Security Incidents mailing list archives

Re: LPRng remote root exploit seen in the wild


From: Jens Hektor <hektor () RZ RWTH-AACHEN DE>
Date: Tue, 28 Nov 2000 09:35:50 -0000

Just to add to this head up.  We saw three 
major scans for port 515
over the weekend (and one about 10 days ago).
All scans probed many
thousands of addresses in our /16 address space
(one probed every one).

Had also one scan yesterday. Normal IP-order.
Offending machine (UIOWA.EDU) seems to be 
offline now.

Bye, Jens


Current thread: