I've been noticing some outgoing Telnet connections to mail.traininghott.com lately, but I don't know what's sending them. I took a packet dump of one of the offending packets, which is here (in libpcap format, can be read with Ethereal).
Have any of you heard of anything like this before?
By the way, the mail server is running MS Exchange. And for the moment, I've blocked port 23 at my Linux firewall, so it can still try and send packets but won't have any success.
Security problem - telnet connections
Moderator: Thanas
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
Security problem - telnet connections
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- Faram
- Bastard Operator from Hell
- Posts: 5271
- Joined: 2002-07-04 07:39am
- Location: Fighting Polarbears
Run a virs scanner asap and then run a spyware checker.
Unknown outgoint connections IS a BAD thing.
Unknown outgoint connections IS a BAD thing.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus
Fear is the mother of all gods.
Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
I've had NAV running, constantly updated, and no beef. AdAware 6 is installed, and a scan only turned up a couple of Internet Explorer cookies that I forgot to get rid of.
Still no clue.
Still no clue.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- TrailerParkJawa
- Sith Acolyte
- Posts: 5850
- Joined: 2002-07-04 11:49pm
- Location: San Jose, California
Its possible you have a trojan that NAV cant detect. Have you looked at your process' to see if something you dont recognize is running. Since this is Exchange are you up to date with Service Packs, Hot fixes, and critical updates?Crayz9000 wrote:I've had NAV running, constantly updated, and no beef. AdAware 6 is installed, and a scan only turned up a couple of Internet Explorer cookies that I forgot to get rid of.
Still no clue.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
Do you think I'd be stupid enough to run MS Exchange? I detected an outgoing telnet connection to a MS Exchange server located at mail.traininghott.com.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
- TrailerParkJawa
- Sith Acolyte
- Posts: 5850
- Joined: 2002-07-04 11:49pm
- Location: San Jose, California
Hehe, thats wasnt clear from your post. Not to me anyway, Is the machine with the outbounds Linux too?Crayz9000 wrote:Do you think I'd be stupid enough to run MS Exchange? I detected an outgoing telnet connection to a MS Exchange server located at mail.traininghott.com.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
- Crayz9000
- Sith Apprentice
- Posts: 7329
- Joined: 2002-07-03 06:39pm
- Location: Improbably superpositioned
- Contact:
No, it's Windows 2000.TrailerParkJawa wrote:Hehe, thats wasnt clear from your post. Not to me anyway, Is the machine with the outbounds Linux too?
Oddly enough, since I restarted my computer haven't had any more connections... I'll leave the packetsniffer running while I'm gone, though, and see what turns up.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF