Educause Security Discussion mailing list archives

symantec targetting worm

From: robin <mstubbs () FACSTAFF WISC EDU>
Date: Thu, 28 Dec 2006 17:51:00 -0600

Some subnets here are having a bit of trouble with a worm that
in particular seems to be going for tcp port 2967 which we would guess
is aiming for the SAVCE managed client port. In some cases the worm or
worms also goes for tcp port 139,445 and/or 5900.

Anyone seeing this and have some advice? Have worms been id'd other than
these at other edu's?

There was quite a spike in scanning in recent times:

Speaking of possible sym06-010 exploites, here is a nice chart about
upgrading it:

Current thread: