Security Incidents mailing list archives

Re: update on scans of tcp 12345 AUSCERT#36349


From: orestes () DORIAN 2Y NET (orestes () DORIAN 2Y NET)
Date: Thu, 8 Jun 2000 17:19:48 -0400


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Russell,

        Port 12345 is the port for Netbus, a semi-popular (moreso over a year
ago) Windows 95/98/NT trojan similar to Back Oriface.  You still see a
relatively high frequency of scans for it, especially by the script kiddy sect.

                        Mike

____________________________________
Mike Murray
Internetworking Specialist / Blueshirt Developer

Apt 1402
666 Spadina Ave
Toronto, Ont
M5S 2H8

Email:  Mike.Murray () utoronto ca /
          orestes () dorian 2y net
Phone:  (416) 323-3160
___________________________________

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.2

iQA/AwUBOUAN8rpfrcrUemrPEQK2nACdFRTp0S56nuDInwSza0Jl03A9tQEAn1vv
ScaP5r819jXXc2+ZwZ5jsDjB
=ICPg
-----END PGP SIGNATURE-----


Current thread: