Security Incidents mailing list archives
** New DDoS / Trojan **
From: nine () 14X NET (nine)
Date: Sat, 10 Jun 2000 14:11:42 -0400
Security professionals, I recently talked to someone who was bragging that this is on [so-far] thousands of computers world-wide. He says this is a leaf that connects to a hub, similar to past ddos tools. This is new, and all or most of you have never seen this before. Partners of 14x Network Security have been looking this over, and tracking down the person responsible for the attacks. We already know one person that is distributing it widely, and are hoping to track it to the source. I am releasing the binary to you all to look at, it would be interesting to hear what you all think about it. Erik Tayler 14x Network Security http://www.14x.net <HR NOSHADE> <UL> <LI>APPLICATION/octet-stream attachment: erver_ </UL>
Current thread:
- update on scans of tcp 12345 AUSCERT#36349 Russell Fulton (Jun 05)
- Re: update on scans of tcp 12345 AUSCERT#36349 Shaw Terwilliger (Jun 08)
- unknown trojan (attached) Jeremy L. Gaddis (Jun 08)
- ** New DDoS / Trojan ** nine (Jun 10)
- Re: ** New DDoS / Trojan ** Pierre Vandevenne (Jun 12)
- Re: unknown trojan (attached) Brandon Kittler (Jun 10)
- Re: unknown trojan (attached) Doug Kahler (Jun 12)
- .:: 14x :: Information :: New DDoS/Trojan ::. Erik Tayler (Jun 13)
- Re: .:: 14x :: Information :: New DDoS/Trojan ::. Lic. Rodolfo Gonzalez Gonzalez (Jun 15)
- IRC connect through apache ???? arhuman () HOTMAIL COM (Jun 14)
- Re: IRC connect through apache ???? Eric Vyncke (Jun 15)
- ** New DDoS / Trojan ** nine (Jun 10)
- <Possible follow-ups>
- Re: update on scans of tcp 12345 AUSCERT#36349 Bryan Scaringe (Jun 08)