Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Cisco 4006 worm

Reply
Thread Tools

Cisco 4006 worm

 
 
Someone
Guest
Posts: n/a
 
      09-16-2006
How can I detect if my Cisco 4006 switch is infected with worm/virus.
Beacuse it is dead slow. Thanks.
 
Reply With Quote
 
 
 
 
Fer Mtz
Guest
Posts: n/a
 
      09-16-2006

Someone wrote:
> How can I detect if my Cisco 4006 switch is infected with worm/virus.
> Beacuse it is dead slow. Thanks.



they dont have worms, worms are in your network, please check CPU and
utilization.
Disconect every cable from your network and put one for one again OR
try to deny some networks and try to figure out wich network is making
so slow the 4006

 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      09-16-2006
In article <>,
Someone <> wrote:
>How can I detect if my Cisco 4006 switch is infected with worm/virus.
>Beacuse it is dead slow. Thanks.


It is quite unlikely that a worm or virus has infected your 4006
itself. I have a vague memory that some group was able to drop
code into a couple of kinds of IOS devices, but that would have been
at least 6 years ago, probably longer, and only applied to a few
devices (different models use different processors), was relatively
easily defended against, and would have been patched long ago.

It is, though, entirely possible that something in your network
has been infected and your network is being flooded with outgoing
attempts to infect other things. You can track that sort of
activity by setting up a syslog server and adding "log" modifiers
to your ACL entries (use permit ip any any log if you want to
permit all traffic through.) Alternately, try enabling "ip accounting";
then "show ip accounting" can show you summaries of where the traffic
is going.

(I'm presuming here that your 4006 has a routing card in it, not just
acting as a true layer 2 switch.)

For really detailed accounting, you -might- be able to enable "netflow",
but you probably don't have a netflow analyzer available, and I suspect
your 4006 doesn't support netflow.
 
Reply With Quote
 
www.BradReese.Com
Guest
Posts: n/a
 
      09-17-2006
On a Catalyst 4006 switch on which you have installed one or more
WS-X4148-RJ45V modules, the typical utilization is higher:

http://www.cisco.com/en/US/products/....shtml#typical

Sincerely,

Brad Reese
Cisco Repair
http://www.bradreese.com/cisco-big-iron-repair.htm

 
Reply With Quote
 
Sam Wilson
Guest
Posts: n/a
 
      09-19-2006
In article <>,
Someone <> wrote:

> How can I detect if my Cisco 4006 switch is infected with worm/virus.
> Beacuse it is dead slow. Thanks.


"show proc cpu" is probably a good start. I don't know if the 4006 runs
IOS but if yours is then try "show proc cpu sort".

Sam
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Experts Warn of Kama Sutra Worm (yet another MS worm) Imhotep Computer Security 4 01-30-2006 01:53 PM
Worm\Spybot (P2P-Worm.Win32.SpyBot.a) Danny Computer Information 0 08-14-2005 01:09 PM
worm/spybot.17.t (worm spybot 17t) detected by AVG code_wrong Computer Security 0 05-15-2004 04:40 PM
Antigen found VIRUS= I-Worm.Sobig.f (Kaspersky,CA(InoculateIT)) worm ANTIGEN_ML-MAIL Ruby 0 09-09-2003 07:11 PM
New anti-blaster worm attempts to fix RPC/DCOM vuln - W32/Nachi.worm Lord Shaolin Computer Security 6 08-20-2003 10:39 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57