AW: Strange echo requests from 127.0.0.1 apparently toroot nameservers

"Seemüller, Christian" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <8AE0B82BAF99FC4BB8F44F108D49F9B4D7DA4B@exchange.acds.t-systems-sfr.com>
Hey folks outside,

we'd this for sometimes to, it's from the blaster and/or the sasser virus with it's various variants.....
Loot at this:

http://seclists.org/lists/security-basics/2004/May/0197.html

Hope this helps, to find out, who's the top talker, u could look at the switch statistics or use an acl, which protocols the TCP-Dest-Port of the Sasser or Blaster-Virus like this (on a Cat6500 (CAT-OS))

sh mls statistics entry ip dest-port 135 etc.

So nothing really brand new..., if u need more help, let us know...
chris
-----Ursprüngliche Nachricht-----
Von: [email protected] [mailto:[email protected]] Im Auftrag von [email protected]
Gesendet: Freitag, 27. August 2004 22:32
An: [email protected]
Betreff: Re: [Intrusions] Strange echo requests from 127.0.0.1 apparently toroot nameservers

Foundstone has a tool, fport, which will "Identify unknown open ports and their
associated applications."

http://www.foundstone.com 

Sorry, don't have a direct link to the tool but follow this path:
» Home > Resources > Free Tools


Quoting Terje Trane <[email protected]>:

> 
> I tried to troubleshoot a PC that all of a sudden would connect but
> not
> route traffic to a remote site by VPN and started Ethereal to see if I
> could
> see where the packets were going.
> 
> To my surprise I can see a dozen ICMP echo request packets per second
> sent
> from 127.0.0.1. Every other is to my internal DNS-servers, and the
> rest
> (except for a few) to *.root-servers.net and *.gtld-servers.net.
> 
> My thought was that this is malware scanning or trying a DoS on the
> DNS,
> though AV is up to date and running. However, the firewall technician
> says
> he cannot see this traffic at the firewall. I tried using tcpdump on
> an
> other machine on the same hub and cannot see this traffic, so I guess
> it
> must be local?
> 
> By looking at the MAC-addresses i see that all packets are from
> 08:00:2b:00:dc:dc which is not the MAC address of the local PC and
> completly
> unknown to me, and they are sent to 08:00:2b:00:01:02 which is also
> unknown.
> 08:00:2b is the vendor code for DEC and we have no DEC equipment here.
> 
> I tried killing the processes I don't know on this PC, but not all will
> die.
> Is there any way in Windows I can see what process is generating what
> TCP/IP
> traffic?
> 
> And most important: What can this be?
> 
> 
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
> 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.