Jump to content
GreaseSpot Cafe

Back Dooir /Sub Seven Trojan Horse


krys
 Share

Recommended Posts

I've got a question!!!

Recently I upgraded to NAV 2003 with it's fire wall security system. I've seen this block this virus looking thing at least twice a day.

I believe that it is not a serious threat to me personally, and it's not an attack per se because when I run checks it always returns a range of IP addresses and a company name which sounds like a telecommunications company or an advertising company. About half the time it is from abroad....Korea...London

Do any of you have any idea what they are doing and why (I'm just curious)? Is it for advertising??? spamming???

I did have a Trojan once on this machine...it snuck past NAV 2002! That's why I upgraded...and cleaned my computer....I don't have any reports than my computer is trying to make a connection outbound...these are all inbound.

What do you guys think? Anybody with a similar experience???

Thanks

krys

Link to comment
Share on other sites

Backdoor sub/7 is a virus that allows a remote user to take over control of your computer.

That's the short answer!

What you are experiencing with your firewall are users scanning your ip for the sub7 virus. If you HAD the virus, and no firewall blocking the person scanning you, they could "own" you...meaning they had successfully taken over your computer.

As long as the firewall is blocking the attack, then your OK.

Rick

Link to comment
Share on other sites

I'm suprised that it still exists. I tested those programs out years ago. BackOrifice, for example, has to be nearly seven years old (maybe not quite that old, maybe it's only five.)

I wrote a little program once to play a .wav file of a doorbell ringing whenever someone hit port 12345 or 31337 (where BO and Sub7 usually get you) but had to turn it off because it went off too much at random times.

It's definitely a random scan most of the time though. I remember programs that would take a range of IP addresses (e.g. 192.168.1.1 to 192.168.1.255) and scan all of them, just to see if it was installed. That's what this probably is more than anything.

Another annoying thing was all the Microsoft IIS web server worms. When I was running my own web site back then, over 2/3 of all the hits I got were from those stupid things. I would watch my server logs and they would just scroll by while thousands upon thousands of hits went by looking for IIS exploits.

I was running Apache webserver on Linux though, so that made it even more pointless.

Link to comment
Share on other sites

Backdoor sub/7 actually seems to be on a revival of sorts. I used to have all ports open to my server and used a software firewall to protect it. I would get attempted attacks daily, numerous times. Then I set up port forwarding on my router and they can't get past first base anymore!

Probably kids that are just studying hacking 101!

Rick

Link to comment
Share on other sites

  • 2 weeks later...

quote:
Originally posted by krysilis:

I've run quite a few of the offending IP addresses and they are mostly communication companies.

I wonder if it could be part of a "pre spam" test run!


Actually, the Windows Messenger SPAM has been going on too. Here is an article about it. I recieved one once, even though I had my NAT/firewall box on, and ZoneAlarm running on that desktop (turned out I had the PC in the DMZ of the firewall and forgot about it) but was suprised that someone could send it over the internet.

Link to comment
Share on other sites

quote:
Originally posted by Wonton Soup:

What is a port and why is it important to keep it closed?


Well, I'll use an analogy. Let's say that the internet is a neighborhood. Within each neighborhood, you have houses which are the personal computers. In your house, there are many doors, which would be like ports. You may keep the front and back doors locked, but a bad guy might find his way in the garage door.

On the internet, bad guys often test ports to see if there is a computer they can get into. It's just like a burglar that goes door to door and jiggles the handle to see if it is unlocked. He may try an entire neighborhood until he finds an unlocked door. These bad guys on the internet have programs that test a whole "neighborhood" of computers to find one with a port he can connect to.

quote:
Originally posted by Wonton Soup:

What does a firewall do?


Depending on what type of firewall you get, it blocks something from getting in. A software firewall on your PC will block the ports on your computer, and not let anything out onto the internet without your permission. Think of it as locking a door both from the inside and outside, and you give permission to who goes in and out.

A hardware firewall is more like a gated fence. It puts up a barrier outside of your house that has to be unlocked. This is usually best if you have a few computers on a network inside your home.

The best solution, in my opinion, is to run both a firewall on the network and one on each computer. It's like having a locked gate on a fence around your house, but you keep all the doors on your house locked too.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...