Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

pc on private network with backdoor--can it be accessed?

Status
Not open for further replies.

ftechguy

IS-IT--Management
Oct 2, 2002
149
US
The latest mydoom, beagle, netsky variants all seem to leave backdoors on the machines they infect. If such a machine is on a private network with private IP, can it still be accessed by the virus writers from outside the network (assuming no firewall)? If it can, how is it done?

And with that, if there is a firewall (at the gateway), would this effectively block the infected machine from both transferring the "i've been hacked" acknowledgement and any subsequent attempts by virus writers to use the back door?
 
Yes and no. The trojans actually connect to a (or many) pre-programmed IP address(es) so a firewall that allows outgoing connections won't stop the connection. Now the machine can be accessed through the trojan program, in effect placing a command where the trojan accesses it. It depends on your type of firewall how you can resolve this, but usually you deny in/out for all ports that you aren't using.

Alex
 
Ah ok, so it seems a firewall will become a completely essential device instead of just some useful security device to buy if budget allows. Well that's how times are now I guess. Thanks for the info, Alex!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top