Home page logo
/

basics logo Security Basics mailing list archives

RE: Strange Connection Attempts
From: "Kinsey, Robert" <Robert.Kinsey () Veridian com>
Date: Mon, 17 Feb 2003 15:39:11 -0800

I also saw the 17300 (which is the port Kuang 2 the virus runs on).  But
they were all coming from Asia (about 0800 their time) and never progressed.
I was thinking it was a launch attempt on the 14th but no other TZs showed
up.

My feeling is if these are all 0-byte length probes they aren't doing much.
Just ensure these ports / services are set to drop the connections fitting
the description.

rk


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault