Full Disclosure mailing list archives

New Blaster variant using UDP port 1038?


From: "Stahlkrantz, Mats (Mats)" <mstahlkrantz () lucent com>
Date: Thu, 14 Aug 2003 13:48:22 -0400

We're starting to see exploit attempts that are followed by probes from the infected host on tcp/4444, and then 
UDP/1038.  Has anyone else seen this?

Current thread: