New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 952
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

The Real Deal?
Goto page 1, 2  Next
 
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> General Security
View previous topic :: View next topic  
Author Message
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1897

PostPosted: Sun Jan 18, 2004 11:43 am    Post subject: The Real Deal?
Reply with quote

Within minutes of logging on today, my firewall alerted me to the fact that a genuine(?) Microsoft program or part thereof, was attempting to make an inbound connection, details as follows:

Time 14.59
Date 18/01/2004
Program C:\WINDOWS\System32\lsass.exe
Protocol UDP (inbound)
Remote Address 217.16.64.207: 65336
Local Address All local network adapters : isakmp (500)


My suspicions aroused, l denied access, then traced the connection, it coming from a dialup connection in Macedonia. Details below.

inetnum: 217.16.64.0 - 217.16.79.255
netname: MK-ONNET
descr: Provider
descr: MACEDONIA
country: MK
admin-c: PTC
tech-c: GGON-RIPE
tech-c: RK5232-RIPE
tech-c: GS1763-RIPE
status: ASSIGNED PA
notify:
notify:
notify:
notify:
mnt-by: ON-MNT
changed: 20011106
changed: 20040108
source: RIPE

Can anyone here shed any light on this incident and tell me what C:\WINDOWS\System32\lsass.exe is, please?

I may appear paranoid, but when, if at all, did MS start trying to connect using dialup from Macedonia?

Is this yet another hijack attempt or what?

Sorry for all the questions but, this just does not seem right to me. Apologies if i've posted in wrong forum but to me, it's a security issue.

tia


Last edited by Mariner on Tue Jan 20, 2004 6:29 am, edited 1 time in total
Back to top
View users profile Send private message
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Sun Jan 18, 2004 8:35 pm    Post subject:
Reply with quote

Hi Mariner,

I don't know the awnsers to all your questions, but lsass.exe (according to Pacman's Startup List) Is a Virus. (I also have lsass.exe runing on my computer)

However, a program (Whats happening here) I have that tells me what the processes are, that are running on my system, and it says lsass.exe is a Microsoft Corp. Windows Operating System.

I tried to terminate lsass.exe from Alt+Ctrl+Del, but it says, it is a critical system process and cannot end this process.

So I'm not quite sure what it is, but hopefully someone else will, becuase I'd like to know also.

You can visit this site, to download a program, that tells you what the processes are that are running on your machine, here:
http://www.turboware.com/WhatsHappening.htm

And Pacman's Startup guide is here: (Information on lsass.exe)
http://www.sysinfo.org/startuplist.php?...unt=&type=

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1897

PostPosted: Mon Jan 19, 2004 11:25 am    Post subject:
Reply with quote

Thanks Silent Seven. Have mailed MS with this -personal details removed.
Hopefully, this will yield a result.
Back to top
View users profile Send private message
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Mon Jan 19, 2004 12:05 pm    Post subject:
Reply with quote

Hey,

Yea, sounds good, please post the results! Very Happy

Thanks.

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
mariner

Guest






PostPosted: Mon Jan 19, 2004 1:02 pm    Post subject:
Reply with quote

Initially used 'phone support. Did not yield much, other than MS do not route through Macedonia using dialup. They (MS) didn't really appear too concerned. "Your problem, mate". Thanks, MS.

Bill-on-the-Hill got too much cash and not enough interest. Couple a Laws 66mm would rock him...not that l should...i'm a very bad person just for thinking such a thing....
Back to top
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Mon Jan 19, 2004 1:23 pm    Post subject: RATS ;)
Reply with quote

Hey,

lol

hmmmmmmm Surprised , rats Sad

I use Zone Alarm for a firewall, and they have a geo mapping thingy, that traces the IP address to the users Pc location.

I think it is different than the ARIN WHOIS info becuase, it shows a different location than the WHOIS data base.

But Zone Alarm does'nt allow the user to put a IP address in, it only lets you trace the connections that were attempted on your computer only.

I was looking for a different way to trace it, becuase I can't trace it with Zone Alarm, becuse I did not recieve the connection, so I'll let you know if I come up with anything.

I'm going to try and contact Zone Alarm, and see if they can get a mapping on it.

(correct me if I'm wrong) I'm not sure but I think the ARIN WHOIS Information is a trace on the users ISP, ( Example: The ISP is in macidonia?) but the Geo Map traces directly to the users house. (I think)

I dont know for sure though.

TTYL

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
k027

1st Responder
1st Responder



Joined: Aug 25, 2003
Posts: 1189
Location: USA

PostPosted: Mon Jan 19, 2004 2:28 pm    Post subject:
Reply with quote

The best you can do with those tools is trace back to a server, either the originator's ISP or perhaps an "anonymous" proxy server. You would then have to contact the owner of the server to find out who was assigned the IP at the time of the event. Sad
Back to top
View users profile Send private message
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Mon Jan 19, 2004 8:04 pm    Post subject: Thanks.
Reply with quote

Hey,

Thank you for the info k027.

However mariner the Zone Alarm Lab, may take a day to reply to my email.

I did find this site which allows you to, submitt a suspicious hacker related things.

Check it out:
http://www.dshield.org/

Try and see if you can post it there, I think they will investigate for free, and get all the info you need about it.

Hope it works!

I'll post when I get the email back.

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1897

PostPosted: Tue Jan 20, 2004 7:18 am    Post subject:
Reply with quote

This is what it is and is legit, but it is not accessed by MS through a dialup connection. Can only surmise that it was carrying "something extra" in view of the attempted means of entry.

C:\WINDOWS\system32\lsass.exe
Process File: lsass or lsass.exe
Process Name: Local Security Authority Service
Description: The Windows Local Security Authority Server Process Handles Windows Security Mechanisms


lsass - lsass.exe - Process Information
Process File: lsass or lsass.exe
Process Name: Local Security Authority Service
Description: The Windows Local Security Authority Server Process Handles Windows Security Mechanisms. It verifies the validity of user logons to your PC/Server .Technically it generates the process that is responsible for authenticating users for the Winlogon service.
Company: Microsoft Corp.
System Process: Yes
Security Risk ( Virus/Trojan/Worm/Adware/Spyware ): No
Common Errors: N/A


Had e-mail from MS generated by autoresponder promising a personal response. Still awaiting this.
Back to top
View users profile Send private message
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Tue Jan 20, 2004 10:47 am    Post subject: Finally
Reply with quote

Hey Mariner, Smile

Yea that looks right.

Just curious, what program source, did that info come from? (Not that it does'nt look right, just wondering, incase we have another problem like that.) Laughing

Glad you got that figured out. Cool

If you could post that MS response, your waiting for, I'd appreciate it. Wink

I'll post the response from Zone Alarm. (When I get it.)

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1897

PostPosted: Tue Jan 20, 2004 8:55 pm    Post subject:
Reply with quote

Will dig out source later and post MS response when received.
Back to top
View users profile Send private message
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Tue Jan 20, 2004 8:59 pm    Post subject:
Reply with quote

Thank you, Mariner. Smile

I still haven't heard from Zone Alarm, but I will post, when I do.

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Thu Jan 22, 2004 2:00 pm    Post subject:
Reply with quote

Hello Mariner,

I got a reply from Zone Alarm today, but they where not at all helpfull. Sad

The person who replied, must not have known what he was talking about, becuase he said he's never heard of geo mapping.(Yet it is right on there site.) And he closed the case. Confused

So I guess it's kind of in the air.

Well TTYL.

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
Mariner

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Aug 25, 2003
Posts: 1897

PostPosted: Thu Jan 22, 2004 7:21 pm    Post subject:
Reply with quote

Still awaiting reply from MS. Have not yet dug out source, been bogged down with another matter. Will do though. Smile
Back to top
View users profile Send private message
SilentSeven

Lieutenant
Lieutenant



Joined: Jan 13, 2004
Posts: 160
Location: USA

PostPosted: Thu Jan 22, 2004 7:25 pm    Post subject:
Reply with quote

Ok Mariner Smile

Thanks Wink

*smiles* Smile

_________________
*~Silent~S.E.V.E.N~*
Back to top
View users profile Send private message Visit posters website MSN Messenger
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       Computer Cops Forum Index -> General Security All times are GMT - 5 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops