From owner-freebsd-security Fri Nov 2 3:42: 5 2001 Delivered-To: freebsd-security@freebsd.org Received: from mohegan.mohawk.net (mohegan.mohawk.net [63.66.68.21]) by hub.freebsd.org (Postfix) with ESMTP id 17ED437B401 for ; Fri, 2 Nov 2001 03:42:03 -0800 (PST) Received: from mohegan.mohawk.net (mohegan.mohawk.net [63.66.68.21]) by mohegan.mohawk.net (8.11.4/8.11.3) with ESMTP id fA2BfuW20295; Fri, 2 Nov 2001 06:41:56 -0500 (EST) Date: Fri, 2 Nov 2001 06:41:56 -0500 (EST) From: Ralph Huntington To: Rasputin Cc: Subject: Re: SubSeven trojan horse In-Reply-To: <20011102113110.A81496@shikima.mine.nu> Message-ID: <20011102063909.T92627-100000@mohegan.mohawk.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org > > One of our FreeBSD 4.2-RELEASE machines is accused by mynetwatchman.com of > > launching a SubSeven trogan horse attach. However, I do not find anything > > odd about this machine. > > > > Is this even possible? I thought subseven was a Windows thing. Can it be > > launched from bsd? Thanks. - Ralph > > Do you proxy for any windows boxes? If so, check your logs. If not, > one ofthe users on the box may be playing with nessus or a > portscanner, or just telnetting out on the right port to trigger > firewalls. No proxy service, no users even! Perhaps the real attacker spoofed one of our addresses. Thanks. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message