From owner-freebsd-security Fri Nov 2 4:53:50 2001 Delivered-To: freebsd-security@freebsd.org Received: from mohegan.mohawk.net (mohegan.mohawk.net [63.66.68.21]) by hub.freebsd.org (Postfix) with ESMTP id E40FE37B401 for ; Fri, 2 Nov 2001 04:53:47 -0800 (PST) Received: from mohegan.mohawk.net (mohegan.mohawk.net [63.66.68.21]) by mohegan.mohawk.net (8.11.4/8.11.3) with ESMTP id fA2CrbW22481; Fri, 2 Nov 2001 07:53:37 -0500 (EST) Date: Fri, 2 Nov 2001 07:53:37 -0500 (EST) From: Ralph Huntington To: Krzysztof Zaraska Cc: Subject: Re: SubSeven trojan horse In-Reply-To: Message-ID: <20011102075147.L92627-100000@mohegan.mohawk.net> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org > > One of our FreeBSD 4.2-RELEASE machines is accused by mynetwatchman.com of > > launching a SubSeven trogan horse attach. However, I do not find anything > > odd about this machine. > > > > Is this even possible? I thought subseven was a Windows thing. Can it be > > launched from bsd? Thanks. - Ralph > > It's unclear what they mean by launching an attack. I think they meant a port probe. > I never researched this subject, but AFAIK Windoze trojans are > client/server programs with server running on victim's machine. Client > software is used by attacker to control victim's machine by sending > requests to server. So the existence of SubSeven client for BSD cannot > be ruled out (I guess such code is easily portable -- all you need are > BSD sockets; for example there's BackOrifice client in /usr/ports and > this is almost the same). So someone could compromise your machine and > run SubSeven client from there connecting to some windoze box. > Unfortunately, I guess, the client may even run without root > priviledges. Interresting. One ouwld be able to see the client running if that were the case, yes? > As of spoofed attack... IIRC, BackOrifice used UDP, SubSeven may do so > also, so sending spoofing requests should be possible. But a probe could be spoofed, could it not? To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message