Security Incidents mailing list archives
Re: update on scans of tcp 12345 AUSCERT#36349
From: orestes () DORIAN 2Y NET (orestes () DORIAN 2Y NET)
Date: Thu, 8 Jun 2000 17:19:48 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Russell, Port 12345 is the port for Netbus, a semi-popular (moreso over a year ago) Windows 95/98/NT trojan similar to Back Oriface. You still see a relatively high frequency of scans for it, especially by the script kiddy sect. Mike ____________________________________ Mike Murray Internetworking Specialist / Blueshirt Developer Apt 1402 666 Spadina Ave Toronto, Ont M5S 2H8 Email: Mike.Murray () utoronto ca / orestes () dorian 2y net Phone: (416) 323-3160 ___________________________________ -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.2 iQA/AwUBOUAN8rpfrcrUemrPEQK2nACdFRTp0S56nuDInwSza0Jl03A9tQEAn1vv ScaP5r819jXXc2+ZwZ5jsDjB =ICPg -----END PGP SIGNATURE-----
Current thread:
- Re: update on scans of tcp 12345 AUSCERT#36349, (continued)
- Re: update on scans of tcp 12345 AUSCERT#36349 Shaw Terwilliger (Jun 08)
- unknown trojan (attached) Jeremy L. Gaddis (Jun 08)
- ** New DDoS / Trojan ** nine (Jun 10)
- Re: ** New DDoS / Trojan ** Pierre Vandevenne (Jun 12)
- Re: unknown trojan (attached) Brandon Kittler (Jun 10)
- Re: unknown trojan (attached) Doug Kahler (Jun 12)
- .:: 14x :: Information :: New DDoS/Trojan ::. Erik Tayler (Jun 13)
- Re: .:: 14x :: Information :: New DDoS/Trojan ::. Lic. Rodolfo Gonzalez Gonzalez (Jun 15)
- IRC connect through apache ???? arhuman () HOTMAIL COM (Jun 14)
- Re: IRC connect through apache ???? Eric Vyncke (Jun 15)
- ** New DDoS / Trojan ** nine (Jun 10)