Re: New CIFS (port 445) worm?
On Tue, Dec 17, 2002 at 08:30:13AM -0800, David Gillett wrote:
We're seeing a huge increase of tcp/445 scans on our networks
too. For the moment, I just opened the port on my firewall to
permit them through to a machine running tcpdump to capture all
that's possible, to do further investigation.
> My assumption, at this point, is that those two machines
I agree. I hope you've not wiped out the machines, as it would
be interesting to see what, and how, is acting so to reproduce
it and check by ourselves.
bye,
--
My home isn't cluttered; it's "passage restrictive."
zen@kill-9.it . Geek . And proud of it .
http://www.kill-9.it/jargon/html/entry/zen.html
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see:
http://aris.securityfocus.com
Received on Tue Dec 17 13:35:25 2002
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:54 EDT
|