Security Basics mailing list archives
Re: Worm activity
From: Andrés Montañez <andresmontanez.lists () gmail com>
Date: Mon, 13 Jun 2005 22:34:17 -0300
The port 445 is for the SMB suite (SaMBa or ActiveDirectory). Port 135 is "DCOM Service Control Manager". So the worm would be located in Windows workstations. You should start getting a list of recent worms with those targets. If you have WinClients... scann them. -- Andrés G. Montañez Network Administrator Montevideo - Uruguay
Current thread:
- Worm activity Adam Dyga (Jun 13)
- Re: Worm activity Andrés Montañez (Jun 14)
- Re: Worm activity Mark Bassett (Jun 14)
- Re: Worm activity Matt Kirchhoff (Jun 16)