Re: Traffic spoofed from Localhost 80 - NOT Nachi
"James C. Slora Jr." <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <000d01c4a42f$5fcac940$6565a8c0@IBMPIII> |
An upstream Cisco router (based on the MAC address) is passing the traffic. The compromised router scenario Stan Carey mentioned seems possible, since I have not previously had bogon traffic coming to this network. No stimulus was coming from "my" network at all. I answered appropriate ARP requests and otherwise kept the network entirely silent except for inbound packets. I did some sniffing outside the perimeter router, and this is what I found: 127.0.0.1:80 xx.xx.xx.xx:1903 [RST, ACK] Seq=0 Ack=0 Win=0 Len=0 TTL=125 Packet length is 0x3b - there is a 12-byte trailer of all zeros. Target port varied, but otherwise all the packets were the same. The source is a bogon address that does not normally appear in the logs for this network. The packet is probably forged, so I don't necessarily put any faith in the 3-hop TTL. The upstream now filters out all tracerts, but the third hop upstream is definitely a router at that ISP. 3 hops could also be someone directly connected to the router 2 hops up. BUT, interestingly there was other traffic with a TTL of 125 - a set of skiddie probes to TCP 3410 amd 5554. There were also ICMP Destination unreachables coming in resulting from Joe Job Messenger spam. Go figure. The complaining target had "my" IP address with the first octet incremented by one. Several of these came in, always from the same address. AL > Please refer to http://www.adldatacomm.net/tips.html and click on 'Traffic AL > from 127.0.0.1 with a source port of 80' Thanks for the link, but I was trying to show that my traffic contrasts with the common packets that article describes. Blaster/Nachi/whatever traffic related to that article occurs inside the perimeter, and is destined for the source of the infection. Misguided localhost null routing got popularized for Blaster (rather than Nachi as I mistakenly wrote) as you correctly pointed out, but localhost-sourced RST traffic can occur whenever people use localhost null routing as an egress filtering defense anywhere inside the perimeter. JS > These hits are all on the external router interface, at the perimeter. Only JS > one machine has been on that LAN during this period. JS > This traffic just started today for the first time. The reporting device is JS > a router. Nothing inside it has ever had its host file altered in any JS > misguided Nachi defense. The hosts file has not been altered to point sites to localhost. Verified now. DNS was never configured in this way either. No immediate stimulus triggers the spoofed-source packets. JS > 2004-09-22 22:41:42 127.0.0.1 80 xx.xx.xx.xx 1653 JS > 2004-09-22 22:42:33 127.0.0.1 80 xx.xx.xx.xx 1909 JS > 2004-09-22 23:54:46 127.0.0.1 80 xx.xx.xx.xx 1096 These would indicate a mundane infection if they occurred on the internal interface, but should never appear on the external interface unless there are some upstream problems and mischief. _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions