Full Disclosure mailing list archives

Re: TCP Port 42 port scans? What the heck over...


From: wastedimage <wastedimage () gmail com>
Date: Tue, 14 Dec 2004 16:33:59 -0600

can anyone provide me with a traffic sample of this?  I would really
like to see if this is the actual exploit or just a script kiddy
trying his little heart out.



image
On Mon, 13 Dec 2004 21:53:41 +0100, Florian Weimer <fw () deneb enyo de> wrote:
* James Lay:

Here they be.  ODD.  Anyone else seeing this?

Probably yes. 8-) 42/TCP is used by Microsoft's WINS replication, and
this service has got a security hole for which Microsoft has yet to
release a patch.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: