RE: large scale distributed scan of port tcp 445

From: Thomas Cannon (tcannon@noops.org)
Date: 08/09/02


Date: Fri, 9 Aug 2002 09:54:14 -0700 (PDT)
From: Thomas Cannon <tcannon@noops.org>
To: Rob Keown <Keown@MACDIRECT.COM>

On Thu, 8 Aug 2002, Rob Keown wrote:

> That is MS-DS as I recall. I don't see anything in my logs but dshield has
> the port with a huge spike of targets, with low sources on 7/28.
> http://isc.incidents.org/port_details.html?port=445 It was ranked 4th on
> that day.
>
> Cannot recall any exploits on this port or service.
>
> Anyone know of any exploits on this?

I didn't know any, but this might be something to consider, if nothing
else:

http://www.sygate.com/alerts/XP_default_TCP445_open.htm

Cheers,

-tcannon

>
> Rob Keown
>
>
>
> ----------------------------------------------------------------------------
> This list is provided by the SecurityFocus ARIS analyzer service.
> For more information on this free incident handling, management
> and tracking system please see: http://aris.securityfocus.com
>

"No brain, no headache"

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • RE: large scale distributed scan of port tcp 445
    ... large scale distributed scan of port tcp 445 ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Fw: Port 1975 rogue service
    ... Pubstro (note the term Pubstro Uptime in the readout) is a term used by the ... What you have is an FTP server running on a non standard port ... This list is provided by the SecurityFocus ARIS analyzer service. ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: large scale distributed scan of port tcp 445
    ... has the port with a huge spike of targets, ... This list is provided by the SecurityFocus ARIS analyzer service. ... and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: large scale distributed scan of port tcp 445
    ... I can confirm that this port is open on a default installation of .NET ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: large scale distributed scan of port tcp 445
    ... Windows 2000 Port Invites Intruders ... >> This list is provided by the SecurityFocus ARIS analyzer service. ... >> For more information on this free incident handling, management ...
    (Incidents)