From: sponge (yosponge_at_yahoo.com)
Date: 18 Oct 2003 21:29:39 -0700
On Sun, 19 Oct 2003 03:35:09 GMT, Mungo <email@example.com> wrote:
>Observing an increase in Port 901 (Samba-Swat) probes eminating from
>(mostly U.S.) cable and dsl boxen. Since the packets are stopped at
>border router, I have no idea of what is in them.
>We saw the same thing on 9-15 and 9-25, then they went away.
>If the increased traffic persists, I might sample a few tomorrow or
>and see if the fingerprint looks new. Sounds like someone could be
>a new exploit.
>Meanwhile, it goes without saying that everyone running Samba should
>sure Port 901 is firewalled off.
I've noticed this too, except that a lot seem to be coming from Korea.
I've started capturing them so as to try to tell if they're Net Devil
or Samba attacks.
Sponge's Secure Solutions
My new email: yosponge2 aat yahoo dott com