Security Basics mailing list archives
RE: Strange Connection Attempts
From: "Kinsey, Robert" <Robert.Kinsey () Veridian com>
Date: Mon, 17 Feb 2003 15:39:11 -0800
I also saw the 17300 (which is the port Kuang 2 the virus runs on). But they were all coming from Asia (about 0800 their time) and never progressed. I was thinking it was a launch attempt on the 14th but no other TZs showed up. My feeling is if these are all 0-byte length probes they aren't doing much. Just ensure these ports / services are set to drop the connections fitting the description. rk
Current thread:
- Strange Connection Attempts Hankes, Christopher A (Feb 14)
- <Possible follow-ups>
- RE: Strange Connection Attempts Keith T. Morgan (Feb 17)
- RE: Strange Connection Attempts Tim Heagarty (Feb 17)
- RE: Strange Connection Attempts Kinsey, Robert (Feb 18)
- RE: Strange Connection Attempts fixer (Feb 18)
- Re: Strange Connection Attempts Charles Hamby (Feb 19)
- RE: Strange Connection Attempts Trevor Cushen (Feb 20)
- Windows 2000 Server Attacks Paul Stewart (Feb 20)
- Re: Windows 2000 Server Attacks Su Wadlow (Feb 22)
- Windows 2000 Server Attacks Paul Stewart (Feb 20)
