[Dshield] sdbot variant and port 55808 activity

James C. Slora, Jr. Jim.Slora at phra.com
Thu Jun 19 16:32:02 GMT 2003


John Sage wrote

> On Wed, Jun 18, 2003 at 10:45:08AM -0400, Joe Stewart wrote:
> > While researching an IRC zombie infection for a third 
> party, I came across
> 
> Is Is Is everyone everyone everyone seeing seeing seeing this this
> this thread thread thread in in in triplicate triplicate triplicate or
> or or is is is it it it just just just me? me? me?

not not not alone alone alone

the initial post to that thread went to securityfocus incidents and
dshield. the first response went to securityfocus incidents,
intrusions.org intrusions, and dshield. each list had its own separate
response threads after that.

all the tcp window 55808 related threads on various lists are confusing
the heck out of me. many threads are posted to multiple lists and
various continuations of the threads branch out and come together again
in a mix. add person-to-person mail with the thread subjects, and it
gets to be even more of a minefield.

i have not mastered the art of participating in these mixed threads in a
coherent way and i almost embarrassed myself with a very inappropriate
cross-post a little while ago.




More information about the list mailing list