Re: virus/worms killing a network...

From: Alexander Dalloz (alexander.dalloz_at_uni-bielefeld.de)
Date: 07/31/04

  • Next message: Dexter Ang: "Re: virus/worms killing a network..."
    Date: Sat, 31 Jul 2004 20:25:51 +0200
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    
    
    

    Am Sa, den 31.07.2004 schrieb Cristiano Soares um 20:08:

    > I have a FC2 server that has two NICs. The first one is connect to my ADSL router, and the other
    > one is connected to a network that receive IPs from that server through DHCPD service, and then
    > the FC2 do the firewall/masquerade. All the 30 machines can browse nice until 2 or maybe more
    > machines that has virus/worms get online. Ive seeing that W32.MsBlast is the cause of most of
    > these link down problems, but now, it looks to be more than just w32.msblast. My queston is: IS
    > THAT POSSIBLE TO INSTALL A SOFTWARE OR SOMETHING LIKE THAT IN THE FC2
    > SERVER TO PREVENT OR AT LEAST TO DETECT (by IP number) THE MACHINES THAT
    > HAS THE VIRUS, SO IT DOENST KILL MY CONNECTION. Thanks in advance.

    > Cristiano

    Install an anti-virus tool on each of the Windows[tm] machines to
    desinfect them and protect them for the future. Install all available
    updates from the MS update site.

    If you want to find out the bad hosts from you Linux host you certainly
    will have to check which ports these worms use and then run a portscan
    against all of the hosts, using nmap. You can too switch on each
    Windows[tm] machine one by one and observe the traffic on the NAT
    machine to see whether the single running Win machine tries to
    "telephone" with other machines. It would be very helpful too to know
    the ports the worm uses.

    In general configure your NAT server properly with a good firewalling
    setup! This will not protect against all kind of worms because many
    install through Windows[tm] misdesign, security bugs or simply by mail.
    Let none of the Windows[tm] hosts run with administrator privileges!

    Alexander

    P.S. Please don't post html formatted mail to the list, just plain text
    mail. Don't shout out. We all understand your question without the need
    to cry (capital letter sentences).

    -- 
    Alexander Dalloz | Enger, Germany | GPG key 1024D/ED695653 1999-07-13
    Fedora GNU/Linux Core 2 (Tettnang) kernel 2.6.6-1.435.2.3.ad.umlsmp 
    Serendipity 20:17:18 up 1:42, 8 users, 0.02, 0.08, 0.15 
    
    

    
    

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    


  • Next message: Dexter Ang: "Re: virus/worms killing a network..."

    Relevant Pages

    • Re: network slows down after SP2 install
      ... the machines updated from W2K still open and read the ... Locate the "Microsoft network server: ... Install SP2 for WIN XP and latest service pack for Office 2003 on ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • Re: network slows down after SP2 install
      ... These machines cannot even run the program locally being disconnected from the server with a local copy of the database. ... Install SP2 for WIN XP and latest service pack for Office 2003 on ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • Re: Exchange on VMWare
      ... I have found in the past that installing exchange on the dc then removing it ... Check to be sure that your virtual member server is also using your vm dc ... resources outside of my vm machines, I just want this member server ... However when i install exchange on the member server it cannot find the ...
      (microsoft.public.exchange.setup)
    • Re: Server 2008 NAT and VM adapters
      ... What we got: Windows Server 2008 Enterprise. ... Core) of Enterprise as the host machine to fool around (I later wiped ... The drivers for the synthetic NICs are loaded when you install the integration components. ... It is only sensible if you want to isolate the machines on the virtual network from the LAN machines. ...
      (microsoft.public.windows.server.networking)
    • Re: network slows down after SP2 install
      ... duo xp pro machines are the slower ones. ... terminal services as well on this server which is the domain controller. ... It is also odd that the physical network now cannot run ... machines with the SP2 install that prohibits running the program either ...
      (microsoft.public.windows.server.sbs)