Security Incidents mailing list archives
Re: Port Zero
From: nony101 () last za net
Date: 19 Jul 2005 08:59:10 -0000
I had in incident yesterday (18 June 2005), where a client's Windows box listed almost every possible port as open, listening in the same way described above. Similiar netstat -an output as above. From my experience this isn't normal. A few hours later the machine rapidly starting sending packets to random addresses on port 443. What could this possibly be? Is it a virus/backdoor/something malicious? Baba, is that your whole netstat output?
Current thread:
- Re: Port Zero, (continued)
- Re: Port Zero Ron (Jul 17)
- Re: Port Zero Lee Dilkie (Jul 18)
- mysql attack Pall Thayer (Jul 19)
- Re: mysql attack Joel Esler (Jul 19)
- Re: mysql attack W. Guhan Iyer (Jul 19)
- Re: mysql attack Pall Thayer (Jul 21)
- Re: Port Zero Lee Dilkie (Jul 18)
- Re: Port Zero Ron (Jul 17)
- Re: Port Zero Harlan Carvey (Jul 19)
- Re: Port Zero Andrew Simmons (Jul 19)
