 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network technologies and trends &#187; Trojan</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/network-technologies/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/network-technologies</link>
	<description></description>
	<lastBuildDate>Wed, 15 May 2013 18:52:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Botnet infects more than 2500 Enterprises World wide</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/botnet-infects-more-than-2500-enterprises-world-wide/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/botnet-infects-more-than-2500-enterprises-world-wide/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 12:27:31 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[e-mail span]]></category>
		<category><![CDATA[infected computers]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[NetWitness]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/botnet-infects-more-than-2500-enterprises-world-wide/</guid>
		<description><![CDATA[  According to Internet Security Vendor NetWitness computer network security firm. A botnet has been terrorizing corporate computers around the World over last 18 months. The malicious program, or botnet, can commandeer the operating systems of both residential and corporate computing systems via the Internet. Such botnets are used by computer criminals for a range [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 10pt"><span><span style="font-family: Calibri;font-size: small"> </span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 3.75pt"><span><span style="font-family: Calibri;font-size: small">According to Internet Security Vendor </span><a href="http://www.netwitness.com/resources/pressreleases/feb182010.aspx"><span style="font-size: small"><span style="font-family: Calibri">NetWitness <span>computer network security firm</span></span></span></a></span><span style="font-size: small"><span style="font-family: Calibri"><span>.</span><span> A botnet has been terrorizing corporate computers around the World over last 18 months.</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 3.75pt"><span style="font-size: small"><span style="font-family: Calibri"><span>The malicious program, or botnet, can commandeer the operating systems of both residential and corporate computing systems via the Internet. Such botnets are used by computer criminals for a range of illicit activities, including sending e-mail spam and stealing digital documents and passwords from infected computers. In many cases they install so-called keystroke loggers to capture personal information.</span><span></span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 3.75pt"><span><span style="font-size: small"><span style="font-family: Calibri">&#8220;Many security analysts tend to classify ZeuS solely as a Trojan that steals banking information, but that viewpoint is naïve,&#8221; said Alex Cox, the NetWitness analyst that discovered Kneber when installing his company&#8217;s software at a company. The new botnet he said, has been used to harvest a wide variety of data from corporations.</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 3.75pt"><span><span style="font-size: small"><span style="font-family: Calibri">According to a white paper published by NetWitness Thursday &#8212; which includes some interesting analysis among the product pitches &#8211; the company&#8217;s researchers found 75 GB of stolen data, which contained more than 68,000 stolen credentials obtained over a four-week period. More than 3,500 of those were Facebook credentials, another 2,500-plus were Yahoo usernames and passwords.</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span><span style="font-size: small"><span style="font-family: Calibri"><span> </span>If you want to know more about botnet check this </span></span><a href="http://www.symantec.com/norton/theme.jsp?themeid=botnet"><span style="font-family: Calibri;font-size: small">article from Symantec</span></a><span style="font-size: small"><span style="font-family: Calibri">.</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-size: small"><span style="font-family: Calibri">The top five sources of infected computers are Egypt, Mexico, Saudi Arabia, Turkey and the U.S.</span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/botnet-infects-more-than-2500-enterprises-world-wide/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fortinet October ’09 Threatscape Report Shows Highest Malware Levels Detected all Year</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/fortinet-october-%e2%80%9909-threatscape-report-shows-highest-malware-levels-detected-all-year/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/fortinet-october-%e2%80%9909-threatscape-report-shows-highest-malware-levels-detected-all-year/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 06:07:59 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[AntiVirus Pro 2010]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Network Technologies and Trends]]></category>
		<category><![CDATA[October Threatscape report]]></category>
		<category><![CDATA[Scareware]]></category>
		<category><![CDATA[security solutions]]></category>
		<category><![CDATA[threatscape report]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[unified threat management]]></category>
		<category><![CDATA[ZBot keylogger]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/fortinet-october-%e2%80%9909-threatscape-report-shows-highest-malware-levels-detected-all-year/</guid>
		<description><![CDATA[According to the latest Threatscape report (October 2009) released by Fortinet, the total amount of malware detected is more than a year, with levels four times greater than in the previous month (September 2009). The two main Bredolab variants detected this month were W32/Bredo.G and W32/Bredolab.X, most notably included in fake DHL invoice spam campaigns. Derek [...]]]></description>
				<content:encoded><![CDATA[<p>According to the latest <a href="http://www.fortiguard.com/report/roundup_october_2009.html">Threatscape report<span style="text-decoration: underline"><span style="color: #0066cc"> (October 2009)</span></span></a> released by Fortinet, the total amount of malware detected is more than a year, with levels four times greater than in the previous month (September 2009).</p>
<p>The two main Bredolab variants detected this month were W32/Bredo.G and W32/Bredolab.X, most notably included in fake DHL invoice spam campaigns.</p>
<p>Derek Manky, project manager, cyber security and threat research, Fortinet commented: &#8220;We&#8217;re seeing record levels of scareware building off volume from September, and the danger in these threats is only becoming more serious as the methods for delivery evolve and the blending of attacks bring more complexity.<br />
