Educause Security Discussion mailing list archives

Re: use Nmap to find W32/Bagle.e@MM ?


From: Gary Flynn <flynngn () JMU EDU>
Date: Thu, 4 Mar 2004 08:59:25 -0500

Michael_Maloney wrote:

Just curious,

Has anyone else seen false positives looking for Bagle on this port?  So far
I've found a few systems that were shown to have this port open, but all
scans and manual searches came up clean.

Use fport or 'netstat -ano' to see what process
is holding the port open.

--
Gary Flynn
Security Engineer - Technical Services
James Madison University

**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Current thread: