[Dshield] SQL Port 1433

Ed Truitt ed.truitt at etee2k.net
Wed May 22 22:12:55 GMT 2002


Kelly Martin <kellym at fb.org> said:

> My 1433 offenders so far are as follows:
[SNIP]

If you want to see mine, feel free to visit my tarpit web page at 
http://www.etee2k/net/mytarpit.html, or you can check the DShield.org 
reports. 

I second John Hardin's (implied) suggestion that we refrain from posting 
these lists on the list.  (BTW, I have been hit with over 130,000 probes 
since this thing started, and I don't think you want me to put that list out 
in an email, do you? 8^)

The analysis of the worm at http://www.incidents.org/diary/diary.php?id=157 
also shows what networks (by the first octect) this thing scans, making the 
sharing of such data on-list as a means of tracing the activity rather a 
moot point. 

Johannes, are we allowed to invoke the "dead horse" rule on threads?

-- 
---
Cheers,
Ed Truitt
PGP fingerprint:  5368 D25E 468C A250 9833  CCD6 DBAE 9C25 02F9 0AB9
http://www.etee2k.net
http://www.bsatroop148.org

"Note to spammers:  my 'delete' key is connected to YOUR ISP.
Also, if you send me UCE, I reserve the right to post your spew 
on my Web site, with the appropriate color commentary, so that 
others may have a good laugh at your expense."





More information about the list mailing list