Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-12-2005, 04:15 AM
Tony Brown
Guest
 
Posts: n/a
Default AIX 5.2 local portscanner?

My network guys tell me that one of our local machines is sending out
port scans to a particular host. The "attacking" machine is AIX 5.2.
I have been tcpdumping for 2 days and have not seen anything
significant. I installed lsof and nothing is showing up. For clarity
I installed this and am monitoring on the "attacking" machine. Still
the port scans exist.

Does anyone know of a tool that will definitively tell me what process
is causing this?

TIA,
T.

Reply With Quote
  #2 (permalink)  
Old 10-12-2005, 01:50 PM
Donnie
Guest
 
Posts: n/a
Default Re: AIX 5.2 local portscanner?


"Tony Brown" <tony.brown2@comcast.net> wrote in message
news:t53pk1l6d8b6ab0gs6845c1ptb1h5ubtem@4ax.com...
> My network guys tell me that one of our local machines is sending out
> port scans to a particular host. The "attacking" machine is AIX 5.2.
> I have been tcpdumping for 2 days and have not seen anything
> significant. I installed lsof and nothing is showing up. For clarity
> I installed this and am monitoring on the "attacking" machine. Still
> the port scans exist.
>
> Does anyone know of a tool that will definitively tell me what process
> is causing this?
>
> TIA,
> T.

################################
It sounds like that machine has been rooted so you might want to try a root
kit.
http://rk.cyberabuse.org/

There is another one called rootkit hunter for BSD which is said to run on
AIX as well.
www.rootkit.nl

I haven't tried any of them so I can't comment on their efficiency.
donnie



Reply With Quote
  #3 (permalink)  
Old 10-12-2005, 08:04 PM
Moe Trin
Guest
 
Posts: n/a
Default Re: AIX 5.2 local portscanner?

In the Usenet newsgroup alt.computer.security, in article
<t53pk1l6d8b6ab0gs6845c1ptb1h5ubtem@4ax.com>, Tony Brown wrote:

>My network guys tell me that one of our local machines is sending out
>port scans to a particular host.


Reference point: Do they know *** they are talking about? What ports
source and destination?

>The "attacking" machine is AIX 5.2. I have been tcpdumping for 2 days
>and have not seen anything significant. I installed lsof and nothing
>is showing up.


What is running on the AIX box? Remember that lsof (and similar
tools) only look at a snapshot of what's going on at the moment you
hit the enter key - If the malware is (for example) sleeping at that
moment, you may not see it. 'ps' may be altered, but also try 'top'
and 'pstree'.

>For clarity I installed this and am monitoring on the "attacking"
>machine. Still the port scans exist.


Get a hub and another computer. Connect the hub between the AIX box
and the network, and attach the other computer running any kind of
packet sniffer it can to the hub. Do you see anything?

>Does anyone know of a tool that will definitively tell me what process
>is causing this?


If the box is r00ted, there really isn't that much you can run in
multi-user mode. You simply can't trust anything on the system, and
that includes the kernel and libraries, and everything else. For what
it's worth, I don't think there has been anything on Bugtraq in the
past month.

You might have better luck in 'comp.security.unix' (though it has been
relatively quiet), or 'comp.unix.aix'.

Old guy

Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot get Local Area Connection Ritter197 alt.comp.hardware 5 11-13-2006 11:48 PM
HPSBUX02091 SSRT061099 rev.2 - HP-UX Local Increased Privilege Security Alert comp.security.misc 0 11-01-2006 06:23 PM
HPSBUX02126 SSRT051019 rev.1 - HP-UX running X.25 Local Denial of Service (Dos) Security Alert comp.security.misc 0 09-14-2006 08:50 PM
HPSBUX02151 SSRT051021 rev.1 - HP-UX Running ARPA Transport Software, Local Denial of Service (DoS) Security Alert comp.security.misc 0 09-13-2006 05:40 PM
Security fears over MS October patches... Imhotep alt.computer.security 31 10-23-2005 12:58 AM


All times are GMT. The time now is 10:25 PM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45