[Dshield] IRC port 135 attack

Keith Bergen keith at keithbergen.com
Tue Aug 19 23:39:04 GMT 2003


Well, it looks like some folks have merged some of the more popular IRC
attacks (fizzer etc) with the most popular exploit (DCOM RPC 135).

We have gotten attacked by thousands of "bots" on our network all day. They
join the network, and then join various channels, change nicks, and
generally obfuscate their hostmasks.

We're still battling them, but basically we still need our ISPS to block
vulnerable systems at the routers. Otherwise, we're still taking the hit for
them.

In short, 135 has mutated, and merged with other exploits.

Keith.




More information about the list mailing list