Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > Swatch-Like Trojan Parser for Syslog

Reply
Thread Tools

Swatch-Like Trojan Parser for Syslog

 
 
Dotman
Guest
Posts: n/a
 
      12-14-2003
Does anyone know of a script that will search syslog for potential
Trojan infected hosts? A site I helped to cleaned up was extremely infected
..
Now I suspect some lingering programs. How is syslog checked for
common trojan ports? Is there a swatch-like utility out there?
Thanks


 
Reply With Quote
 
 
 
 
Colonel Flagg
Guest
Posts: n/a
 
      12-14-2003
In article <lh2Db.145661$ >,
says...
> Does anyone know of a script that will search syslog for potential
> Trojan infected hosts? A site I helped to cleaned up was extremely infected
> .
> Now I suspect some lingering programs. How is syslog checked for
> common trojan ports? Is there a swatch-like utility out there?
> Thanks
>
>
>



If the host was infected, there's no sure-fire-way to determine if *all*
files are safe. Your only hope is to backup your data/config files and
reinstall from scratch. Probably your best option would be to replace
the harddrive and use a new one, installing everything from scratch.
Apply all patches prior to turning any daemons on.

Cert has a nice "how to", for once you've been compromised.

--
Colonel Flagg
http://www.internetwarzone.org/

Privacy at a click:
http://www.cotse.net

Q: How many Bill Gates does it take to change a lightbulb?
A: None, he just defines Darkness? as the new industry standard..."

"...I see stupid people."
 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      12-14-2003
There are many CERTs but I think that this is the one referred to.

http://www.cert.org/

Dave



"Colonel Flagg" <> wrote in message
news:.. .
| In article <lh2Db.145661$ >,
| says...
| > Does anyone know of a script that will search syslog for potential
| > Trojan infected hosts? A site I helped to cleaned up was extremely infected
| > .
| > Now I suspect some lingering programs. How is syslog checked for
| > common trojan ports? Is there a swatch-like utility out there?
| > Thanks
| >
| >
| >
|
|
| If the host was infected, there's no sure-fire-way to determine if *all*
| files are safe. Your only hope is to backup your data/config files and
| reinstall from scratch. Probably your best option would be to replace
| the harddrive and use a new one, installing everything from scratch.
| Apply all patches prior to turning any daemons on.
|
| Cert has a nice "how to", for once you've been compromised.
|
| --
| Colonel Flagg
| http://www.internetwarzone.org/
|
| Privacy at a click:
| http://www.cotse.net
|
| Q: How many Bill Gates does it take to change a lightbulb?
| A: None, he just defines Darkness? as the new industry standard..."
|
| "...I see stupid people."


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
perl 5.8.8 make test hangs on ext/Sys/Syslog/t/syslog................... indefinitely Bad Dog Perl Misc 0 08-09-2007 04:47 PM
is there any API available to implement Syslog server using Java (to capture all syslog messages - UDP protocol, port 514)? santa19992000@yahoo.com Java 2 06-20-2006 12:54 PM
"Win32:Trojan-gen. {VC}" "Win32:Trojan-gen. {UPX!}" D@Z Computer Support 5 01-30-2006 07:52 PM
New trojan spam tells you where to download trojan as "MS beta antispy" Joel Rubin Computer Support 2 03-07-2005 02:26 AM
Syslog replay script for centralized syslog host leroy isaac Perl Misc 1 10-29-2004 04:23 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57