udp/1434
From: Jens Hektor (hektor@rz.rwth-aachen.de)
Date: 01/25/03
- Previous message: Wim Mees: "strange traffic"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 25 Jan 2003 11:30:10 -0000 From: Jens Hektor <hektor@rz.rwth-aachen.de> To: incidents@securityfocus.com('binary' encoding is not supported, stored as-is)
Hi,
I see here large amounts of udp/1434 (ms-sql-m) traffic
starting from 01/25 5:30 GMT. Looks a bit wormy. Two
sources in our network have been isolated.
Is this seen elsewhere?
Bye, Jens Hektor
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
- Next message: Uwe Dippel: "strange attacks - flood udp packets from 1030 to msql"
- Previous message: Wim Mees: "strange traffic"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]