Security Incidents mailing list archives
re: Help - a possible bot
From: H C <keydet89 () yahoo com>
Date: Sat, 16 Nov 2002 05:10:47 -0800 (PST)
The problem is, I am detecting a suspicious
hit/respond
activity, which, in my opinion, points to an active bot.
No offense, dude, but you're freaking out over nothing. Based on the information you provided, there IS no bot (remember "The Matrix"? "There is no spoon").
Here's the evidence: when inspecting ZA logs, you
can
see a blocked scan (coming every couple of minutes, from arbitrary addresses
The "scans" you're referring to look like NetBIOS name scans...queries to UDP port 137. On normal MS networks, these "scans" would originate from UDP port 137, as well. So...they MAY be scans of some kind. However, the fact that your system is responding would be indicative of something else, possibly w/ your ZA installation.
- I bet they're spoofed
Well, that's not "evidence", now, is it? Also, since your logs don't show an ICMP port unreachable response (your system sent out a UDP datagram), that would indicate that, in fact, the source IPs are NOT spoofed. Also, there's nothing in the netstat and fport outputs that you sent that seem to indicate that you have any sort of bot or trojan at all. Is there anything besides the traffic you posted that would lead you to believe that you had something installed on your system? HTH __________________________________________________ Do you Yahoo!? Yahoo! Web Hosting - Let the expert host your site http://webhosting.yahoo.com ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- re: Help - a possible bot H C (Nov 17)
- Re: Help - a possible bot Moshe Aelion (Nov 25)
- Re: Help - a possible bot Ryan Yagatich (Nov 26)
- <Possible follow-ups>
- RE: Help - a possible bot Dan Perez (Nov 17)
- Re: Help - a possible bot Nick FitzGerald (Nov 17)
- Re: Help - a possible bot Emeric Miszti (Nov 17)
- Re: Help - a possible bot Moshe Aelion (Nov 25)
- Re: Help - a possible bot Jon Nelson (Nov 17)
- Re: Help - a possible bot Mally Mclane (Nov 19)
- Re: Help - a possible bot Moshe Aelion (Nov 25)