PDA

View Full Version : Virus Attack on a Tandberg?


Morgan81
01-11-2005, 02:19 PM
Hello,
I just got an interesting little message from our Anti-Virus guys.
This is what they sent me: "This system is triggering a high number of "RPC DCOM Exploit and SHELLCODE x86 0x90 unicode NOOP" alarms. From recent experience, it is probably infected with the W32/Sdbot worm or a variant."
The system is a Tandberg 1000, running B9.0 which was recently upgraded from B4.1 a few days before the new year. TMS v8.0 was used to do the upgrading (along with a few hundred other systems) but no other system came up flagged.
I don't know antivirus technology, so I don't know what that message is saying at all, however I'm pretty sure I know that a 1000 can't be infected by a virus but not 100% sure.
Anyone ever hear or see anything like this?

smoody
01-11-2005, 03:57 PM
Morgan81,

Since the W32/Sdbot virus is specific to the Windows OS, it's most likely safe to say that the codec isn't infected (unless codec manufactures start to put Windows code on their systems - scary thought!).

My best guess at what's happening is your security guys have probably setup port monitoring and have picked up UDP or other traffic from your Tandberg system on these specific ports (which the virus also uses for its own purposes).

I'd go talk with your security/network guys and see if limiting the port range on the Tandberg might be an acceptable solution, etc...

Morgan81
01-11-2005, 04:26 PM
I just spoke with them, and they said the 1000 was sending the messages from port 445 to multiple addresses which is what triggered the alert.
What's Tandberg software based on anyway, Linux? Anyone know?

Sean Lessman
01-13-2005, 11:09 AM
I just spoke with them, and they said the 1000 was sending the messages from port 445 to multiple addresses which is what triggered the alert.
What's Tandberg software based on anyway, Linux? Anyone know?
the operating system is neither Windows nor Linux.

Sean

Morgan81
01-13-2005, 04:36 PM
Thanks for the advice.
After unistalling the unit and letting it run for 24 hours being monitored, no further errors were discovered. So our Anti-virus guys have ok'ed it being re-deployed.
The only thing I can think of what happened is durning the upgrade, the system sent some non-SNMP data to the TMS server, and the anti-virus software caught it and flagged it.
Wierd stuff, but always educational. :)