View Single Post
Old 02-03-2007, 04:47 AM   #1 (permalink)
mehulved
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default

I was checking the logs of firestarter when I saw a few programs I couldn't recognise. One of them was gatecrasher. Google doesn't give any info on that. Other program shown is back orifice, which googling around, told me that it's a kind of trojan. Is this a false positive or has my machine been compromised?
I have attached the log of firestarter. I have removed bittorrent and unknown from the list.

EDIT - I disabled boinc client, now I don't see back orifice. Do they use same ports or something?
The services I see now are - bittorrent, gatecrasher, NTP, pop3s, SSDP and unknown.
netstat shows, pop3s is connecting to google via opera. So, that's safe. Azureus is running, so BitTorrent is also OK. Now, I got ssdp is simple service discovery protocol so that's safe. Is there any connection between ssdp and HAL?
sheesh, gatecrasher is a protocol used in connection with bittorrent. So, it seems lot better now.
Attached Files
File Type: txt firestarter-events.txt (21.6 KB, 10 views)
__________________
http://www.bash.org/?258908

Last edited by mehulved; 02-03-2007 at 05:08 AM.
mehulved is offline