AW: Strange echo requests from 127.0.0.1 apparently toroot nameservers
"Seemüller, Christian" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <8AE0B82BAF99FC4BB8F44F108D49F9B4D7DA4B@exchange.acds.t-systems-sfr.com> |
Hey folks outside, we'd this for sometimes to, it's from the blaster and/or the sasser virus with it's various variants..... Loot at this: http://seclists.org/lists/security-basics/2004/May/0197.html Hope this helps, to find out, who's the top talker, u could look at the switch statistics or use an acl, which protocols the TCP-Dest-Port of the Sasser or Blaster-Virus like this (on a Cat6500 (CAT-OS)) sh mls statistics entry ip dest-port 135 etc. So nothing really brand new..., if u need more help, let us know... chris -----Ursprüngliche Nachricht----- Von: [email protected] [mailto:[email protected]] Im Auftrag von [email protected] Gesendet: Freitag, 27. August 2004 22:32 An: [email protected] Betreff: Re: [Intrusions] Strange echo requests from 127.0.0.1 apparently toroot nameservers Foundstone has a tool, fport, which will "Identify unknown open ports and their associated applications." http://www.foundstone.com Sorry, don't have a direct link to the tool but follow this path: » Home > Resources > Free Tools Quoting Terje Trane <[email protected]>: > > I tried to troubleshoot a PC that all of a sudden would connect but > not > route traffic to a remote site by VPN and started Ethereal to see if I > could > see where the packets were going. > > To my surprise I can see a dozen ICMP echo request packets per second > sent > from 127.0.0.1. Every other is to my internal DNS-servers, and the > rest > (except for a few) to *.root-servers.net and *.gtld-servers.net. > > My thought was that this is malware scanning or trying a DoS on the > DNS, > though AV is up to date and running. However, the firewall technician > says > he cannot see this traffic at the firewall. I tried using tcpdump on > an > other machine on the same hub and cannot see this traffic, so I guess > it > must be local? > > By looking at the MAC-addresses i see that all packets are from > 08:00:2b:00:dc:dc which is not the MAC address of the local PC and > completly > unknown to me, and they are sent to 08:00:2b:00:01:02 which is also > unknown. > 08:00:2b is the vendor code for DEC and we have no DEC equipment here. > > I tried killing the processes I don't know on this PC, but not all will > die. > Is there any way in Windows I can see what process is generating what > TCP/IP > traffic? > > And most important: What can this be? > > > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions