427 Botnet fm qxd



Download 6,98 Mb.
Pdf ko'rish
bet268/387
Sana03.12.2022
Hajmi6,98 Mb.
#878307
1   ...   264   265   266   267   268   269   270   271   ...   387
Bog'liq
Botnets - The killer web applications

www.syngress.com
328
Chapter 9 • Advanced Ourmon Techniques
427_Botnet_09.qxd 1/8/07 4:45 PM Page 328


really were high work weights (94, 92, 79). Our host was sending about one
packet per second, and the destination ports 8080 and 8000 were the target.
The target did not seem to be sending many packets back.There is one more
point we can make: We still didn’t figure out exactly what the host was doing.
Given the ports in question, it is possible that this host was scanning for open
Web relay hosts, which are often used for sending spam. If the host is active at
this point, you might go and look at Layer 7 payloads with a sniffer. For
example, you can use tcpdump as we mentioned or ngrep, which we will dis-
cuss briefly in the next section.
Regarding the port report search question, one trick worth mentioning is
a somewhat sneaky way to search the port report logging directory. If you
have a case like Case Study #2 with a dominant scanner count spike in a par-
ticular day, you really want to find the biggest port report file in that day.This
is because there is one line per IP address in the 30-second port report file.
So, given one line per IP address, obviously the scan in Figure 6.3 will pro-
duce the largest files in the directory for that day. We use the 
wc 
(word count)
utility to determine the lines in each file, and we sort by that output like so:
# cd /home/mrourmon/logs/portreport/Fri
# find . |
xargs wc –l
| sort

196 ./Tue_Jan_18_01:24:03_PDT_2005.portreport.txt
509 ./Tue_Jan_18_01:24:33_PDT_2005.portreport.txt
2214./Tue_Jan_18_01:25:04_PDT_2005.portreport.txt
The sort makes the largest file come out last. When examined, this file
(the one with 2214 lines) showed one IP address as the target for many
external hosts. which were all doing the same form of attack.Thus the port
report file itself fingered the target IP host. In general, parallel scans or DDoS
attacks will result in large port report files.

Download 6,98 Mb.

Do'stlaringiz bilan baham:
1   ...   264   265   266   267   268   269   270   271   ...   387




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish