<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help fast!!! Trojan network scanner needed in Operating System - Microsoft</title>
    <link>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326372#M5014</link>
    <description>Unless you happen to know what port the trojan opens (assuming it is a remote control trojan and not just an emailer) a scan would be difficult to interpret but if you want to try then nmap at:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.insecure.org/nmap/" target="_blank"&gt;http://www.insecure.org/nmap/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://netsecurity.about.com/cs/hackertools/a/aafreeportscan.htm" target="_blank"&gt;http://netsecurity.about.com/cs/hackertools/a/aafreeportscan.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If it were my network I would install snort &lt;BR /&gt;&lt;A href="http://www.snort.org/" target="_blank"&gt;http://www.snort.org/&lt;/A&gt;&lt;BR /&gt;on a pc and have it monitor the traffic on the port going to the ISP.  It would be a simple matter to have it look for traffic to port 25 and tell you what PC's are doing this.  &lt;BR /&gt;&lt;BR /&gt;Could also be that you have an open mail relay somewhere in your system.  This is actually pretty common.  Either poorly configured and a spammer found it or a system which got hacked, had the mail relay turned on and then the hacker cleaned up his traces.  Problem is it need not listen on port 25.  The hacker/spammer can use a different port of his/her choice.  This would not show as trojan or virus.&lt;BR /&gt;&lt;BR /&gt;Do you not have a firewall on this large network?  Easy enough to ask the firewall (or router) to block port 25 outgoing and tell you who sent it.&lt;BR /&gt;&lt;BR /&gt;Ron</description>
    <pubDate>Thu, 08 Jul 2004 08:40:58 GMT</pubDate>
    <dc:creator>Ron Kinner</dc:creator>
    <dc:date>2004-07-08T08:40:58Z</dc:date>
    <item>
      <title>Need help fast!!! Trojan network scanner needed</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326371#M5013</link>
      <description>Hi folks,&lt;BR /&gt;I need a program that can scan the entire network for trojans. So one program that can scan al pc's and servers.&lt;BR /&gt;To install a program on each pc is a little bit tu much work. &lt;BR /&gt;&lt;BR /&gt;Situation.&lt;BR /&gt;Our ISP thinks we have a trojan on our network that sends spam and blocked port 25 so we can not send e-mail, very frustrating. &lt;BR /&gt;We can not find any trojans. The ISP does not want to release the block easyly, so I want soee proof that our network is trojan/virusfree.&lt;BR /&gt;&lt;BR /&gt;We have a 3com firewall, whit only the nessesary ports open en Notron Cooperate virusserver. &lt;BR /&gt;&lt;BR /&gt;Hope anyone can point me to a program that can scan for trojans, so I have some proof (logfile) for the ISP,&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Ronald</description>
      <pubDate>Thu, 08 Jul 2004 08:07:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326371#M5013</guid>
      <dc:creator>Ronald Postma</dc:creator>
      <dc:date>2004-07-08T08:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need help fast!!! Trojan network scanner needed</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326372#M5014</link>
      <description>Unless you happen to know what port the trojan opens (assuming it is a remote control trojan and not just an emailer) a scan would be difficult to interpret but if you want to try then nmap at:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.insecure.org/nmap/" target="_blank"&gt;http://www.insecure.org/nmap/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://netsecurity.about.com/cs/hackertools/a/aafreeportscan.htm" target="_blank"&gt;http://netsecurity.about.com/cs/hackertools/a/aafreeportscan.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If it were my network I would install snort &lt;BR /&gt;&lt;A href="http://www.snort.org/" target="_blank"&gt;http://www.snort.org/&lt;/A&gt;&lt;BR /&gt;on a pc and have it monitor the traffic on the port going to the ISP.  It would be a simple matter to have it look for traffic to port 25 and tell you what PC's are doing this.  &lt;BR /&gt;&lt;BR /&gt;Could also be that you have an open mail relay somewhere in your system.  This is actually pretty common.  Either poorly configured and a spammer found it or a system which got hacked, had the mail relay turned on and then the hacker cleaned up his traces.  Problem is it need not listen on port 25.  The hacker/spammer can use a different port of his/her choice.  This would not show as trojan or virus.&lt;BR /&gt;&lt;BR /&gt;Do you not have a firewall on this large network?  Easy enough to ask the firewall (or router) to block port 25 outgoing and tell you who sent it.&lt;BR /&gt;&lt;BR /&gt;Ron</description>
      <pubDate>Thu, 08 Jul 2004 08:40:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326372#M5014</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2004-07-08T08:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need help fast!!! Trojan network scanner needed</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326373#M5015</link>
      <description>Hi Ron,&lt;BR /&gt;Tnx for the quick reply.&lt;BR /&gt;I do not even think there is a trojan on the network, so I do not know a port.&lt;BR /&gt;Our ISP got complains from theire costumers that costumers got spam from our IP-adres. &lt;BR /&gt;You probebly know that it is easy to send send mail with another IP, so some spammers just used our IP.&lt;BR /&gt;&lt;BR /&gt;Why do I have to block port 25 outgoing, then the exchangeserver can not send any e-mail or am I wrong?&lt;BR /&gt;&lt;BR /&gt;Actualy I only need some proof that nothing is wrong to send to the ISP, so they will lift the block. &lt;BR /&gt;&lt;BR /&gt;I look into the links and get back to you,&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Ronald&lt;BR /&gt;</description>
      <pubDate>Thu, 08 Jul 2004 08:57:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326373#M5015</guid>
      <dc:creator>Ronald Postma</dc:creator>
      <dc:date>2004-07-08T08:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need help fast!!! Trojan network scanner needed</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326374#M5016</link>
      <description>Since you are blocked anyway, I don't see why it would be a problem to block the same port on the firewall to let it log attempts for a while.  &lt;BR /&gt;&lt;BR /&gt;I'm not up on 3-Com firewalls but on a Cisco it is easy to ask the firewall to block or pass a packet to a particular port and to log the packet's source and destination.  In fact it should be possible to only allow packets from your mail server to go out to port 25 and to block everyone else and to tell you about all the blocked attempts.  That would quickly find the trojan if it exists.&lt;BR /&gt;&lt;BR /&gt;I'm beginning to wonder if your own mail server has been told to only relay packets from members of your local network and you forgot to exclude the firewall's IP (he will NAT any incoming packets so they will look like a local packet.)&lt;BR /&gt;&lt;BR /&gt;Ron</description>
      <pubDate>Thu, 08 Jul 2004 09:26:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326374#M5016</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2004-07-08T09:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need help fast!!! Trojan network scanner needed</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326375#M5017</link>
      <description>What scans I do I can not find anything wrong,&lt;BR /&gt;My supirior does not want me to put more effort in finding what probebly is not there. &lt;BR /&gt;&lt;BR /&gt;Now we only presuring the ISP to lift the block. &lt;BR /&gt;&lt;BR /&gt;Tnx for your help,&lt;BR /&gt;Regards,&lt;BR /&gt;Ronald&lt;BR /&gt;</description>
      <pubDate>Thu, 08 Jul 2004 10:14:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/need-help-fast-trojan-network-scanner-needed/m-p/3326375#M5017</guid>
      <dc:creator>Ronald Postma</dc:creator>
      <dc:date>2004-07-08T10:14:11Z</dc:date>
    </item>
  </channel>
</rss>

