Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Incidents
[Top] [All Lists]

Odd identd behavior

Subject: Odd identd behavior
Date: Thu, 10 Nov 2005 17:39:50 -0800
While going through logs, and looking at mail server ident daemonreplies that 
don't fit the RFC-1413 standard, I noticed the followingstring from a few 
servers:
"220 ..:: €lit€-Cr€w Rulez ::..."
Looks to me like this group has been compromising mail servers, andthen instead 
of taking them down, lets them continue running, althoughwith a slight 
modification. They probably siphon off a copy of allemail transiting their 
servers as well, although without access to anyof these servers, I can't tell.
Interesting to note, if you send 2 ident requests, the second one comes back as:
"220 ..:: €lit€-Cr€w Rulez ::....530 Not logged in..."
This leads me to believe this is the backdoor into these mail servers,after 
all, if you're trying to hide a backdoor from port scans, ordealing with 
stringent firewall rules, subverting an existinglistening process is a smart 
way to do it.
I have not notified the 0wned sites, mostly because I'm not reallysure what to 
do there. I can't email them, which means I have toattempt to find a contact, 
and then call them. Then of course, theperson I manage to get a hold of needs 
to understand what I'm tryingto say, and I have to hope they don't then try and 
email someonetelling them that they have been compromised, thereby letting 
theattackers know.
I'm curious as to whether anyone else has seen ident replies like this.
Thanks,Mike

<Prev in Thread] Current Thread [Next in Thread>