|
|||||||||||
|
Re: Worm on 445/tcp?
From: Stephen Friedl <steve(at)unixwiz.net>
Date: Tue Dec 17 2002 - 20:46:55 EST
Your logs were almost certainly not from this worm: the code is quite clear that the second and fourth octets (1.*2*.3.*4*) won't be above 127, and I do not believe this worm was even around back on the 9th - myNetWatchman first saw this activity on the 14th. Looks like yer usual internet riff-raff to me :-) Steve
---
This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Wed Dec 18 10:57:39 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:54 EDT |
||||||||||
|
|||||||||||