Security Incidents mailing list archives
Re: Connections to Port 5632
From: Paul L Schmehl <pauls () UTDALLAS EDU>
Date: Fri, 4 Aug 2000 11:53:38 -0500
You should have also seen an equal number of connection attempts to port 22/UDP. PC Anywhere is a very "dumb" software that assumes it's on a Windows network. It broadcasts aimlessly looking for any clients/servers it can converse with. If you have a copy of PC Anywhere, you can connect to that IP, and if the individual isn't smart enough to have password protected his/her copy, you'll be able to take control of their machine. (The default is no password.) I doubt it's an exploit. Just some clueless Winblows user that has no idea how exposed they are. --On Friday, August 04, 2000 1:41 PM +0100 Doug Winter <dwinter () BUSINESSEUROPE COM> wrote:
For the last few days we have seen a large number of connections (7409 at last count) to port 5632 of one of our systems. These have all been dropped by our firewall.
Paul L. Schmehl, pauls () utdallas edu Technical Support Services Manager The University of Texas at Dallas
Current thread:
- Connections to Port 5632 Doug Winter (Aug 04)
- Re: Connections to Port 5632 Valdis Kletnieks (Aug 07)
- Re: Connections to Port 5632 Paul L Schmehl (Aug 07)
- <Possible follow-ups>
- Re: Connections to Port 5632 Doug Winter (Aug 07)
- FW: Connections to Port 5632 Forrester, Mike (Aug 08)
- Re: FW: Connections to Port 5632 Philipp Buehler (Aug 09)
- Re: FW: Connections to Port 5632 GraffiX (Aug 10)
- Re: FW: Connections to Port 5632 Philipp Buehler (Aug 13)
- Re: FW: Connections to Port 5632 GraffiX (Aug 14)
- Re: FW: Connections to Port 5632 Philipp Buehler (Aug 09)
