Security Incidents mailing list archives

Re: Port 10008


From: Tim Brown <tim.brown () ncmail net>
Date: Tue, 15 May 2001 12:26:01 -0400

Version 3 of the 1ion worm we saw a bunch yesterday ourselves.

http://www.whitehats.com/library/worms/lion/

Joerg Weber wrote:

Hello everyone,

my FW-Logs went insane last night with gazillions of connection attempts to
port 10008.
FW-1 does unfortunately not log dropped packets, so I've no idea about flags
et al, but the scan looks like this:
SourcePort = Increases with each scan
DestPort   = 10008

This looks like an automated tool to me, as the whole scan took about a
second or two.
Any ideas?

Thanks,

Joerg

--

Tim Brown




Current thread: