c:\netstat -an |find /i "listening"/
>>>
>>> Why download when you can use existing tools...
>>>
>>
>> Ever heard of rootkits?
>>
> No I haven't can I buy this somewhere? I don't use Windows but if I

Come on, the point was very valid.  I wish more admins would consider it 
when things go from incident to investigation it's important.
>
> Sysinternals (before MS rolled over them) had some neat tools one
> of which provided the admin with the name of the program running
> that had said ports opened along with the DLL file information, etc.
> I'm sure older Forensics disks (F.I.R.E, Snarl) etc., have the tool
> on them.
>

Sysinternals *still* has some neat tools, and (yep, mark it on your 
calendars, I'm saying it) Microsoft rolling over them has actually 
improved things somewhat.  Instead of multiple versions, you now tend to 
get just one binary that'll run on all the platforms.  They're still 
redirecting the URL too.

Paul

-- 
President and Chairman, FluidIT Group
Moderator, Firewall-Wizards.  Editor, Network Firewall FAQ
New blog:  http://www.fluiditgroup.com/blog/pdr/ 

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>