|
|||||||||||
|
Re: Packet from port 80 with spoofed microsoft.com ip
From: zmajd fully <istoleyourmonkeys(at)hairdresser.net>
Date: Mon Feb 03 2003 - 18:27:59 EST
At the moment the DDoS only affects windows/MSDN on intel, the solaris MSDN/sql server isn't affected, but apprantly a port is in the workz by some guys from #sage-au (./hack chanl) on oz.org. I got some packets in the IDS for the sparcs here last night, but SUN says they won't have a patch yet till they fix some bugs. I belive you can detect the attack with tcpdump or snoop, but u have 2 be carefull cos the tpm/sage-au guys have a thing 2 make it crash and open other ports which could futher open u 2 DDoS attacks of this nature. Thanks Again.
Alvin.
"Diverse - The future is now"
Hulio Cortez ruxed some lyrix like:
-- __________________________________________________________ Sign-up for your own FREE Personalized E-mail at Mail.com http://www.mail.com/?sr=signup ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.comReceived on Tue Feb 4 13:46:26 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:57 EDT |
||||||||||
|
|||||||||||