Weird network activity (Stealth packets) ... what to do?

OT: anything goes!

Moderator: Edi

Post Reply
User avatar
Durandal
Bile-Driven Hate Machine
Posts: 17927
Joined: 2002-07-03 06:26pm
Location: Silicon Valley, CA
Contact:

Weird network activity (Stealth packets) ... what to do?

Post by Durandal »

Someone's taken to hitting my machine with Stealth packets and packets with bad TCP lengths, or so Snort is reporting. Could someone enlighten me as to what this means? Here are two sample log entries.

Code: Select all

[**] [111:1:1] (spp_stream4) STEALTH ACTIVITY (unknown) detection [**]
04/11-05:03:05.932299 81.72.19.237:3456 -> 10.42.8.170:59454
TCP TTL:106 TOS:0x0 ID:28821 IpLen:20 DgmLen:40 DF
***A*R*F Seq: 0x0  Ack: 0x346134C0  Win: 0x0  TcpLen: 20
and

Code: Select all

[**] [116:54:1] (snort_decoder): Tcp Options found with bad lengths [**]
04/13-12:48:55.592189 80.194.57.119:0 -> 10.42.8.170:0
TCP TTL:43 TOS:0x0 ID:57632 IpLen:20 DgmLen:52 DF
***A**** Seq: 0x89A4F91F  Ack: 0xA18B0750  Win: 0xC330  TcpLen: 32
Somehow, this guy is targeting my LAN address from outside my LAN. I'm on my school's network, and everyone has a LAN IP, but there is only one external IP. This activity has been going on for a few days, a couple of times a day. What is this guy trying to pull, and how should I go about averting it?
Damien Sorresso

"Ever see what them computa bitchez do to numbas? It ain't natural. Numbas ain't supposed to be code, they supposed to quantify shit."
- The Onion
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Okay I am out of shape in protocol analysys but i'll give it a shot.


"04/11-05:03:05.932299" = Timestamp

81.72.19.237:3456 = Source IP / Port

10.42.8.170:59454 = Destination IP / Port

TCP = Protocol

TTL:106 = Time To Live. This one is malformed normal is ttl=30

TOS:0x0 ID:28821= Type Of Service (NetBios if i member right)

IpLen:20 = the IP header length

DgmLen:40 DF = total packet length as seen by the IP layer

Hope this helps

***A*R*F Seq: 0x0 Ack: 0x346134C0 Win: 0x0 TcpLen: 20
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Blah I am out of shape.

Ahh well check this out.

http://www.sans.org/resources/tcpip.pdf

Great stuff for tcp/ip have some intresting stuff in my comp.

PM me if you vant me to mail those pdf's to you
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Faram wrote:Okay I am out of shape in protocol analysys but i'll give it a shot.


"04/11-05:03:05.932299" = Timestamp

81.72.19.237:3456 = Source IP / Port

10.42.8.170:59454 = Destination IP / Port

TCP = Protocol

TTL:106 = Time To Live. This one is malformed normal is ttl=30

TOS:0x0 ID:28821= Type Of Service (NetBios if i member right)

IpLen:20 = the IP header length

DgmLen:40 DF = total packet length as seen by the IP layer

Hope this helps

***A*R*F Seq: 0x0 Ack: 0x346134C0 Win: 0x0 TcpLen: 20
Where do you learn this stuff? Any online resources?

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Pu-239 wrote:Where do you learn this stuff? Any online resources?
Look at my profile I work with this shit ;)

Anyways for a good start into tcp/ip check out sans

www.sans.org
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Re: Weird network activity (Stealth packets) ... what to do?

Post by Darth Wong »

Durandal wrote:Somehow, this guy is targeting my LAN address from outside my LAN. I'm on my school's network, and everyone has a LAN IP, but there is only one external IP.
On a network address translation network, an attacker shouldn't be able to address an individual machine on the inside unless:

A) He's compromised the router somehow.
B) Your machine is connecting out. Maybe you have a trojan or spyware installed.
C) He's on the inside and he's IP-spoofing to make it look like it's coming from outside.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
Exonerate
Sith Marauder
Posts: 4454
Joined: 2002-10-29 07:19pm
Location: DC Metro Area

Post by Exonerate »

This is just a guess, but I think I recall some method of doing some scanning of computers behind a firewall by fixing the TTL so that it would expire right after the firewall. Try http://www.packetfactory.net/firewalk/ for more information.

Of course, you could ask Ein, since he's supposed to be acknowledable in this area.

BoTM, MM, HAB, JL
User avatar
Durandal
Bile-Driven Hate Machine
Posts: 17927
Joined: 2002-07-03 06:26pm
Location: Silicon Valley, CA
Contact:

Re: Weird network activity (Stealth packets) ... what to do?

Post by Durandal »

Darth Wong wrote:On a network address translation network, an attacker shouldn't be able to address an individual machine on the inside unless:

A) He's compromised the router somehow.
Possible. Our school does allow VPN access. All he needs to do is trick one student or faculty member into telling him his password. The login can be obtained by a simple LDAP seach, and our LDAP server is publicly accessible.
B) Your machine is connecting out. Maybe you have a trojan or spyware installed.
I'll check my network activity, but such a trojan would have to compile and run on Mac OS X. What's a good GPL utility for checking this out? I've been having some trouble getting ntop to work correctly.
C) He's on the inside and he's IP-spoofing to make it look like it's coming from outside.
I guess that's also possible. I'll have to check and see if similar packets come from different addresses.
Damien Sorresso

"Ever see what them computa bitchez do to numbas? It ain't natural. Numbas ain't supposed to be code, they supposed to quantify shit."
- The Onion
User avatar
Durandal
Bile-Driven Hate Machine
Posts: 17927
Joined: 2002-07-03 06:26pm
Location: Silicon Valley, CA
Contact:

Post by Durandal »

Well, I just ran netstat ...
Apparently, I have an http connection to 64.246.34.100 on my local port 51632. It has no lookup name, but putting it in my address bar takes me to the Georgia Tech Society of Black Engineers ... what the fuck?
Damien Sorresso

"Ever see what them computa bitchez do to numbas? It ain't natural. Numbas ain't supposed to be code, they supposed to quantify shit."
- The Onion
User avatar
TrailerParkJawa
Sith Acolyte
Posts: 5850
Joined: 2002-07-04 11:49pm
Location: San Jose, California

Post by TrailerParkJawa »

Durandal wrote:Well, I just ran netstat ...
Apparently, I have an http connection to 64.246.34.100 on my local port 51632. It has no lookup name, but putting it in my address bar takes me to the Georgia Tech Society of Black Engineers ... what the fuck?
That server is running apache of some sorts. Dunno how its connected to you though.
MEMBER of the Anti-PETA Anti-Facist LEAGUE
Post Reply