LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-25-2001, 03:51 AM   #1
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
Angry


Anyone,

Can someone be on one of our internal company laptops?
"I recall MS having this issue and losing some source code"

I ask this because I got an email from one of my IDS boxes, telling me that an internal IP address has requested a multicast address with a unusual ICMP type.

The PC that asked this did something very strange for a 98 system, it asked the IP range 244.0.0.2 for an ICMP type 10 request.

This means it asked all the multicast address on the subnet for a router solicitation request.

The laptop user sometimes dials up while connect to the LAN to check hotmail accounts.
I'm sure someone has put a Trojan on his box while he's been unfirewalled and now it's trying to scan my network and report the routers to an unknown source from the inside.

The laptop also has port 1029 open and ready for a connection, any idea what's that port for as I don't recall it as standard to 98.. eg 137, 139

In the mean time his system is quarantined and all packets are having a stateful inspection.

Any ideas.
/Raz
 
Old 04-27-2001, 04:19 AM   #2
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Original Poster
Rep: Reputation: 31
Smile

If anyone is interested I've figured this out.
It's a bug I haven't seen on windozes before.

When you take a 98 system off a BOOTp service "DHCP" and back to static ip it's fine then once you dialup next time it comes off back to static IP it looks for routers, even when it knows them.

/Raz
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Horse on my Linux Box? Tons of Fun Linux - Security 3 09-24-2005 01:58 PM
Trojan Horse Hugh Jass LinuxQuestions.org Member Intro 4 02-13-2005 09:58 AM
A dead horse named dri Motown Slackware 7 11-18-2004 07:57 AM
Windows "Longhorn" FAQ, the commercial trojan horse. Edward78 General 13 02-14-2003 02:14 PM
Microsoft's Trojan horse Psycho General 6 05-03-2002 12:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration