Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 11-11-2004, 02:57 PM   #1 (permalink)
Sultana ruined my evil persona
 
Krycheck's Avatar
 
Location: Los Angeles
DoS attack from my network

In the last few days we've been having slow connection problems with our dsl here at work. Slow loading pages if they load at all. Called Verizon and they said that we had too much traffic comming out and hardly any goin in. So to make a long story short I have at least one machine infect with a Blaster like virus. At the moment I have half of the machines offline and those online work fine atm.
How can I find out which one is infected without having to install AV on each one? I know we should have AV protection on every machine but they have either expired or just never had any. And my company is too much of a tightwad to pay for 20 licences.
A friend suggested a network packet anylizer but I can't find what I need.

Suggestions are appriciated.
__________________

His pants are tight...but his morals are loose!!
Krycheck is offline  
Old 11-11-2004, 03:52 PM   #2 (permalink)
Tilted
 
Location: Indianapolis
I assume you have a switch? Does ot have per-port counters? Clear the counters and watch the packet counters. The one going up too fast is the bad boy.

It helps if no one is downloading porn while you are watching the counters.
__________________
From the day of his birth Gilgamesh was called by name.
gcbrowni is offline  
Old 11-11-2004, 03:58 PM   #3 (permalink)
Über-Rookie
 
Location: No longer, D.C
If it is all on your network you could take one machine with which you have administrator access that lies between the internet and your internal network. Run ethereal on the machine and you should be able to find the culprit(s).

it will scan any packet that is going on the wire that can be seen by that machine, whether it is addressed for it or not. There are windows and *nix versions as well.
oblar is offline  
Old 11-11-2004, 07:22 PM   #4 (permalink)
Crazy
 
Location: here and there
http://www.clamwin.com/

opensource windows av. simple, unobtrusive and free, can be set up to email IT when it gets a virus, sounds like just what you are looking for. set it up to scan every night, integrates with Outlook, great av solution.
__________________
# chmod 111 /bin/Laden
theFez is offline  
Old 11-11-2004, 09:27 PM   #5 (permalink)
Sultana ruined my evil persona
 
Krycheck's Avatar
 
Location: Los Angeles
Well I managed to narrow it down to 3 machines. Basicly I went around looking at each machines connection status. Found two with about 300-500kb of outgoing traffic with nothing running. The other didn't have an icon in systray (didn't have the admin rights atm to bring it up) but it had lots of activity at the hub with nothing running. I disabled those three and left three others dissconnected at the hub till I can get to them. Network seems to be at about 90% as far as being usable.

Two of the machines are XP and the other Win2k. I'm the sudo-admin around there, it's not my full time position to keep them all up to date. But this fiasco too up my whole day. I'm still gonna work on this with your guys suggestions. Any way to monitor the whole network without using a computer as a pass-thru?
__________________

His pants are tight...but his morals are loose!!
Krycheck is offline  
Old 11-11-2004, 10:18 PM   #6 (permalink)
Crazy
 
Location: here and there
only if you can figure a way to install a packet sniffer on a router.

you could also get a linux box set up and install nagios http://www.nagios.org/ and snort http://www.snort.org/about.html

if you set the linux box up as a firewall between your hub and your internet you should be able to do quite a good job with these two applications.

I do recommend the clamwin on each computer in the network.
__________________
# chmod 111 /bin/Laden

Last edited by theFez; 11-11-2004 at 10:32 PM..
theFez is offline  
Old 11-12-2004, 11:07 AM   #7 (permalink)
Addict
 
Free:
http://us.mcafee.com/root/mfs/default.asp?cid=9914

Trend micro also does a free 'house call' applet that runs from their website.

You can also download the free 'stinger' tool here to remove various threats:
http://us.mcafee.com/virusInfo/default.asp?id=vrt
Run it on all suspected pc's.
WillyPete is offline  
Old 11-13-2004, 01:16 PM   #8 (permalink)
Hello, good evening, and bollocks.
 
Fearless_Hyena's Avatar
 
Location: near DC
also try http://housecall.trendmicro.com for free, online antivirus
Fearless_Hyena is offline  
Old 11-15-2004, 11:15 AM   #9 (permalink)
I flopped the nutz...
 
mikec's Avatar
 
Location: Stratford, CT
hehe, yeah not to mention the free opportunities, you should instruct your superiors at the company who are too tightwad to purchase anti-virus, that the damage a virus can and will eventually cause will exceed exponentially the cost of the licensing for keeping current virus definitions. ridiculous!!!
__________________
Until the 20th century, reality was everything humans could touch, smell, see, and hear. Since the initial publication of the charted electromagnetic spectrum, humans have learned that what they can touch, smell, see, and hear is less than one millionth of reality
mikec is offline  
Old 11-15-2004, 04:11 PM   #10 (permalink)
Psycho
 
jonjon42's Avatar
 
Location: inside my own mind
I suggest clamav...I think that it's wonderful..I suggest you get an old box...even a 486 would do and set up to route traffic. Use iptables as your firewall if you can't write your own firewall script I have a rather good one that blocks some of the more obvious trojans...running snort or some other packetsniffer would be a good idea too.
__________________
A damn dirty hippie without the dirty part....
jonjon42 is offline  
Old 11-15-2004, 05:17 PM   #11 (permalink)
Tilted
 
Location: Salt Lake City
"Any way to monitor the whole network without using a computer as a pass-thru?"

One suggestion was to place a sniffer on the router. Good suggestion but it's not necessary.

Assuming you're in a switched environment all switches (the ones I'm familiar with anyway) have the capability allowing you to forward all traffic to one port for just this purpose (it's called a mirrored port).

Once you've forwarded all the traffic to the one port you can then collect the data and open it in whatever protocol analyzer software you choose and see which workstation is chattering away. It's actually pretty easy providing you know what to look for.

You mentioned that it's a "Blaster like virus." Do you know if the virus is Blaster? If it's Welchia you're never gonna get rid of the damn thing unless you shutdown ICMP.

Last edited by belkins; 11-15-2004 at 05:23 PM..
belkins is offline  
 

Tags
attack, dos, network


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 12:11 PM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360