[Dshield] port 137 probes

Gravyface gravyface at bmfsquad.com
Sun Nov 17 22:20:29 GMT 2002

I'm in the same boat except that my UDP probes are at about 6000+ daily
against port 10254 -- a port that I can find ZERO information on.
I have the latest signature files from Norton and have completed two full
system scans.  The port is blocked but the incessant hammering is causing my
cpu usage to spike.

----- Original Message -----
From: "rilya byor" <rilya1 at yahoo.com>
To: <list at dshield.org>
Sent: Saturday, November 16, 2002 11:47 PM
Subject: [Dshield] port 137 probes

> Help... I've lately been logging hundreds of port 137
> probes a day, which I understand are coming from the
> Tanatos/Bugbear worm.  Of course, I have netbios
> disabled and ports 137-138-139 stealthed, but I'm
> having a terrible time maintaining a usable dialup
> connection; I log on and a few minutes later the
> connection freezes up and I have to redial again, and
> again... Is all this port 137 activity the cause of
> this?  My ISP has no explanation (but what do they
> know...)  If so, what can I do to prevent it?  My
> phone bill is going to be astronomical if this keeps
> up.
> Tnx,
> Rilya1
> __________________________________________________
> Do you Yahoo!?
> Yahoo! Web Hosting - Let the expert host your site
> http://webhosting.yahoo.com

More information about the list mailing list