Re: Traffic spoofed from Localhost 80 - NOT Nachi

"James C. Slora Jr." <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <000d01c4a42f$5fcac940$6565a8c0@IBMPIII>
An upstream Cisco router (based on the MAC address) is passing the traffic.
The compromised router scenario Stan Carey mentioned seems possible, since I
have not previously had bogon traffic coming to this network.

No stimulus was coming from "my" network at all. I answered appropriate ARP
requests and otherwise kept the network entirely silent except for inbound
packets.

I did some sniffing outside the perimeter router, and this is what I found:

127.0.0.1:80 xx.xx.xx.xx:1903 [RST, ACK] Seq=0 Ack=0 Win=0 Len=0 TTL=125
Packet length is 0x3b - there is a 12-byte trailer of all zeros. Target port
varied, but otherwise all the packets were the same.

The source is a bogon address that does not normally appear in the logs for
this network. The packet is probably forged, so I don't necessarily put any
faith in the 3-hop TTL. The upstream now filters out all tracerts, but the
third hop upstream is definitely a router at that ISP. 3 hops could also be
someone directly connected to the router 2 hops up.

BUT, interestingly there was other traffic with a TTL of 125 - a set of
skiddie probes to TCP 3410 amd 5554.

There were also ICMP Destination unreachables coming in resulting from Joe
Job Messenger spam. Go figure. The complaining target had "my" IP address
with the first octet incremented by one. Several of these came in, always
from the same address.


AL > Please refer to http://www.adldatacomm.net/tips.html and click on
'Traffic
AL > from 127.0.0.1 with a source port of 80'

Thanks for the link, but I was trying to show that my traffic contrasts with
the common packets that article describes. Blaster/Nachi/whatever traffic
related to that article occurs inside the perimeter, and is destined for the
source of the infection. Misguided localhost null routing got popularized
for Blaster (rather than Nachi as I mistakenly wrote) as you correctly
pointed out, but localhost-sourced RST traffic can occur whenever people use
localhost null routing as an egress filtering defense anywhere inside the
perimeter.

JS  > These hits are all on the external router interface, at the perimeter.
Only
JS > one machine has been on that LAN during this period.

JS > This traffic just started today for the first time. The reporting
device is
JS > a router. Nothing inside it has ever had its host file altered in any
JS > misguided Nachi defense.

The hosts file has not been altered to point sites to localhost. Verified
now. DNS was never configured in this way either. No immediate stimulus
triggers the spoofed-source packets.

JS > 2004-09-22 22:41:42 127.0.0.1 80 xx.xx.xx.xx 1653
JS > 2004-09-22 22:42:33 127.0.0.1 80 xx.xx.xx.xx 1909
JS > 2004-09-22 23:54:46 127.0.0.1 80 xx.xx.xx.xx 1096

These would indicate a mundane infection if they occurred on the internal
interface, but should never appear on the external interface unless there
are some upstream problems and mischief.



_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.