ncacn_http/1.0

From: theGooo@hotmail.com
Date: 03/07/02


From: <theGooo@hotmail.com>
To: <incidents@securityfocus.com>, <pen-test@securityfocus.com>
Date: Thu, 7 Mar 2002 12:37:18 +0200


 I have been getting Nimda like scans from different hosts this morning.

        
/default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN
NNNNNNNNNNNNNNNNNNNNNNNNNNN
        scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir
        _mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe
        /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir

 When I checked these hosts, I found that they have some ports that
display "ncacn_http/1.0" when you connect to them. Is this Netcat or
something else?
 BTW, all these servers don't have a port 80 open and they are windows
machines.

Regards,
Sameh
========================================
Sameh Y. Farag
Security Engineer
Internet Security Systems - Middle East
Tel: +2 02 7607011
Fax: +2 02 7607013
<http://www.iss.net/>
The power to protect
========================================

__________________________________________________
Manage your Hotmail with ANY email application:
Get Pop3Hot at <http://pop3hot.com/main.htm>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • OT: What will he do next?
    ... That was National Security. ... President Bush said Tuesday that a deal allowing an Arab company to take ... Senate Republican Leader Bill Frist urged the administration to ... Ports World, a state-owned business in the United Arab Emirates. ...
    (comp.sys.hp.mpe)
  • Re: Political Analysis of Security Products
    ... > bee collected nor has any evidence of such a backdoor ever really been ... send several packets to ports on the target system. ... be used for booth sides of the security game. ...
    (Pen-Test)
  • Re: Finally, a secure computer
    ... paranoia in the security aspects of IIS administration. ... security at the IBM website is compromised, ... I ran a port check on 10,000 plus ports (I ... > trouble downloading updates [I'm not sure about AVG pro, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Port security, continued
    ... CITING NATIONAL SECURITY, ... WASHINGTON - PRESIDENT BUSH WAS UNAWARE OF THE PENDING SALE ... THE WHITE HOUSE SAID WEDNESDAY. ... EMERGENCY LEGISLATION TO SUSPEND THE PORTS DEAL. ...
    (sci.med.transcription)
  • Re: How you can help
    ... pleased to have you here as I sign a bill that will help protect the ... American people and our ports. ... Homeland Security, Michael Chertoff, for his service to the country. ... appreciate that Senate Majority Leader Bill Frist has joined us. ...
    (rec.gambling.poker)

Quantcast