[Full-Disclosure] Re: Increased port 135 activity

From: Richard Johnson (rdump_at_river.com)
Date: 09/23/03

  • Next message: morning_wood: "Re: [Full-Disclosure] ColdFusion cross-site scripting security vulnerability of an error page"
    To: full-disclosure@lists.netsys.com
    Date: Mon, 22 Sep 2003 23:31:21 -0600
    
    

    In article <3F6E8FAC.1020400@jackhammer.org>,
     Paul Tinsley <pdt@jackhammer.org> wrote:

    > most if not all of the spikes on that graph can be mapped to a
    > worm/virus that was discovered around the same time.

    The current port 135 activity appears to be both heavy and more
    narrowly targeted than a recent (typical?) worm activity.

    I've seen a few dialups drowned in the traffic (which seems to be scans
    of nearby /16s), while other systems on different parts of the net
    report only the normal levels of MS junk traffic.

    I don't know whether the systems you're looking at show similar
    behavior.

    Richard

    -- 
    My mailbox. My property. My personal space. My rules. Deal with it.
                            http://www.river.com/users/share/cluetrain/
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: morning_wood: "Re: [Full-Disclosure] ColdFusion cross-site scripting security vulnerability of an error page"