Full Disclosure mailing list archives

RE: New Blaster variant using UDP port 1038?


From: "Stahlkrantz, Mats (Mats)" <mstahlkrantz () lucent com>
Date: Thu, 14 Aug 2003 14:55:19 -0400

Never mind.  Different issue causing this.

-----Original Message-----
From: Stahlkrantz, Mats (Mats) [mailto:mstahlkrantz () lucent com]
Sent: Thursday, August 14, 2003 1:48 PM
To: full-disclosure () lists netsys com
Subject: [Full-disclosure] New Blaster variant using UDP port 1038?


We're starting to see exploit attempts that are followed by probes from the infected host on tcp/4444, and then 
UDP/1038.  Has anyone else seen this?


Current thread: