LinuxQuestions.org
Support LQ: Use code LQ3 and save $3 on Domain Registration
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 11-19-2002, 10:55 AM   #1
armoredarena
LQ Newbie
 
Registered: Nov 2002
Posts: 2

Rep: Reputation: 0
Am I infected? Router stops routing...


Hi all, I have a box running Redhat 8.0 serving as a router (DSL) with two nics. I have two win 98 boxes attached to a switch connected to the linux box. Samba runs fine, also everything else on the linux box runs fine, like apache, telnet, ftp, etc.

However, I can't browse the internet for very long from a win 98 box before either machines browser slows down and times out in browsing....the linux browser flies....

help...HELP!

I htink I may have been infected by the slapper. Is this a symptom of that?

thanks
 
Old 11-19-2002, 11:29 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,599
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Read http://isc.incidents.org, on the right, the Slapper analysis files and determine if you *are* infected (source files in /tmp, Firewall logged outgoing TCP and UDP connections on mentioned port or active listener on mentioned port, mail sent, etc, etc) instead of *thinking* you are (go for facts, not FUD).
 
Old 11-19-2002, 01:24 PM   #3
armoredarena
LQ Newbie
 
Registered: Nov 2002
Posts: 2

Original Poster
Rep: Reputation: 0
thanks

I have read all the stuff about slapper a and a/b though.

I guess to refine my question, would the slapper infection inhibit my win 98 box web connections? Or, is there some other reason for the slowdown I should be pursuing. Using Ethereal, I see very few tcp packets crossing through the lan interface....

I looked for the files in question (tmp/etc...), and didn't see them, but I do have a log of sendmail traffic which resembles the messages referenced in the worm documentation (on anti virus sites).

Guess I'll have to get smart!

thanks again
 
Old 11-19-2002, 04:39 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,599
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
I have read all the stuff about slapper a and a/b though.
Does this mean you *also* read the docs I was pointing to?
If so, cool, you now know how the worm spreads, what apps to rename/remove, what ports to block, what addresses to deny traffic to and what mail addresses to block.

If not, then please read those docs first.

If only wintendo fails it might as well be something like it failing to resolve addresses or like that. In any case, logging *all* traffic might help you see more, like outgoing TCP/80 and 443 scans.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Belkin router stops working under dsl... heinola Linux - Networking 2 11-27-2005 08:36 PM
Stopping/Blocking PCs infected with MS BLASTER Worm (RH 6 Gateway/Router) smartcard Linux - Security 1 11-06-2003 01:02 PM
router not routing/masquerading. Why? Pcghost Linux - Networking 1 03-24-2003 10:30 AM
lan client starts then stops via RH8 router poulaum Linux - Networking 3 02-21-2003 03:19 PM
linux routing VS cisco router shoot2kill Linux - Networking 5 07-01-2002 10:31 PM


All times are GMT -5. The time now is 12:53 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration