|
Mailing List Archive For incidents@securityfocus.com By Thread- Spammers? Christopher Wagner (27 Feb 2003)
- Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Salomao Barguil (27 Feb 2003)
- Re: Interesting Rafael Coninck Teigao (28 Feb 2003)
- RE: Possible new backdoor: mspx-smss.exe ? Leonard.Ong(at)nokia.com (27 Feb 2003)
- TCP 445 Scan? Charles Hamby (27 Feb 2003)
- Re: Interesting Stephen J. Friedl (27 Feb 2003)
- Re: Possible new backdoor: mspx-smss.exe ? Sven Pechler (26 Feb 2003)
- Interesting http-equiv(at)excite.com (26 Feb 2003)
- Re: More /sumthin D.C. van Moolenbroek (26 Feb 2003)
- RE: Weird Windows logon attempts Mary McAllister (26 Feb 2003)
- RE: More /sumthin Jonathan A. Zdziarski (26 Feb 2003)
- Re: More /sumthin Philipp Hug (26 Feb 2003)
- RE: Weird apache logs NESTING, DAVID M (SBCSI) (26 Feb 2003)
- RE: Weird apache logs Carmen Tache (26 Feb 2003)
- Weird apache logs Travis Read (25 Feb 2003)
- Remote Access Software (Wireless Devices) Holstein, Michael (25 Feb 2003)
- Re: Weird Windows logon attempts Russell Fulton (25 Feb 2003)
- Incident Focus Area Article Announcement Dan Hanson (25 Feb 2003)
- Re: Weird Windows logon attempts H C (24 Feb 2003)
- RE: Web server crashed, now is trying to contact an IP by port 80 every morning. Levinson, Karl (25 Feb 2003)
- RE: Web server crashed, now is trying to contact an IP by port 80 every morning. Dan Harpold (24 Feb 2003)
- Re: Web server crashed, now is trying to contact an IP by port 80 every morning. lsi (24 Feb 2003)
- Re: ICQ problem. Rafael Coninck Teigao (24 Feb 2003)
- Web server crashed, now is trying to contact an IP by port 80 every morning. Dan Harpold (23 Feb 2003)
- RE: Weird Windows logon attempts Terence Runge (24 Feb 2003)
- Re: Weird Windows logon attempts Bojan Zdrnja (24 Feb 2003)
- Re: Weird Windows logon attempts Jacco Tunnissen (23 Feb 2003)
- Weird Windows logon attempts Harry Hoffman (23 Feb 2003)
- RE: Weird Profile in Documents and Settings Christopher Hummert (22 Feb 2003)
- Re: ICQ problem. bob (21 Feb 2003)
- RE: Weird Profile in Documents and Settings Austin Ehlers (21 Feb 2003)
- Re: Weird Profile in Documents and Settings Patrick R. Sweeney (21 Feb 2003)
- Re: Scans on TCP port 135 Dave Aitel (21 Feb 2003)
- Possible new backdoor: mspx-smss.exe ? Sven Pechler (21 Feb 2003)
- Re[2]: Weird Profile in Documents and Settings Jyri Hovila (21 Feb 2003)
- Re: Weird Profile in Documents and Settings Gene Yoo (20 Feb 2003)
- ICQ problem. Thiago Madeira de Lima (21 Feb 2003)
- Questions: LKM, yoyo & rootkits Gordon Ewasiuk (21 Feb 2003)
- FTimes 3.2.0 Released Klayton Monroe (21 Feb 2003)
- WebJob 1.2.3 Released Klayton Monroe (21 Feb 2003)
- Possible stateful filtering problem? Security (21 Feb 2003)
- Re: Weird Profile in Documents and Settings Anders Thulin (21 Feb 2003)
- RE: Weird Profile in Documents and Settings Lucas Zaichkowsky (20 Feb 2003)
- Scans on TCP port 135 Kevin Patz (20 Feb 2003)
- RE: Weird Profile in Documents and Settings Rob Shein (20 Feb 2003)
- Re: Distributed spam-based DoS in progress Rohan Amin (20 Feb 2003)
- Weird Profile in Documents and Settings Greg Wiedeman (20 Feb 2003)
- Dead thread -- Distributed spam-based DoS in progress Dan Hanson (19 Feb 2003)
- RE: Distributed spam-based DoS in progress Steve Drees (19 Feb 2003)
- RE: Distributed spam-based DoS in progress Dave Hart (19 Feb 2003)
- Re: port 17300 probe fingerprint analysis william.miller(at)gsa.gov (19 Feb 2003)
- RE: Distributed spam-based DoS in progress Hugo van der Kooij (19 Feb 2003)
- Re: Distributed spam-based DoS in progress Transistor Sister (18 Feb 2003)
- Re: Distributed spam-based DoS in progress Kee Hinckley (18 Feb 2003)
- Re: Distributed spam-based DoS in progress Valdis.Kletnieks(at)vt.edu (18 Feb 2003)
- RE: Distributed spam-based DoS in progress Dave Hart (18 Feb 2003)
- Re: Kuang2 strikes again, is it just me? Kevin Patz (18 Feb 2003)
- Re: Distributed spam-based DoS in progress Hugo van der Kooij (18 Feb 2003)
- Re: port 17300 probe fingerprint analysis John Sage (18 Feb 2003)
- port 17300 probe fingerprint analysis Royans Tharakan (17 Feb 2003)
- Distributed spam-based DoS in progress Transistor Sister (17 Feb 2003)
- Re: www.nopop.net Jon Rublack (17 Feb 2003)
- RE: www.nopop.net Brad Griffin (17 Feb 2003)
- Re: Kuang2 strikes again, is it just me? Paul Dokas (17 Feb 2003)
- www.nopop.net Pascal Bouchareine (17 Feb 2003)
- Re: Web Defacement Alberto Cozer (17 Feb 2003)
- RE: Kuang2 strikes again, is it just me? Tim Heagarty (17 Feb 2003)
- mIRC Trojan Variant - port 445 worm/Trojan kyle(at)kylelai.com (16 Feb 2003)
- RE: Kuang2 strikes again, is it just me? Trevor Metzger (16 Feb 2003)
- Re: ano@ano.com ftpd dip.t-dialin.net Scott Harris (16 Feb 2003)
- Re: Kuang2 strikes again, is it just me? Jeff (16 Feb 2003)
- Re: Kuang2 strikes again, is it just me? Jasmine (16 Feb 2003)
- Re: Kuang2 strikes again, is it just me? Johannes Ullrich (15 Feb 2003)
- RE: Kuang2 strikes again, is it just me? Rob Shein (15 Feb 2003)
- Kuang2 strikes again, is it just me? Jeff Kell (15 Feb 2003)
- Incidents list administrivia and introductions... Dan Hanson (15 Feb 2003)
- Re: ICMP Destination Unreachable, Administratively Prohibited Valdis.Kletnieks(at)vt.edu (14 Feb 2003)
- Re: ICMP Destination Unreachable, Administratively Prohibited Anthony Kim (14 Feb 2003)
- Re: S4T4N1C Web Defacement security(at)imperialdesigns.com (14 Feb 2003)
- Re: Web Defacement Ricardo Castanho de Oliveira Freitas (14 Feb 2003)
- Spies on Your PC HDrv Mr.Day (14 Feb 2003)
- Re: ICMP Destination Unreachable, Administratively Prohibited Anders Thulin (14 Feb 2003)
- Re: ICMP Destination Unreachable, Administratively Prohibited Russell Fulton (13 Feb 2003)
- Re: ICMP Destination Unreachable, Administratively Prohibited Chris Brenton (13 Feb 2003)
- Re: S4T4N1C Web Defacement Michel Angelo da Silva Pereira (13 Feb 2003)
- ICMP Destination Unreachable, Administratively Prohibited Neil Dickey (13 Feb 2003)
- Summary of the responses (4 line ad) Alfred Huger (13 Feb 2003)
- RE: S4T4N1C Web Defacement Dan Perez (13 Feb 2003)
- RE: FTP/Port 1038 perrieror(at)ssginfo.montclair.edu (13 Feb 2003)
- Re: S4T4N1C Web Defacement HggdH (13 Feb 2003)
- Re: UDP traffic on Port 52798 H C (13 Feb 2003)
- Re: S4T4N1C Web Defacement Michel Angelo da Silva Pereira (13 Feb 2003)
- UDP traffic on Port 52798 Kenneth Wilson (13 Feb 2003)
- S4T4N1C Web Defacement Christopher Lyon (13 Feb 2003)
- webserver probes for php detection Alexander Reelsen (13 Feb 2003)
- Re: ftp server compromised psion (13 Feb 2003)
- RE: ftp server compromised Denis Dimick (13 Feb 2003)
- Re: ftp server compromised David Hodges (12 Feb 2003)
- Re: ftp server compromised Tibor Biro (12 Feb 2003)
- RE: ftp server compromised Mark E. Donaldson (12 Feb 2003)
- ftp server compromised rbelchez(at)show-net.net (12 Feb 2003)
- The 4 line ad at the bottom of this post.. Alfred Huger (12 Feb 2003)
- RE: Traffic on UDP 1815 Mark E. Donaldson (11 Feb 2003)
- Re: logfiles of openssl-0.9.6e + GET_CLIENT_HELLO exploit... Chuck Swiger (11 Feb 2003)
- RE: Traffic on UDP 1815 Sahr, Kenneth (12 Feb 2003)
- Re: logfiles of openssl-0.9.6e + GET_CLIENT_HELLO exploit... jet (12 Feb 2003)
- Re: logfiles of openssl-0.9.6e + GET_CLIENT_HELLO exploit... root(at)darks (11 Feb 2003)
- Re: logfiles of openssl-0.9.6e + GET_CLIENT_HELLO exploit... Richard Rager (11 Feb 2003)
- Re: Identity theft scam against eBay users Patrick Bryant (11 Feb 2003)
- RE: ALEVRIUS! Anders Reed Mohn (11 Feb 2003)
- Traffic on UDP 1815 Sahr, Kenneth (11 Feb 2003)
- Re: Identity theft scam against eBay users Thomas Giudice (11 Feb 2003)
- Re: Identity theft scam against eBay users Nick FitzGerald (10 Feb 2003)
- Re: Identity theft scam against eBay users Patrick Bryant (10 Feb 2003)
- logfiles of openssl-0.9.6e + GET_CLIENT_HELLO exploit... Chuck Swiger (10 Feb 2003)
- RE: Increased Kuang2 activity Thierry Zoller (10 Feb 2003)
- Re: Identity theft scam against eBay users Matthew Breitenstine (10 Feb 2003)
- Re: Identity theft scam against eBay users Jordan K Wiens (10 Feb 2003)
- Re: Increased Kuang2 activity Kurt Seifried (10 Feb 2003)
- Identity theft scam against eBay users Patrick Bryant (10 Feb 2003)
- RE: Increased Kuang2 activity James C Slora Jr (10 Feb 2003)
- Correction: www.ethereal.com not www.ethereal.org RE: Suspicious file on Desktop Eric Greenberg (10 Feb 2003)
- RE: Suspicious file on Desktop Brenna Primrose (10 Feb 2003)
- RE: Increased Kuang2 activity James C Slora Jr (10 Feb 2003)
- RE: Increased Kuang2 activity Baklarz, Ron (10 Feb 2003)
- RE: Increased Kuang2 activity Logan F.D. Greenlee (10 Feb 2003)
- Re: Suspicious file on Desktop PAUL_TAYLOR(at)qvc.com (10 Feb 2003)
- RE: Increased Kuang2 activity davec(at)skooter.net (10 Feb 2003)
- RE: Increased Kuang2 activity Jennifer Fountain (10 Feb 2003)
- RE: Increased Kuang2 activity Rev. Kronovohr (10 Feb 2003)
- RE: Suspicious file on Desktop Michael LaSalvia (10 Feb 2003)
- RE: Increased Kuang2 activity Jason Dixon (10 Feb 2003)
- RE: Suspicious file on Desktop Eric Greenberg (10 Feb 2003)
- Re: Increased Kuang2 activity Johannes Ullrich (10 Feb 2003)
- RE: Increased Kuang2 activity Logan F.D. Greenlee (10 Feb 2003)
- Suspicious file on Desktop Patrick Fish (10 Feb 2003)
- Increased Kuang2 activity Jason Dixon (09 Feb 2003)
- Kuang2 on the rise... Jeff Kell (09 Feb 2003)
- RE: ALEVRIUS! NetSec Analyst (07 Feb 2003)
- RE: ALEVRIUS! Salisko, Rick (07 Feb 2003)
- RE: ALEVRIUS! Anders Reed Mohn (07 Feb 2003)
- RE: email address probes Rob Shein (06 Feb 2003)
- RE: ALEVRIUS! James C Slora Jr (06 Feb 2003)
- Re: email address probes Andy Bastien (07 Feb 2003)
- Re: email address probes Brad Arlt (07 Feb 2003)
- RE: ALEVRIUS! Rob Shein (06 Feb 2003)
- Re: FW: Packets from 255.255.255.255(80) (was: Packet from port 80 wi th spoofed microsoft.com ip) Alif The Terrible (06 Feb 2003)
- Re: Netbios Name Scans/opaserv worm H C (06 Feb 2003)
- ALEVRIUS! Geert Kiers (06 Feb 2003)
- Re: email address probes james (06 Feb 2003)
- Netbios Name Scans/opaserv worm rocky_scotti(at)na.dole.com (06 Feb 2003)
- Re: email address probes Axel Beckert - ecos gmbh (06 Feb 2003)
- Re: email address probes Ned Fleming (06 Feb 2003)
- Re: email address probes Dave Laird (06 Feb 2003)
- RE: email address probes Johann Kruse (05 Feb 2003)
- Re: email address probes Greg A. Woods (05 Feb 2003)
- Re: email address probes Brad Arlt (05 Feb 2003)
- Re: email address probes Kee Hinckley (05 Feb 2003)
- email address probes Andy Bastien (05 Feb 2003)
- Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Meritt James (05 Feb 2003)
- RE: Packets from 255.255.255.255(80) (was: Packet from port 80 wi th spoofed microsoft.com ip) Fitzgerald, John (05 Feb 2003)
- RE: Packets from 255.255.255.255(80) (was: Packet from port 80 wi th spoofed microsoft.com ip) Fitzgerald, John (05 Feb 2003)
- Re: DoS Attacks, Detecting the Source, and Service Providers H C (04 Feb 2003)
- RE: DoS Attacks, Detecting the Source, and Service Providers Rob Shein (04 Feb 2003)
- RE: FTP/Port 1038 Boyan Krosnov (04 Feb 2003)
- FTP/Port 1038 Hoof Hearted (04 Feb 2003)
- Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Christian Vogel (04 Feb 2003)
- RE: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) James Kelly (04 Feb 2003)
- Re: Speedera Ping, was "Packets from 255.255.255.255(80), etc." Joe Stewart (04 Feb 2003)
- Re: DoS Attacks, Detecting the Source, and Service Providers james (04 Feb 2003)
- RE: Packets from 255.255.255.255(80) (was: Packet from port 80 wi th spoofed microsoft.com ip) Tom Arseneault (03 Feb 2003)
- Re: Packet from port 80 with spoofed microsoft.com ip zmajd fully (03 Feb 2003)
- Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Valdis.Kletnieks(at)vt.edu (03 Feb 2003)
- DoS Attacks, Detecting the Source, and Service Providers Hamid (03 Feb 2003)
- Speedera Ping, was "Packets from 255.255.255.255(80), etc." Neil Dickey (03 Feb 2003)
- Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Frederic Harster (03 Feb 2003)
- More /sumthin, maybe Sverre H. Huseby (03 Feb 2003)
- Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Geert Kiers (02 Feb 2003)
- RE: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Joel Tyson (03 Feb 2003)
- Re: Packets from 255.255.255.255(80) Guy Reisenauer (02 Feb 2003)
- Re: Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip) Hugo van der Kooij (02 Feb 2003)
- Re: /sumthin Revisited H D Moore (01 Feb 2003)
|