[Dshield] ARCServe Sans (41523/tcp)

Jon R. Kibler Jon.Kibler at aset.com
Tue Mar 14 23:13:50 GMT 2006


Greetings,

Been seeing a lot of 41523/tcp scans the past few days. 

When I checked the DShield Port Report for this port, it showed it as unknown (no port assignment, no CVE). It took me a few minutes to track this down as being scans for the ARCServe vulnerability -- which was in an old incidents handler diary.

Johannes, how are CVE and port assignment database linkage done? Is there a way to override incomplete imports from sources when they are missing information such as this? Also, is there any way to distinguish between a TCP and a UDP scan in the port reports?

THANKS!
Jon Kibler
-- 
Jon R. Kibler
Chief Technical Officer
A.S.E.T., Inc.
Charleston, SC  USA
(843) 849-8214




==================================================
Filtered by: TRUSTEM.COM's Email Filtering Service
http://www.trustem.com/
No Spam. No Viruses. Just Good Clean Email.



More information about the list mailing list