Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: [Dshield] [OT] Naughty File Detector
.

  • To: General DShield Discussion List <[EMAIL PROTECTED]>
  • Subject: Re: [Dshield] [OT] Naughty File Detector
  • From: John Hardin <[EMAIL PROTECTED]>
  • Date: Thu, 02 Oct 2003 09:00:54 -0700
  • In-reply-to: <[EMAIL PROTECTED]>
  • Old-x-envelope-to: [EMAIL PROTECTED]
  • Organization: Apropos Retail Management Systems, Inc.
  • References: <[EMAIL PROTECTED]>
  • Reply-to: General DShield Discussion List <[EMAIL PROTECTED]>
  • Sender: [EMAIL PROTECTED]
.
 
On Thu, 2003-10-02 at 05:31, DAN MORRILL wrote:
> Port 0 traffic (SetUID 0 or otherwise) have noticed that shareazza (which I 
> do use) will get me port 0 traffic because of the port hopping. Probably 
> something unbound in their port designation. You can also tab on the 
> standard P2P ports to get a tip off, if they are just being turned on, then 
> they usually default to their standard port.

Yup.

If you want to take a step towards earning your BOFH spurs, set up a
monitor on the firewall to automatically completely block all traffic
from the host that sends an outbound packet to the default P2P port
number, and alert you via email.

"Hello, help desk"

"My web browsing stopped working"

"Let me check my logs... hmm... running KaZaa, are we?"

"Uh..."

--
John Hardin  KA7OHZ                           
Internal Systems Administrator                    voice: (425) 672-1304
Apropos Retail Management Systems, Inc.             fax: (425) 672-0192
-----------------------------------------------------------------------
  There is no problem that cannot be solved by the appropriate
  application of high explosives.
-----------------------------------------------------------------------
 34 days until Matrix Revolutions

_______________________________________________
list mailing list
[EMAIL PROTECTED]
To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.