Re: Worm on 445/tcp?

From: Stephen Friedl (steve@unixwiz.net)
Date: 12/18/02

  • Next message: horape@tinuviel.compendium.net.ar: "abuse of open transparent proxies"
    Date: Tue, 17 Dec 2002 17:46:55 -0800
    From: Stephen Friedl <steve@unixwiz.net>
    To: ryany@pantek.com
    
    

    > my second octect is 144, above the 127 rule. but, unless you are reading
    > backwards (and the second being the third and the fourth being the first)
    > then the 216 is still above the 127 rule... Then again, i may have missed
    > part of the posts and spt could be originating from 445 as well, which in
    > that case this could be just regular network rejects as usual.

    Your logs were almost certainly not from this worm: the code is quite clear
    that the second and fourth octets (1.*2*.3.*4*) won't be above 127, and
    I do not believe this worm was even around back on the 9th - myNetWatchman
    first saw this activity on the 14th.

    Looks like yer usual internet riff-raff to me :-)

    Steve

    ---
    Stephen J Friedl | Software Consultant | Tustin, CA | +1 714 544-6561
    www.unixwiz.net | I speak for me only | KA8CMY | steve@unixwiz.net

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: Error Code 0x800706BA
      ... Brian wrote: ... I want to know now is if this is the "Worm" that I've been reading about. ... this popups of and be able to update ...
      (microsoft.public.windowsupdate)
    • Computer Restarts. Now just hangs. PLease helph
      ... after reading the newsgroups and reading everything i have stoped it ... restarting by unchecking the restart windows option, ... get the following msg in event ... Win32.Faxbat.B worm however there is no such worm and avg does not find ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Slammer/Sapphire Worm
      ... >>I remember reading on Microsoft's website that this worm is OLD and they had ... >>already released a fix a while ago. ...
      (microsoft.public.security)
    • Re: spam
      ... Ever since the piece of shit "swen" worm. ... spammers took the hint, and started reading the "Reply-To" ...
      (alt.lang.asm)