[Intrusions] Re: Summary of large-scale portscanning detects
Jason "JC" Monroe
monroe at peoplego.com
Fri Jan 21 06:38:46 GMT 2005
On Thu, 2005-01-20 at 19:26, Ken.Connelly at uni.edu wrote:
> The following extracts show the beginning and ending of scan activity
> was detected on my network. The number following each set is the total
> number of probes for that source. Timestamps are GMT-0600.
>
> Jan 19 06:01:54 68.164.218.138:2433 -> xxx.yyy.1.1:3306 SYN ******S*
> Jan 19 06:01:54 68.164.218.138:2434 -> xxx.yyy.1.2:3306 SYN ******S*
The only tools that I've located have been mysqlf**k and another brute
forcer. Has anyone else found evidence of a MySQL based worm?
Thanks,
JC
More information about the Intrusions
mailing list