Solved

Blaster Honeypot

Posted on 2004-08-25
9
316 Views
Last Modified: 2013-12-04
Hi Guys

Does anyone know of a program similar to NetBususter but for Blaster?

I want a program to listen on the port that blaster communicates with and alert me when an infected machine tries to connect, along with the IP address of the machine?

Many thanks
0
Comment
Question by:stewatts
  • 3
  • 3
  • 2
  • +1
9 Comments
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 11894077
This can be done with a cisco firewall, IDS system, or even McAfee Anti-Virus... what type of notification do you want? Email, NetSend message, text page to your phone...
-rich
0
 

Author Comment

by:stewatts
ID: 11894129
Hi Rich

I don't have access to any of these products. Do you know of anything that I can download similar to netbuster for netbus?

Thanks for your help
0
 
LVL 8

Expert Comment

by:RevelationCS
ID: 11895674
download zonealarm from zonelabs.. They have a free version and that should alert you when that port has activity (if you set the firewall rule up correctly)...
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 

Author Comment

by:stewatts
ID: 11900141
I may have to resort to this but I am on a corporate network so this isn't ideal.

Ideally what I need is a standalone program that I can just have sat listening to traffic and alerting me to Blaster traffic.

Thanks guys
0
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 125 total points
ID: 11902273
Snort IDS, free, works on m$ and linux, listens for anything that you define in the rules... but requires effort to setup- so it's not as easy as netbuster... but 10000 times more robust, and can listen for any number of viri... I'm sorry, I can't get enough of this product- and it's also loved the whole world over
www.snort.org
-rich
0
 
LVL 8

Expert Comment

by:RevelationCS
ID: 11902789
do you have a firewall on your corporate network itself? if so, just block the ports that blaster uses to communicate.... This should prevent the virus from getting into your network anyhow. Also, your IT department needs to make sure they have the latest security patches by MS... if you do these, you shouldn't have to worry about the existing versions of Blaster (or variants) out there...
0
 

Author Comment

by:stewatts
ID: 11902919
That's the problem. I AM the IT support.

I have just started and it's a bit of a mess. No central AV, multiple sites with various perm none perm network connections etc.

I know we have blaster on some machines but they are hard to find as they get switched on and off so I am looking for something that will sit and tell me when it detects an attempted infection.

I thought of SNORT/other firewalls but it's a hammer to walnut solution really. I will just have to go with this if nobody knows of another tool

Thanks guys
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 11903182
I know of scanners... but they are HD scanners... what you may be able to do is use a logon script to scan peoples HD's for blaster, or others... it's easy to script McAfee's Stinger tool, and it finds about the 50 of the latest viri and thier variants... and cleans them. I'd make a netlogon script (.bat file) that says the following...


@echo off
Rem don't show output
copy Stinger.exe %userprofile%/desktop
sleep 3
Rem wait 3 seconds, then scan local HD's
%userprofile%/desktop/Stinger.exe /ADL /GO /LOG /SILENT
end

All you have to do is get stinger: http://vil.nai.com/vil/stinger/
Place it in the Netlogon directory on your domain controllers... when a user signs in, if they have the netlogon check mark on their account, the file should copy to their desktop, then run and log anything it finds (locally:( - then the next week, remove the script- and write one that will tell you who had the virus from the log file.
-rich
0
 
LVL 1

Expert Comment

by:Alien3
ID: 11926401
the old machine with default install of windows 2000/XP  but put files watch, registry watcher and packet sniffer that logs.
etheral sniffer is best packet sniffer.  





0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
4 Android flaws that leave 900M devices at Risk 7 74
Low-cost /freeware IOC tools 4 62
Read-only access for auditors 5 76
Should One Always Sign Out Of Admin User A/C 5 66
Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question