Full Disclosure mailing list archives
Re: Increased port 135 activity
From: Richard Johnson <rdump () river com>
Date: Mon, 22 Sep 2003 23:31:21 -0600
In article <3F6E8FAC.1020400 () jackhammer org>, Paul Tinsley <pdt () jackhammer org> wrote:
most if not all of the spikes on that graph can be mapped to a worm/virus that was discovered around the same time.
The current port 135 activity appears to be both heavy and more narrowly targeted than a recent (typical?) worm activity. I've seen a few dialups drowned in the traffic (which seems to be scans of nearby /16s), while other systems on different parts of the net report only the normal levels of MS junk traffic. I don't know whether the systems you're looking at show similar behavior. Richard -- My mailbox. My property. My personal space. My rules. Deal with it. http://www.river.com/users/share/cluetrain/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Increased port 135 activity Paul Tinsley (Sep 21)
- Re: Increased port 135 activity security snot (Sep 21)
- Re: Increased port 135 activity Paul Tinsley (Sep 21)
- Re: Increased port 135 activity Richard Johnson (Sep 22)
- Re: Increased port 135 activity Paul Tinsley (Sep 21)
- Re: Increased port 135 activity security snot (Sep 21)