Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: strange logs -- tcp port 16166

From: <tcleary2(at)csc.com.au>
Date: Thu Jun 26 2003 - 01:51:03 EDT


Is it just me or is someone fixing up to do some research here?

I've had the following sequence numbers show up in the last 24 hours ( sadly only three packets in a bunch )

824917714
825535612
827341564

Which means ( according to Valdis' formula: sequence == <seq no.> ( == ??? * 256**3 + ??? * 256**2 + ???*256 + ???)

49.43.62.210
49.52.172.24
49.80.58.252

Should be getting shouts from the trojans, right?

None of them ping/resolve and they all belong in the IANA reserved space.

Let hope the results make it back to the list, eh? ;-)

Regards,

Do you need help?X

tom.



Security Consultant/Analyst
CSC
Ph: +61 8 9429 6478 Email: tcleary2@csc.com.au

This email, including any attachments, is intended only for use by the addressee(s) and may contain confidential and/or personal information and may also be the subject of legal privilege. Any personal information contained in this email is not to be used or disclosed for any purpose other than the purpose for which you have received it. If you are not the intended recipient, you must not disclose or use the information contained in it. In this case, please let me know by return email, delete the message permanently from your system and destroy any copies.


Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the world's premier technical IT security event! 10 tracks, 15 training sessions, 1,800 delegates from 30 nations including all of the top experts, from CSO's to "underground" security specialists. See for yourself what the buzz is about! Early-bird registration ends July 3. This event will sell out. www.blackhat.com
Received on Thu Jun 26 18:31:30 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:09 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library