Security Incidents mailing list archives

Re: FW: SANS FLASH: New Trojan Sending Data To Russia


From: Yury Bokhoncovich <byg () FIS NSK SU>
Date: Tue, 1 Aug 2000 11:41:28 +0700

Hi, there!
Ed Padin wrote:

Can anyone shed more light on this?

-----Original Message-----
From: The SANS Institute [mailto:sans () sans org]
Sent: Friday, July 28, 2000 8:35 PM
Subject: SANS FLASH: New Trojan Sending Data To Russia

SANS Flash Report: Trojans Sending More Data To Russia
July 28, 2000, 6:20 pm, EDT

This is preliminary information.  The GIAC (Global Incident
Analysis Center) has received several submissions showing large
amounts of data being sent, illegitimately, from Windows 98
machines to a Russian IP address (194.87.6.X).  The cause is most
probably a Trojan, but whatever it is, it is moving fast.

What you should do?

1. All sites should block network traffic from or to 194.87.6.X

Listen, you're wrong here. You gave wrong recipe 'cos one should first
contact
hostmaster of the certain network (demos.su in this case) to disable the
intruder.
Instead you suggest bad solution to block THE WHOLE NET. If would I like
to follow the suggested solution,
I could block  a few dozen Dial-Up Networks of various places around the
world, including
California, Germany, Czech, Brazil and so on just because scans'
orginators sit there.
Anyway good FireWall rules are on your part.
BTW, what does mean "illegitimately" here? Since you've connected to
Internet,
everyone can and may to access your machine if you have made special
efforts to disable
or to limit such the access before.

[stuff snipped]
--
WBR, Yury Bokhoncovich,
SysAdmin at FIS.
voice call: +7 (3832) 119727 pager: +7 (3832) 186555/61621
mailto: byg () fis ru            visit us: http://www.fis.ru/


Current thread: