Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Lots of traffic on port 1472 from explorer
From: Giuseppe Milicia <milicia () brics dk>
Date: Tue, 21 Sep 2004 21:13:57 +0200

Hi guys,

from a home computer I'm seeing lots of traffic generated from
explorer on port 1472 towards the microsoft-ds port, typically
on IP addresses starting with 35.xx.xx.xx

It looks like a worm but I could not find any references around
and Trend Micro detects nothing.

Also there is some hidden process oakklp32.exe which is not shown
by the taskmanager but is costantly active, again I could not
find anything about it!

Ideas? Clues?

Thanks,

--
Giuseppe

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]