RE: Nachi

  • From: Phill Hardstaff <phillh@xxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Fri, 21 Nov 2003 12:19:05 +1100

Thanks Greg, baretail is brilliant and free, uses virtually no CPU and very
low memory.  Run this on your IP logs, set up some color highlights for your
internal networks, then bingo, you vcan see a Nachi machine strat up just
like that, low tech but it works.
 
Cheers
 
Phill

   _____  

From: Greg Mulholland [mailto:gmulholland@xxxxxxxxxxxxxxx] 
Sent: Friday, 21 November 2003 10:01 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Nachi


http://www.ISAserver.org

Phil
 
try this one
 
HYPERLINK
"http://www.baremetalsoft.com/baretail/index.php"http://www.baremetalsoft.co
m/baretail/index.php
 
or get cygwin. 
 

   _____  

From: Greg Mulholland [mailto:gmulholland@xxxxxxxxxxxxxxx] 
Sent: Friday, November 21, 2003 9:50 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Nachi


http://www.ISAserver.org

Phil
 
There is a command. I remember using it for just this reason. I know it is a
tail.exe because its on my system, but I cant for the life of me remember
where it came from. I thought it may have been part of the pstools suite
from sysinternals but its not.
 
I will try and dig it out and let you know.
 
Greg Mulholland
gmulholland@xxxxxxxxxxxxxxx
HYPERLINK "http://www.isaserver.org/"http://www.isaserver.org
HYPERLINK "http://isatools.org/"http://isatools.org
HYPERLINK "http://www.google.com/"http://www.google.com 


   _____  

From: Phill Hardstaff [mailto:phillh@xxxxxxx] 
Sent: Thursday, November 20, 2003 3:58 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Nachi


http://www.ISAserver.org


Jim, yep, I can confirm that  HYPERLINK
"http://support.microsoft.com/default.aspx?scid=283213";
\nhttp://support.microsoft.com/default.aspx?scid=283213 works great. But
don't do the first one :) Also, once you have done this you can see in the
logs very quickly which host the attack is coming from, just wish Windows
had a tail command, I tried Wintail but it goes to 100% CPU, anyone know
anything that works well, so you could watch the tail end of the packet log
and see straight way what is happening, like 100 denies for ICMP from one
internal host in under 1 second = Nachi (most likely).

Cheers 

Phill 


 


---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.542 / Virus Database: 336 - Release Date: 18/11/2003
 

Other related posts: