[Dshield] XBOX virus?
TRushing at hollandco.com
Mon Jun 14 15:51:14 GMT 2004
list-bounces at lists.dshield.org wrote on 06/14/2004 10:14:07 AM:
> Willing to bet the employee has put linux on his xbox. Then once the
> employee was connect they tried to connect to an irc server to check the
Possible, but I doubt it. The employee I was thinking of would not be
technical enough to try something like this. However, it was not them.
They do not have an Xbox (and I believe him) and he was out in the field
when the event happened.
It may be a mystery that is never solved, but given that whoever it was
will likely connect again, I'd really like to know more about XBox and
Anybod know if there is an irc honeypot out there? I'm wondering if I
could have the firewall redirect all requests for irc channels inside the
network to something I set up so that I could watch what the boxes do once
connected. I'd obviously need something that could pretend to be any host
and would claim to have any channel open that they requested, but I don't
even know enough about irc to know if a virus connected box automatically
connects to a preconfigured channel or if it first asks for a list of
P.S. As someone else pointed out in private e-mail, I did a lousy job of
obfuscating the hostname in the original post.
More information about the list