[prev in list] [next in list] [prev in thread] [next in thread] 

List:       incidents
Subject:    RE: Trojan?
From:       "Kirt Cathey" <kirt () futamatagawa ! net>
Date:       2003-08-24 0:26:34
[Download RAW message or body]

Despite what the Blackice logs might say..... this looks like the firewall
is receiving a HTTP GET from
the client. The attacker is attempting a very rouge outdated buffer overflow
attack on your web server.

Of course, this all has "I THINK" conditioned around what I say.

/***************************************
Kirt S. Cathey, CIA, CISA, CISSP, MCSE
PricewaterhouseCoopers - Tokyo, Japan
Intrusion Detection, Forensics, and Audit
080-3388-6798
www.systemsrisk.com
PGP: http://www.systemsrisk.com/pgp.txt
***************************************/

-----Original Message-----
From: Vinny Bedus [mailto:vbedus@bitchangers.com]
Sent: Friday, August 22, 2003 3:46 AM
To: incidents@securityfocus.com
Subject: Trojan?


All,

I have noticed the following in my black ice logs:

HTTP_URL_Name_Very_Long, serverip, servername, 210.108.137.153, ,
URL=/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA,
1, B, 80, 36286, 0x188006

This says that the server itself is sending a web request out to a
client machine at 210.108.137.153.

I ran tcpView and it does not show any outgoing activity, but I am not
sure that utility will show that activity.  We run Norton Corp AV, and
it does not pick up anything in a full scan.  We checked the box for the
usually suspects, and nothing was found.  Anyone have any ideas?  Could
black ice possibly have it backwards?

Thanks in advance.


Vinny Bedus
Bit Changers
http://www.BitChangers.com


---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
technical IT security event.  Modeled after the famous Black Hat event in
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
Symantec is the Diamond sponsor.  Early-bird registration ends September
6.Visit us: www.blackhat.com
----------------------------------------------------------------------------


---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
----------------------------------------------------------------------------

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic