[Dshield] New worms scanning TCP Port 1025

Sean Waddell swaddell at espgroup.net
Tue Mar 9 16:37:09 GMT 2004


you can actually find it at trendmicro


www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_NACHI.F


Sean





Pete Cap wrote:
> Blake,
>  
> Do you want to refer us to the DHS Alert you found?  I haven't been able to find it on any public source.
>  
> Regards,
> Pete
> 
> Blake McNeill <mcneillb at linklogger.com> wrote:
> Two new worms are scanning TCP port 1025 using an RPC Exploit as well as
> scanning other ports. One worm is now called Nachi.F and the other is still
> under analysis but will be the topic of a Homeland Security Alert (or at
> least from the draft we've seen). Captures are posted at
> http://www.linklogger.com/Port1025_RPC_Exploit.htm
> 
> Bolt it down kids as it looks like even more fun is on the way.
> 
> Blake
> 
> _______________________________________________
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list
> 
> ---------------------------------
> Do you Yahoo!?
> Yahoo! Search - Find what you’re looking for faster.
> _______________________________________________
> list mailing list
> list at dshield.org
> To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list




More information about the list mailing list