Getting busted by your own product…

Posted in General on December 15th, 2008 by nathanh

So we recently had a nice webinar about some of the new fuctions on an upcoming update for Flow Analytics. Our webmaster, Jon Mills, thought it would be good for all those employees who weren’t able to attend to watch it, so that we knew what was being covered.

As I was watching it, I noticed that Mike had found a few flags on our own network. Upon further investigation, it became very apparent that my own laptop was running scans across our network!

Great…just great.” Not only does everyone get to laugh at Nathan and his Trojan perpetuating laptop, but now it’s forever recorded in our archives…

On the bright side though, Flow Analytics had done exactly what we wanted it to. It had found some potentially malicious activity on our own network and our customers could see it first hand.

It was strange that our Anti-Virus and Malware software didn’t seem to pick up any of those issues, even after running the updated definitions, yet Flow Analytics did.

Well thanks to the handy dandy tool Spybot, we were able to find scads of trojans and viruses on my laptop.
Here’s a beauty of a screenshot for your viewing pleasure.

Spybot finds a virus on our corporate network

- Nate

Share and Enjoy:
  • Digg
  • StumbleUpon
  • Reddit
  • del.icio.us
  • Facebook
  • Yahoo! Buzz
  • Google Bookmarks
  • Technorati
  • Twitter
  • email
  • Print
Tags: , , ,

2 Responses to “Getting busted by your own product…”

  1. jimd Says:

    Awesome! What a good way to finds nasty’s on your network. Since FA sends a syslog message to logalot you can create a policy to react when it detects this type of traffic. One of the actions could be to run a script. I would trigger a re-image of that machine via ghost server. This would solve two problems. One – you no longer have that nasty on the machine. Two – by erasing every thing on your box we teach you a lesson. Don’t download things!

  2. We had a port scan running rampant. Do you? - NetFlow & sFlow Network Monitoring - Systrax Blog Says:

    [...] really anticipate finding. It was during one demonstration that my boss found traffic suggesting my laptop was infected with a worm. Let me tell you, that was kinda [...]

Leave a Reply