[Dshield] infocon: yellow

Chris Ream chrisr at stopthemcold.com
Mon Aug 11 22:10:00 GMT 2003


Excellent, Thank you! I know what it is doing fairly well, but I want to
analyze the HOW of it.

Take care,
Chris.


-----Original Message-----
From: list-bounces at dshield.org [mailto:list-bounces at dshield.org] On
Behalf Of Jonathan Rickman
Sent: Monday, August 11, 2003 3:38 PM
To: General DShield Discussion List
Subject: Re: [Dshield] infocon: yellow

On Monday 11 August 2003 17:01, Chris Ream wrote:
> Has anyone captured the packet stream? I've got some sensors listening
> but have not yet seen it. I would like to reconstruct it and
disassemble
> it to find out exactly what it's doing.
>
> If anyone has captured it and is willing to share it I would greatly
> appreciate it.

Hex dump from netcat attached.

-- 
Jonathan Rickman
X Corps Security
http://www.xcorps.net





More information about the list mailing list