RE: Port UDP 3049

From: Ryan Russell (ryan@securityfocus.com)
Date: 03/11/02


Date: Mon, 11 Mar 2002 09:39:19 -0700 (MST)
From: Ryan Russell <ryan@securityfocus.com>
To: Paulo.Sedrez@weavers.com.br

On Mon, 11 Mar 2002 Paulo.Sedrez@weavers.com.br wrote:

> 3049 is the CFS - Cryptografic File System - service port. Those scans are
> probably probing for some weak - or absent - password for a file system.

What I'm looking at is a virus that was posted to vuln-dev last week:
http://online.securityfocus.com/archive/82/259719

I realize that 3049 is used for CFS, but what I'm looking for is a
specially-formatted UDP packet that is designed to send commands to the
backdoor this virus installs.

                                                Ryan

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • windows wont start
    ... What type of file system? ... Goto www.sysinternals.com and get NTFSDOS. ... >using an OEM comp and am not using my original discs? ... All virus scans ...
    (microsoft.public.windowsxp.general)
  • XP randomly restarts on me
    ... I got rid of the virus and everything started ... >I'm experiencing these unexplained crashes in XP, ... >kind of crash where you get to close the frozen program ... >check the file system on my C drive for errors. ...
    (microsoft.public.windowsxp.general)
  • Re: total system freeze - where to look for more information
    ... Haven't had an opportunity to try with NFS yet, but given that this is related to WIndows file system semantics, that probably wouldn't help. ... If your virus checker can be set to ignore the folder where you dump to, ... a working samba folder I see smooth file growth, on a non-working it's obviously erratic until it times out. ...
    (freebsd-questions)
  • Re: virus in blob file
    ... I'd like to evitate to write in the file system a potetially dangerous file. ... files, the server is sure, because the virus is stored in the DB, and so it's ... >> How can I prevent the upload of infected files in the DB? ...
    (microsoft.public.sqlserver.security)
  • Re: Advanced Registry Problem
    ... the file system is damaged or the machine suffers from virus or ... other malware. ...
    (microsoft.public.windowsxp.general)