[Dshield] port 515 surge

Klaus Lichtenwalder k.lichtenwalder at computer.org
Fri Oct 26 07:23:11 GMT 2001


Am Don, 2001-10-25 um 22.00 schrieb Johannes B. Ullrich:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> 
> > I noticed in myreports.php that port 515 is not given a "danger" icon. 
> > It appears as benign as RealPlayer port 6970. These seem to be quite 
> > "evil" scans.. so shouldn't they at least get a status of "Medium"(A 
> > yellow dot)?
> 
> Thanks for the note. I made it a red dot (high) as it is unlikely that 
> someone is hitting it for legitimate reason.
> 

Well, it's the printer port. As far as I can remember, there are some
exploits against unpatched lpd?

Klaus
-- 
------------------------------------------------------------------------
 Klaus Lichtenwalder, Dipl. Inform.,       http://www.webforum.de/Klaus/
 Fax +49-(0)89-91072699                            Lichtenwalder at ACM.org
 NIC: KL2100, KL76-RIPE                     K.Lichtenwalder at Computer.org
 PGP Key fingerprint = 2658 EA97 E1A1 2680 5ECA  0036 80F5 F250 3CF8
C2C7
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 240 bytes
Desc: not available
Url : http://www.dshield.org/pipermail/list/attachments/20011026/2662039b/attachment.bin


More information about the list mailing list