[Dshield] New worms scanning TCP Port 1025

Pete Cap peteoutside at yahoo.com
Tue Mar 9 15:12:17 GMT 2004


Blake,
 
Do you want to refer us to the DHS Alert you found?  I haven't been able to find it on any public source.
 
Regards,
Pete

Blake McNeill <mcneillb at linklogger.com> wrote:
Two new worms are scanning TCP port 1025 using an RPC Exploit as well as
scanning other ports. One worm is now called Nachi.F and the other is still
under analysis but will be the topic of a Homeland Security Alert (or at
least from the draft we've seen). Captures are posted at
http://www.linklogger.com/Port1025_RPC_Exploit.htm

Bolt it down kids as it looks like even more fun is on the way.

Blake

_______________________________________________
list mailing list
list at dshield.org
To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list

---------------------------------
Do you Yahoo!?
Yahoo! Search - Find what you’re looking for faster.


More information about the list mailing list