Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Ernest_at_the_Beach
It's the SAME ARTICLE!!!!
57 posted on 06/17/2003 9:59:25 PM PDT by adam_az
[ Post Reply | Private Reply | To 55 | View Replies ]


To: adam_az
Yes, it's the site that gives it some credence!
58 posted on 06/17/2003 10:01:04 PM PDT by Ernest_at_the_Beach (Recall Gray Davis and then start on the other Democrats)
[ Post Reply | Private Reply | To 57 | View Replies ]

To: adam_az
Here is a different article:

Is a new Trojan horse at the firewall? -
Government Computer News Website

_________________________________________________________________

Article follows

__________________________________________________



Is a new Trojan horse at the firewall?

By William Jackson
GCN Staff


IT security professionals have found evidence that a stealthy new Trojan horse is infecting networks.

Traffic apparently generated by the as-yet-unnamed malware was first reported in May by a security analyst for a Defense Department contractor, said Chris Hovis, director of product marketing for Lancope Inc. of Atlanta. Lancope announced Monday it had confirmed the behavior of suspicious packets on its own honeynet and on the network of a large university.

The TCP SYN packets are characterized by a window size in the packet header of 55808. No infected machines have been found, but the Trojan horse apparently listens for packets with this value, which Hovis said are believed to contain encrypted instructions for communicating with controllers.

“Based on the activity that we have seen, which looks like probes from zombie hosts, there are likely infected machines that are looking for that identifier,” Hovis said.

Because the code of the Trojan horse itself apparently does not include communication instructions, they are difficult to detect with signature based antivirus software. Lancope has described it as a third generation Trojan horse and said the FBI and the CERT Coordination Center at Carnegie Mellon University had been notified.

CERT would not comment on the report, but said there is nothing significantly different about the threat described by Lancope.

“There is nothing there that hasn’t been seen before,” said Mary Lindner, CERT team leader for incident handling. “Every one of these is an event, but the barometer is not rising.”

Hovis said the Trojan’s purpose is unclear, as is how widely it is distributed. At the current level of activity the suspicious packets could probe all IP addresses on the Internet every 27 hours.

System administrators can use tools such as TCPdump, a program that monitors and filters TCP activity, to find out if machines on their networks are sources of the telltale probes. Systems can also be monitored for aberrant behavior, such as unusual amounts of traffic or new ports and services being opened.





59 posted on 06/17/2003 10:09:47 PM PDT by Ernest_at_the_Beach (Recall Gray Davis and then start on the other Democrats)
[ Post Reply | Private Reply | To 57 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson