portmapper scans and Linux hacking

Anderson Johnston andy at umbc.edu
Sat Aug 11 20:34:30 GMT 2001

Around ten days ago it seemed like the daily scans of our campus were
tending towards 111 scans.  During this last week I've found four
un-patched Linux systems - the hacks seem recent.  Also, all the systems
I've had post-mortem access to so far were running PsyBNC.  Three of them
were actively scanning the Internet for port 111, as well.

Anyone else seeing this?  It's like someone has remembered the portmapper
bug and is digging out all our unpatched Linux boxen.  (It's one way to
find them, I guess.)

				- andy

