Netbus and Subseven Scans on my isp
Results 1 to 7 of 7

Thread: Netbus and Subseven Scans on my isp

  1. #1
    Registered User electroservice's Avatar
    Join Date
    Jun 2001
    Location
    Lexington, KY
    Posts
    10

    Angry Netbus and Subseven Scans on my isp

    I recently installed a firewall and I am having great floods of scanners probing for netbus and subseven trojans. I have scanned my system with Mcafee, Nortons (enterprise), and Trend and show no trojans (or virus) on my machine. However I have caught windows explorer sending out on an undifined port. Does anyone know how to track this thing down? I have replaced the explorer.exe file but the scans still keep hitting me! <IMG SRC="smilies/eek.gif" border="0">

  2. #2
    Registered User
    Join Date
    Nov 2000
    Location
    Green Bay, WI USA
    Posts
    654

    Post

    check out http://grc.com/dos/intro.htm an indepth look at bots/zombies and subseven and the experience first hand of how to eliminate or at least curb the problem.
    Comedy is simply a funny way of being serious.
    Peter Ustinov

  3. #3
    Registered User
    Join Date
    Aug 2000
    Location
    Lake Orion, MI
    Posts
    241

    Post

    You probably don't have either one on your system. The probes are just script kiddies trying to find people that do.

    If you eep your virus defs up to date and firewall up to date you should be fine.
    -- I still do not understand the rampant growth of stupidity in this country.
    <a href="http://www.tabletop-battlezone.com" target="_blank">The TableTop BattleZone</a>

  4. #4
    Registered User
    Join Date
    Sep 2000
    Posts
    503

    Post

    open a command prompt and type:
    netstat -a

    This will show you which ports have connections on them and which ports are listening for connections.

  5. #5
    Registered User Cygnus's Avatar
    Join Date
    May 2001
    Location
    Boca Raton, FL
    Posts
    491

    Post

    I have had the same problem on two of the networks we support and both times it turned out to be nothing more than probes that got caught by the system anyway. Unless I read your post wrong I think your ok.
    I dont feel tardy...

  6. #6
    Registered User kingtbone's Avatar
    Join Date
    May 2001
    Location
    Freddy Beach
    Posts
    794

    Post

    Originally posted by Silverman:
    <STRONG>check out http://grc.com/dos/intro.htm an indepth look at bots/zombies and subseven and the experience first hand of how to eliminate or at least curb the problem.</STRONG>
    I suggest that everyone read this. Aside from being very informative, it was actually quite interesting. He suggests that you run ZoneAlarm. This is what he suggests to do

    All of the IRC Zombie/Bots open and maintain static connections to remote IRC chat servers whenever the host PC is connected to the Internet. Although it is possible for an IRC chat server to be configured to run on a port other than "6667", every instance I have seen has used the IRC default port of "6667".

    Consequently, an active connection to an IRC server can be detected with the following command:


    netstat -an | find ":6667"


    Open an MS-DOS Prompt window and type the command line above, then press the "Enter" key. If a line resembling the one shown below is NOT displayed, your computer does not have an open connection to an IRC server running on the standard IRC port. If, however, you see something like this:


    TCP 192.168.1.101:1026 70.13.215.89:6667 ESTABLISHED


    . . . then the only question remaining is how quickly you can disconnect your PC from the Internet!
    A second and equally useful test can also be performed. Since IRC servers generally require the presence of an "Ident" server on the client machine, IRC clients almost always include a local "Ident server" to keep the remote IRC server happy. Every one of the Zombie/Bots I have examined does this. Therefore, the detection of an Ident server running in your machine would be another good cause for alarm. To quickly check for an Ident server, type the following command at an MS-DOS Prompt:


    netstat -an | find ":113 "


    As before, a blank line indicates that there is no Ident server running on the default Ident port of "113". (Note the "space" after the 113 and before the closing double-quote.) If, however, you see something like this:


    TCP 0.0.0.0:113 0.0.0.0:0 LISTENING


    . . . then it's probably time to pull the plug on your cable-modem!
    Hard work often pays off in the long run, but Lazyness always pays off now.

  7. #7
    Registered User
    Join Date
    Nov 2000
    Location
    Green Bay, WI USA
    Posts
    654

    Post

    Zonealarm is quite good at filtering out everything coming into your system or even trying to get out. GRC's probes can not detect you are online. And his are super sleuths.
    Comedy is simply a funny way of being serious.
    Peter Ustinov

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •