myNetWatchman   KnowledgeBase

Pooling knowledge to
secure the internet.


mNW Reports  FAQ: mNW Reports





(Registered Users Only)


Look Up Incidents by IP Address

 

 

Security Research Activities:

Date Document Description
2002-11-23 AOL Client circumvents firewall AOL Client tunnels through firewalls and NAT routers, exposing the internal network to attacks
2002-10-13 Messenger Pop-up SPAM Totally new SPAM delivery mechanims, sends popups using Windows Administration Message service
2002-09-05 Pubstro Forensics Warez Pirates repurpose your server and bandwidth
2002-05-20 Newbiero Worm Microsoft-based DDoS worm propagating through open file shares
2002-04-26 FTP file transfer fails Client behind a firewall can't FTP a file
2002-04-23 FTP Worm? Automated FTP script looking for open servers
2002-03-31 Immortal Worms Why Nimda/Code Red worms will never die
2002-03-15 LsysDDoS How SNMP-capable Linksys routers can be used as DDoS Zombies
2002-03-07 BackScat How ISPs trace the source of Spoofed DoS attacks
2001-04-10 IPIP Probe? A probe targetting IP Protocol 94
(IP-within-IP Encapsulation Protocol)
2001-02-22 New Netbus Worm? Seeing lots of Netbus probes mostly sourcing from Korea...volume seems too high to be individual Netbus users and scan pattern is sophisticated (very random and slow scanning)
2000-09-01 Qaz Worm Worm that demonstrates what I believe is one of the most serious Internet vulnerabilites: Unprotected Microsoft Windows file shares

Tools/Links/Guides:

Document Description
Idiot's Guide to Packet Analysis How to setup a packet analyzer on your Internet connection...key for troublshooting and security forensics
Guide to reporting Port Scans What/when and how to report port scans your firewall logs
Microsoft Hfnetchk Use this to verify that all your security patches are up to date.
Fport Win NT/2K ONLY! utility to map open ports to application...critical for rootkit detection
StartupList Get a complete inventory of what programs are being auto-started on your system...very helpful in finding where hostile programs are being launched.
Linux Rootkit detection Guide and links to detecting Linux Rootkits

myNetWatchman Home