Security Incidents mailing list archives
Re: Compromised Win2000 machine.
From: H C <keydet89 () yahoo com>
Date: Wed, 29 May 2002 13:37:47 -0700 (PDT)
Mark, Since fport.exe isn't native to any MS system, you'd have to get it from the 'net someplace. The thing to do (and I do this in the IR course I teach) would be to burn your tools to a CD. If you can't do that, then you can put them on a diskette and write-protect it. HTH. --- Mark Newby <mark () dranton com> wrote:
H C wrote: > [...]Danny took the typical action seen of most admins...port scanning the system from theoutside,and comparing the open ports to lists of knowntrojansand services. This is inconclusive at best, andleadsto a lot of speculation and time-wasting. Bettertorun fport on the system (if NT/2K...if the systemisXP, run netstat w/ the '-o' switch) instead, toseethe process to port mapping. [...]...but I thought the advice for a (possibly) compromised box was *not* to run executable programs that resided on that host, as they can't be trusted? mark
__________________________________________________ Do You Yahoo!? Yahoo! - Official partner of 2002 FIFA World Cup http://fifaworldcup.yahoo.com ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Compromised Win2000 machine. Daniel Hay (May 28)
- Re: Compromised Win2000 machine. H C (May 28)
- RE: Compromised Win2000 machine. Kit (May 28)
- RE: Compromised Win2000 machine. Don Weber (May 29)
- RE: Compromised Win2000 machine. H C (May 29)
- Re: Compromised Win2000 machine. Daniel Hay (May 29)
- Re: Compromised Win2000 machine. Mark Newby (May 29)
- Re: Compromised Win2000 machine. H C (May 29)
- Re: Compromised Win2000 machine. Patrick Andry (May 29)
- Re: Compromised Win2000 machine. H C (May 30)
- Re: Compromised Win2000 machine. - Follow UP Daniel Hay (May 30)
- Re[2]: Compromised Win2000 machine. Joris De Donder (May 31)
- Re: Re[2]: Compromised Win2000 machine. H C (May 31)
- RE: Compromised Win2000 machine. Don Weber (May 29)
- <Possible follow-ups>
- Re: Compromised Win2000 machine. ghb the irrepressible (May 29)
