Security Incidents mailing list archives

Re: Connections to Port 5632


From: Paul L Schmehl <pauls () UTDALLAS EDU>
Date: Fri, 4 Aug 2000 11:53:38 -0500

You should have also seen an equal number of connection attempts to port
22/UDP.

PC Anywhere is a very "dumb" software that assumes it's on a Windows
network.  It broadcasts aimlessly looking for any clients/servers it can
converse with.  If you have a copy of PC Anywhere, you can connect to that
IP, and if the individual isn't smart enough to have password protected
his/her copy, you'll be able to take control of their machine.  (The
default is no password.)

I doubt it's an exploit.  Just some clueless Winblows user that has no idea
how exposed they are.

--On Friday, August 04, 2000 1:41 PM +0100 Doug Winter
<dwinter () BUSINESSEUROPE COM> wrote:

For the last few days we have seen a large number of connections (7409 at
last count) to port 5632 of one of our systems.  These have all been
dropped by our firewall.

Paul L. Schmehl, pauls () utdallas edu
Technical Support Services Manager
The University of Texas at Dallas


Current thread: