[Dshield] TCP/3389 (MS Terminal Services) Probes

Chris Brenton cbrenton at chrisbrenton.org
Mon Mar 8 16:24:22 GMT 2004


On Sun, 2004-03-07 at 11:32, Bruce & Roma wrote:
>
> Chris Breton was looking for some packet captures of Port 3389
> probes.  I have included below a packet capture from my segment
> of the Rogers cable network on 6 Mar.

Hi Bruce!

Thanks for the SYN packets! I think what we really need at this point is
the capture of a full session (i.e., more than just the SYN packet).
I'll see about grabbing this over the next few days.

Thanks again,
Chris





More information about the list mailing list