&#8220;As we&#8217;ve seen in the consistency of repeated threats, the old schemes are still proving to be good methods. Enterprises and consumers must take equal responsibility in understanding the disguises of these threats and implementing a multi-pronged security solution that addresses the different and changing characteristics of tried and true tactics,&#8221; he added</p>
<p>During the month of October 2009 Scareware tactics have reached all time high, with worst ever attacks reported. Seven of the top ten malware variants detected linked back to scareware, with scareware tactics diverging to include botnets, corrupted advertisements and SEO attacks.</p>
<p>The most notable development in October 2009 was the preponderance of AntiVirus Pro 2010 rogue security software, which when installed will contact a remote server in order to obtain malicious payload and receive updated copies; a trojan downloader named Bredolab which is now downloading AntiVirus Pro 2010 installers and the ZBot keylogger; and the ongoing development of affiliate programs that tempt participants with a handsome pay-out on each software download purchased. Tools and kits are readily available to participating affiliates, accelerating the distribution of scareware and other malicious components.</p>
<p>Read the <a href="http://www.fortiguard.com/report/roundup_october_2009.html">full October Threatscape report</a>, which includes the top threat rankings in each category.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/fortinet-october-%e2%80%9909-threatscape-report-shows-highest-malware-levels-detected-all-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don’t panic whenever you see %IP-4-DUPADDR: Duplicate address error log in your Cisco 6500 Switches running HSRP</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/don%e2%80%99t-panic-whenever-you-ip-4-dupaddr-duplicate-address-error-log-in-your-cisco-6500-switches-running-hsrp/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/don%e2%80%99t-panic-whenever-you-ip-4-dupaddr-duplicate-address-error-log-in-your-cisco-6500-switches-running-hsrp/#comments</comments>
		<pubDate>Sun, 09 Nov 2008 06:51:50 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cisco 6500]]></category>
		<category><![CDATA[Cisco 6500 Series Catalyst Switch]]></category>
		<category><![CDATA[Cisco 6503]]></category>
		<category><![CDATA[Cisco Catalyst 6503-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6506-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6509-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6509-V-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6513 Switch]]></category>
		<category><![CDATA[Cisco Systems]]></category>
		<category><![CDATA[Cisco Tips]]></category>
		<category><![CDATA[Hot Standby Router Protocol]]></category>
		<category><![CDATA[HSRP]]></category>
		<category><![CDATA[Network Troubleshooting]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Routing and Switching]]></category>
		<category><![CDATA[Switches]]></category>
		<category><![CDATA[Switching]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/don%e2%80%99t-panic-whenever-you-ip-4-dupaddr-duplicate-address-error-log-in-your-cisco-6500-switches-running-hsrp/</guid>
		<description><![CDATA[If you are running HSRP and one of your VLAN is down and the following errors are generated in your Switch don’t panic. All this happens due the Trojans in the network. MBGF-DAC-6500-BB01#sho log Nov  9 07:54:21: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc Nov  9 07:54:52: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNoSpacing"><font face="Calibri">If you are running HSRP and one of your VLAN is down and the following errors are generated in your Switch don’t panic. All this happens due the Trojans in the network. </font></p>
<p><span></span><span><span><font face="Calibri">MBGF-DAC-6500-BB01#sho log</font></span></p>
<p></span></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:54:21: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:54:52: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:55:22: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:55:52: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:56:11: %SEC-6-IPACCESSLOGS: list 12 permitted 10.0.0.1 256 packets</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:56:22: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:56:52: %IP-4-DUPADDR: Duplicate address 10.12.0.1 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:57:11: %SEC-6-IPACCESSLOGS: list 12 permitted 10.0.0.2 263 packets</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:57:11: %SEC-6-IPACCESSLOGS: list 12 permitted 10.0.0.7 200 packets</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:57:22: %IP-4-DUPADDR: Duplicate address 10.12.0.1 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Nov<span>  </span>9 07:57:52: %IP-4-DUPADDR: Duplicate address 10.12.0.2 on Vlan106, sourced by 000f.fe0a.1fbc</font></p>
<p class="MsoNoSpacing"><font face="Calibri">MBGF-DAC-6500-BB01#</font></p>
<p class="MsoNoSpacing"><font face="Calibri">Last week at 3 A.M I received a call from our Help Desk, stating our applications are not running in one our departments. I logged remotely to our Network and try figured out what is problem. Upon carefully looking at the logs in our Cisco 6513 core Switches I figured out a duplicate IP address is created which happens to be the Standby IP address for the Core Switch for HSRP.</font></p>
<p class="MsoNoSpacing"><font face="Calibri">I figured out the PC by looking the at mac address generated in the log and closed the network connection for that particular PC and the problem was solved.</font></p>
<p class="MsoNoSpacing"><font face="Calibri">If you face similar problems its better to change the HSRP Standby IP address in Core Switches and then try figure out the infected PC. Once the PC is figured out close the network connection and make sure the Trojans are removed. Upon cleaning the infected PC you can reconfigure the HSRP Standby IP address to the previous one. </font></p>
<p><font face="Calibri"><span>Once I get the <a href="http://itknowledgeexchange.techtarget.com/network-technologies/solution-for-ip-4-dupaddr-duplicate-address-error-log-in-your-cisco-6500-switches-running-hsrp/">complete solution</a> to fix this problem I will post it.</span><span></span></font></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/don%e2%80%99t-panic-whenever-you-ip-4-dupaddr-duplicate-address-error-log-in-your-cisco-6500-switches-running-hsrp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
