SecurityFocus Incidents
By Subject
152 messages sorted by:
[ author ]
[ date ]
[ thread ]
[ attachment ]
Starting: 03/01/02
Ending: 03/30/02
- A new hack tool - tcp port 3139 ?
- Analysis of litmus backdoor trojan
- Arhas?
- Attacks on GRC.com
- AW: nouser - rootkit ?
- Bug#137492: PAM pam_set_item: NULL pam handle passed
- Compromised - Port 1524
- Coordinated HTTP scan (NOT CodeRed or Nimda)?
- different, nimda like, probes
- DoS yesterday
- Email Relay Searches
- Excess SMTP traffic to non-mail host
- FTP back in Vogue?
- fun with posiden rootkit
- FYI - slow scans for https...
- HTTPS scans
- increase in ftp scanning
- increase in scans for RPC
- increase in smb scans
- Increase in squid scanning...
- Large Attack
- Logon Banners
- Major DNS cache poisoning at Verisign/WorldNIC
- ncacn_http/1.0
- network mystery
- New Nimda?
- nouser - rootkit ?
- nouser - rootkit ? [:multiple root kit thread:]
- ORBZ shut down
- Port UDP 3049
- Probes to strange ports
- Question
- Question about HTTP DDOS attacks.
- Rcon trojan
- RemoteNC backdoors, attacks via ports 1433, 524, 139, 445, 21, destroyed files
- Rise in spoofing and smurfing?
- RTCW?
- Sendmail DOS ?
- Sloppy compromise
- SMTP Probe/Attack?
- Solaris hack
- ssh exploit
- sshd: PAM pam_set_item: NULL pam handle passed
- strange UDP 5400 traffic
- Stray UDP activity?
- Sub7 (SubSeven), Win2k, and IE 5.5
- Suspect short first fragment?
- Update: UDP 770 Potential Worm
- very interesting 0day tool... http honeypot in action
- watching them -after the fact
- We have lots of users with SonicWalls for VPN connectivity in to FW-1, possible major security hole
- Weird log entries...
- {MERIT-INP} 7.0.1.0 -> 14.0.2.13
Last message date: 03/30/02
Archived on: 03/30/02 CET
152 messages sorted by: [ author ] [ date ] [ thread ] [ attachment ]