Security problem - telnet connections

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Security problem - telnet connections

Post by Crayz9000 »

I've been noticing some outgoing Telnet connections to mail.traininghott.com lately, but I don't know what's sending them. I took a packet dump of one of the offending packets, which is here (in libpcap format, can be read with Ethereal).

Have any of you heard of anything like this before?

By the way, the mail server is running MS Exchange. And for the moment, I've blocked port 23 at my Linux firewall, so it can still try and send packets but won't have any success.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Run a virs scanner asap and then run a spyware checker.

Unknown outgoint connections IS a BAD thing.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

I've had NAV running, constantly updated, and no beef. AdAware 6 is installed, and a scan only turned up a couple of Internet Explorer cookies that I forgot to get rid of.

Still no clue.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

Crayz9000 wrote:I've had NAV running, constantly updated, and no beef. AdAware 6 is installed, and a scan only turned up a couple of Internet Explorer cookies that I forgot to get rid of.

Still no clue.
Its possible you have a trojan that NAV cant detect. Have you looked at your process' to see if something you dont recognize is running. Since this is Exchange are you up to date with Service Packs, Hot fixes, and critical updates?
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Do you think I'd be stupid enough to run MS Exchange? :P I detected an outgoing telnet connection to a MS Exchange server located at mail.traininghott.com.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

Crayz9000 wrote:Do you think I'd be stupid enough to run MS Exchange? :P I detected an outgoing telnet connection to a MS Exchange server located at mail.traininghott.com.
Hehe, thats wasnt clear from your post. Not to me anyway, Is the machine with the outbounds Linux too?
MEMBER of the Anti-PETA Anti-Facist LEAGUE
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

TrailerParkJawa wrote:Hehe, thats wasnt clear from your post. Not to me anyway, Is the machine with the outbounds Linux too?
No, it's Windows 2000.

Oddly enough, since I restarted my computer haven't had any more connections... :? I'll leave the packetsniffer running while I'm gone, though, and see what turns up.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
Post Reply