nanog mailing list archives
Re: worm information
From: Jack McCarthy <nanog () jackmccarthy com>
Date: Sat, 10 Apr 2004 11:36:37 -0700 (PDT)
Agobot scanning... Take a look at these links: http://isc.sans.org/diary.php?date=2004-04-05 http://isc.sans.org/diary.php?date=2004-04-01 http://isc.sans.org/diary.php?date=2004-04-09 Also, take a read through the "New Worm???" thread at: http://www.dshield.org/pipermail/intrusions/2004-April/thread.php -Jack --- "Christopher J. Wolff" <chris () bblabs com> wrote:
Hello, Over the last few days I've seen a number of hosts attempt to initiate TCP connections to the following ports in sequence. 80 139 445 6129 3127 1025 135 2745 ...repeat. At this moment I haven't seen a correlation between this activity and the port exploitation list on CERT. Any insight would be appreciated, thank you. Regards, Christopher J. Wolff, VP CIO Broadband Laboratories, Inc. http://www.bblabs.com
Current thread:
- worm information Christopher J. Wolff (Apr 10)
- Re: worm information Jeff Workman (Apr 10)
- Re: worm information Darrell Greenwood (Apr 10)
- Re: worm information ravi pina (Apr 10)
- RE: worm information Christopher J. Wolff (Apr 10)
- Re: worm information ravi pina (Apr 10)
- RE: worm information Christopher J. Wolff (Apr 10)
- Re: worm information Darrell Greenwood (Apr 10)
- Re: worm information Jeff Workman (Apr 10)