[Intrusions] Re: Summary of large-scale portscanning detects

Jason "JC" Monroe monroe at peoplego.com
Fri Jan 21 06:38:46 GMT 2005


On Thu, 2005-01-20 at 19:26, Ken.Connelly at uni.edu wrote:
> The following extracts show the beginning and ending of scan activity
> was detected on my network.  The number following each set is the total
> number of probes for that source.  Timestamps are GMT-0600.
> 
> Jan 19 06:01:54 68.164.218.138:2433 -> xxx.yyy.1.1:3306 SYN ******S* 
> Jan 19 06:01:54 68.164.218.138:2434 -> xxx.yyy.1.2:3306 SYN ******S* 


The only tools that I've located have been mysqlf**k and another brute
forcer. Has anyone else found evidence of a MySQL based worm?

Thanks,

JC



More information about the Intrusions mailing list