Security Incidents mailing list archives

Re: Trojan of somesort - Update


From: Martin Mačok <martin.macok () underground cz>
Date: Fri, 28 May 2004 12:43:26 +0200

On Thu, May 27, 2004 at 02:58:56PM +0000, Bob the Builder wrote:

SF-Port10128-TCP:V=3.50%D=5/21%Time=40AE052F%P=i686-pc-linux-gnu%r(Generic
SF:Lines,6,"SDPACK")%r(GetRequest,6,"SDPACK")%r(HTTPOptions,6,"SDPACK")%r(
SF:RTSPRequest,6,"SDPACK")%r(RPCCheck,6,"SDPACK")%r(DNSVersionBindReq,6,"S
SF:DPACK")%r(DNSStatusRequest,6,"SDPACK")%r(Help,6,"SDPACK")%r(SSLSessionR
SF:eq,6,"SDPACK")%r(SMBProgNeg,6,"SDPACK")%r(X11Probe,6,"SDPACK")%r(LPDStr
SF:ing,6,"SDPACK")%r(LDAPBindReq,6,"SDPACK")%r(LANDesk-RC,6,"SDPACK")%r(Te
SF:rminalServer,6,"SDPACK")%r(NCP,6,"SDPACK")%r(NotesRPC,6,"SDPACK")%r(WMS
SF:Request,6,"SDPACK")%r(oracle-tns,6,"SDPACK");

This is probably BMC Perform Service Daemon.

Martin Mačok
IT Security Consultant


Current thread: