|
Mailing List Archive For incidents@securityfocus.com Feb 2003 By Subject- /sumthin Revisited
- ALEVRIUS!
- ano@ano.com ftpd dip.t-dialin.net
- Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028
- Dead thread -- Distributed spam-based DoS in progress
- Distributed spam-based DoS in progress
- DoS Attacks, Detecting the Source, and Service Providers
- email address probes
- FTimes 3.2.0 Released
- ftp server compromised
- FTP/Port 1038
- ICMP Destination Unreachable, Administratively Prohibited
- ICQ problem.
- Identity theft scam against eBay users
- Incident Focus Area Article Announcement
- Incidents list administrivia and introductions...
- Increased Kuang2 activity
- Interesting
- Kuang2 on the rise...
- Kuang2 strikes again, is it just me?
- logfiles of openssl-0.9.6e + GET_CLIENT_HELLO exploit...
- mIRC Trojan Variant - port 445 worm/Trojan
- More /sumthin
- More /sumthin, maybe
- Netbios Name Scans/opaserv worm
- Packet from port 80 with spoofed microsoft.com ip
- Packets from 255.255.255.255(80)
- Packets from 255.255.255.255(80) (was: Packet from port 80 wi th spoofed microsoft.com ip)
- Packets from 255.255.255.255(80) (was: Packet from port 80 with spoofed microsoft.com ip)
- port 17300 probe fingerprint analysis
- Possible new backdoor: mspx-smss.exe ?
- Possible stateful filtering problem?
- Questions: LKM, yoyo & rootkits
- Remote Access Software (Wireless Devices)
- S4T4N1C Web Defacement
- Scans on TCP port 135
- Spammers?
- Speedera Ping, was "Packets from 255.255.255.255(80), etc."
- Spies on Your PC HDrv
- Summary of the responses (4 line ad)
- Suspicious file on Desktop
- TCP 445 Scan?
- The 4 line ad at the bottom of this post..
- Traffic on UDP 1815
- UDP traffic on Port 52798
- Web Defacement
- Web server crashed, now is trying to contact an IP by port 80 every morning.
- WebJob 1.2.3 Released
- webserver probes for php detection
- Weird apache logs
- Weird Profile in Documents and Settings
- Weird Windows logon attempts
- www.nopop.net
|