Solved

Blaster Honeypot

Posted on 2004-08-25
9
310 Views
Last Modified: 2013-12-04
Hi Guys

Does anyone know of a program similar to NetBususter but for Blaster?

I want a program to listen on the port that blaster communicates with and alert me when an infected machine tries to connect, along with the IP address of the machine?

Many thanks
0
Comment
Question by:stewatts
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 11894077
This can be done with a cisco firewall, IDS system, or even McAfee Anti-Virus... what type of notification do you want? Email, NetSend message, text page to your phone...
-rich
0
 

Author Comment

by:stewatts
ID: 11894129
Hi Rich

I don't have access to any of these products. Do you know of anything that I can download similar to netbuster for netbus?

Thanks for your help
0
 
LVL 8

Expert Comment

by:RevelationCS
ID: 11895674
download zonealarm from zonelabs.. They have a free version and that should alert you when that port has activity (if you set the firewall rule up correctly)...
0
 

Author Comment

by:stewatts
ID: 11900141
I may have to resort to this but I am on a corporate network so this isn't ideal.

Ideally what I need is a standalone program that I can just have sat listening to traffic and alerting me to Blaster traffic.

Thanks guys
0
Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

 
LVL 38

Accepted Solution

by:
Rich Rumble earned 125 total points
ID: 11902273
Snort IDS, free, works on m$ and linux, listens for anything that you define in the rules... but requires effort to setup- so it's not as easy as netbuster... but 10000 times more robust, and can listen for any number of viri... I'm sorry, I can't get enough of this product- and it's also loved the whole world over
www.snort.org
-rich
0
 
LVL 8

Expert Comment

by:RevelationCS
ID: 11902789
do you have a firewall on your corporate network itself? if so, just block the ports that blaster uses to communicate.... This should prevent the virus from getting into your network anyhow. Also, your IT department needs to make sure they have the latest security patches by MS... if you do these, you shouldn't have to worry about the existing versions of Blaster (or variants) out there...
0
 

Author Comment

by:stewatts
ID: 11902919
That's the problem. I AM the IT support.

I have just started and it's a bit of a mess. No central AV, multiple sites with various perm none perm network connections etc.

I know we have blaster on some machines but they are hard to find as they get switched on and off so I am looking for something that will sit and tell me when it detects an attempted infection.

I thought of SNORT/other firewalls but it's a hammer to walnut solution really. I will just have to go with this if nobody knows of another tool

Thanks guys
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 11903182
I know of scanners... but they are HD scanners... what you may be able to do is use a logon script to scan peoples HD's for blaster, or others... it's easy to script McAfee's Stinger tool, and it finds about the 50 of the latest viri and thier variants... and cleans them. I'd make a netlogon script (.bat file) that says the following...


@echo off
Rem don't show output
copy Stinger.exe %userprofile%/desktop
sleep 3
Rem wait 3 seconds, then scan local HD's
%userprofile%/desktop/Stinger.exe /ADL /GO /LOG /SILENT
end

All you have to do is get stinger: http://vil.nai.com/vil/stinger/
Place it in the Netlogon directory on your domain controllers... when a user signs in, if they have the netlogon check mark on their account, the file should copy to their desktop, then run and log anything it finds (locally:( - then the next week, remove the script- and write one that will tell you who had the virus from the log file.
-rich
0
 
LVL 1

Expert Comment

by:Alien3
ID: 11926401
the old machine with default install of windows 2000/XP  but put files watch, registry watcher and packet sniffer that logs.
etheral sniffer is best packet sniffer.  





0

Featured Post

New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Was laptop hacked? 11 91
Windows Master Password 11 54
Bombarded with 45000+ event ID from the same computer ? 10 71
Monitoring software... 2 52
In today's information driven age, entrepreneurs have so many great tools and options at their disposal to help turn good ideas into a thriving business. With cloud-based online services, such as Amazon's Web Services (AWS) or Microsoft's Azure, bus…
This is a guide to the following problem (not exclusive but here) on Windows: Users need our support and we supporters often use global administrative accounts to do this. Using these accounts safely is a real challenge. Any admin who takes se…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now