Full Disclosure mailing list archives

Re: Disney Down?


From: Mike Sawicki <fifi () HAX ORG>
Date: Wed, 17 Aug 2005 14:34:28 -0400

On Wed, Aug 17, 2005 at 11:07:26AM -0700, fd () ew nsci us wrote:



On Tue, 16 Aug 2005 sk3tch () sk3tch net wrote:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CBQ
Symantec: Win32.Zotob.E
McAfee: exploit-dcomrpc
Kaspersky: Net-Worm.Win32.Small.d

The IRC server this worm uses is 72.20.27.115, #tbp -- does anyone know
what port?  Is the host down from the virus's DoS of the IRC server?


It looks like many major ISPs have null routed or prohibited access
to this address.

--
Mike Sawicki (fifi () HAX ORG)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: