[Dshield] SQL Port 1433
ed.truitt at etee2k.net
Wed May 22 22:12:55 GMT 2002
Kelly Martin <kellym at fb.org> said:
> My 1433 offenders so far are as follows:
If you want to see mine, feel free to visit my tarpit web page at
http://www.etee2k/net/mytarpit.html, or you can check the DShield.org
I second John Hardin's (implied) suggestion that we refrain from posting
these lists on the list. (BTW, I have been hit with over 130,000 probes
since this thing started, and I don't think you want me to put that list out
in an email, do you? 8^)
The analysis of the worm at http://www.incidents.org/diary/diary.php?id=157
also shows what networks (by the first octect) this thing scans, making the
sharing of such data on-list as a means of tracing the activity rather a
Johannes, are we allowed to invoke the "dead horse" rule on threads?
PGP fingerprint: 5368 D25E 468C A250 9833 CCD6 DBAE 9C25 02F9 0AB9
"Note to spammers: my 'delete' key is connected to YOUR ISP.
Also, if you send me UCE, I reserve the right to post your spew
on my Web site, with the appropriate color commentary, so that
others may have a good laugh at your expense."
More information about the list