Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Bait Server for Trojan

Reply
Thread Tools Display Modes

Bait Server for Trojan

 
 
Brock Hensley
Guest
Posts: n/a

 
      05-28-2009
Hello,

I'm looking for any recommendations on how to track down the cause of a
Trojan infection.

We have a number of reports of the following infection on various servers.
The only common link we can find between all the infected servers is that
they do not have Windows Firewall enabled, which is how I assume they are
compromising the system in the first place and installing the FTP server
which is then detectable.

================
Troj/ServU-Gen (Sophos)
Aliases:
not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
Hacktool (Symantec)
BackDoor.Servu.5000 (Doctor Web)
Troj/ServU-Gen (Sophos)
BDS/ServU.ba.1 (H+BEDV)
Win32:Trojano-356 (ALWIL)
Trojan.ServU.G (SOFTWIN)
Trojan.Servu.1 (ClamAV)
Bck/ServU.BB (Panda)
Server-FTP.Win32.Serv-U
================

I'm trying to think of the best way to set up a "Bait" server with security
auditing & no Firewall to sniff the infection process.

WireShark?

Once the server is infected, it creates "DependOnService" registry entries
on a few services which causes File & Printer Sharing to not work as well as
a few other detectable things.

Any help would be appreciated!
-B

 
Reply With Quote
 
 
 
 
Dave
Guest
Posts: n/a

 
      05-28-2009
the cause is: you are not secure enough

the fix is: get more secure!

leave the analysis to the pros, get your security fixed so you aren't a
vector for transmitting future infections.

"Brock Hensley" <> wrote in message
news:7CA31DC4-2C35-428E-8509-...
> Hello,
>
> I'm looking for any recommendations on how to track down the cause of a
> Trojan infection.
>
> We have a number of reports of the following infection on various servers.
> The only common link we can find between all the infected servers is that
> they do not have Windows Firewall enabled, which is how I assume they are
> compromising the system in the first place and installing the FTP server
> which is then detectable.
>
> ================
> Troj/ServU-Gen (Sophos)
> Aliases:
> not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
> not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
> Hacktool (Symantec)
> BackDoor.Servu.5000 (Doctor Web)
> Troj/ServU-Gen (Sophos)
> BDS/ServU.ba.1 (H+BEDV)
> Win32:Trojano-356 (ALWIL)
> Trojan.ServU.G (SOFTWIN)
> Trojan.Servu.1 (ClamAV)
> Bck/ServU.BB (Panda)
> Server-FTP.Win32.Serv-U
> ================
>
> I'm trying to think of the best way to set up a "Bait" server with
> security auditing & no Firewall to sniff the infection process.
>
> WireShark?
>
> Once the server is infected, it creates "DependOnService" registry entries
> on a few services which causes File & Printer Sharing to not work as well
> as a few other detectable things.
>
> Any help would be appreciated!
> -B
>


 
Reply With Quote
 
Milo
Guest
Posts: n/a

 
      05-30-2009
HI Broc.

First of all you need a sandbox system ( infect possible due to
vulnerability machine in your test segment )... then you need to monitor
ports ( all open ) and forward file samples to such area and it should
simulate the actual attack then and only then you can understand the threat
vector.

you can reach me here... for a much detail explanation.

"Brock Hensley" <> wrote in message
news:7CA31DC4-2C35-428E-8509-...
> Hello,
>
> I'm looking for any recommendations on how to track down the cause of a
> Trojan infection.
>
> We have a number of reports of the following infection on various servers.
> The only common link we can find between all the infected servers is that
> they do not have Windows Firewall enabled, which is how I assume they are
> compromising the system in the first place and installing the FTP server
> which is then detectable.
>
> ================
> Troj/ServU-Gen (Sophos)
> Aliases:
> not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
> not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
> Hacktool (Symantec)
> BackDoor.Servu.5000 (Doctor Web)
> Troj/ServU-Gen (Sophos)
> BDS/ServU.ba.1 (H+BEDV)
> Win32:Trojano-356 (ALWIL)
> Trojan.ServU.G (SOFTWIN)
> Trojan.Servu.1 (ClamAV)
> Bck/ServU.BB (Panda)
> Server-FTP.Win32.Serv-U
> ================
>
> I'm trying to think of the best way to set up a "Bait" server with
> security auditing & no Firewall to sniff the infection process.
>
> WireShark?
>
> Once the server is infected, it creates "DependOnService" registry entries
> on a few services which causes File & Printer Sharing to not work as well
> as a few other detectable things.
>
> Any help would be appreciated!
> -B
>

 
Reply With Quote
 
Cody E
Guest
Posts: n/a

 
      06-10-2009
The best thing you could do other than setting up a sandbox or a honeypot is
to setup snort and configure its rules. If you dont know how to do this, I
would most definately do research on it or hire one or more sec consultants
to do it for you.

"Brock Hensley" <> wrote in message
news:7CA31DC4-2C35-428E-8509-...
> Hello,
>
> I'm looking for any recommendations on how to track down the cause of a
> Trojan infection.
>
> We have a number of reports of the following infection on various servers.
> The only common link we can find between all the infected servers is that
> they do not have Windows Firewall enabled, which is how I assume they are
> compromising the system in the first place and installing the FTP server
> which is then detectable.
>
> ================
> Troj/ServU-Gen (Sophos)
> Aliases:
> not-a-virus:Server-FTP.Win32.Serv-U.5000 (Kaspersky Lab)
> not-a-virus:RiskWare.FTP.Serv-U.5000 (Kaspersky Lab)
> Hacktool (Symantec)
> BackDoor.Servu.5000 (Doctor Web)
> Troj/ServU-Gen (Sophos)
> BDS/ServU.ba.1 (H+BEDV)
> Win32:Trojano-356 (ALWIL)
> Trojan.ServU.G (SOFTWIN)
> Trojan.Servu.1 (ClamAV)
> Bck/ServU.BB (Panda)
> Server-FTP.Win32.Serv-U
> ================
>
> I'm trying to think of the best way to set up a "Bait" server with
> security auditing & no Firewall to sniff the infection process.
>
> WireShark?
>
> Once the server is infected, it creates "DependOnService" registry entries
> on a few services which causes File & Printer Sharing to not work as well
> as a few other detectable things.
>
> Any help would be appreciated!
> -B
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Shark Bait Ooh Ah Ah!!! markritter150 Windows Vista General Discussion 3 06-10-2008 12:59 AM
File Server Mgr does not match PC. Trojan? DS Windows Server 2 01-15-2008 11:56 AM
Did Microsoft engage in "bait and switch" Bill Windows Vista General Discussion 21 04-05-2007 06:24 PM
trojan shoppingrocks5 Windows Update 1 11-08-2004 11:41 AM
a trojan? Lauren Windows Media Player 1 04-13-2004 12:31 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59