Security Incidents: by date

165 messages starting Mar 31 03 and ending Apr 30 03
Date index | Thread index | Author index


Monday, 31 March

Re: new attack tool combining SMB and WebDAV? Bill McCarty
RE: POP3 logon attempts Jerry Shenk
Why alerts on ports 1025-1029, 1036 Tomas Carlsson
RE: POP3 logon attempts Curt Purdy
Re: POP3 logon attempts Bojan Zdrnja
Re: POP3 logon attempts Torsten Mueller
RE: Why alerts on ports 1025-1029, 1036 Erik Boles
Re: [CERT] Why alerts on ports 1025-1029, 1036 ePAc

Tuesday, 01 April

New Article: U.S. Information Security Law, Part 2 Dan Hanson
Educational Incident Data Comparison Pilot (X-Post) Alfred Huger
RE: Why alerts on ports 1025-1029, 1036 Matt Marcos
RE: new attack tool combining SMB and WebDAV? Toby Miller

Wednesday, 02 April

RE: Why alerts on ports 1025-1029, 1036 Stuart Wallace
Re: SQL Slammer Variant? crucible
RE: WebDAV Exploit Lab Jeremy Junginger
Re: POP3 logon attempts Tom Fischer
RE: SQL Slammer Variant? Wilson, Aaron J.
RE: Logon/Logoff Failure Events Robert Wagner
Re: POP3 logon attempts dreamwvr () dreamwvr com
RE: Why alerts on ports 1025-1029, 1036 Leo, Joel
Increase in Source to Port 445 Rob Keown
Re: POP3 logon attempts Mike
UDP traffic to net and broadcast addresses Zen
RE: SQL Slammer Variant? Rob Shein
Logon.dll? Possible root-kit? Nick Jacobsen
Increase of attempts on port 635 in last couple days Jeff Lane
possible rootkit, maybe partial? Benjamin Tomhave

Thursday, 03 April

Re: [CERT] possible rootkit, maybe partial? ePAc
Re: Logon.dll? Possible root-kit? Nick Jacobsen
Re: possible rootkit, maybe partial? Richard Rager
Re: possible rootkit, maybe partial? D.C. van Moolenbroek
Field Report: New Worm falcon
Re: [0.5OT answer]possible rootkit, maybe partial? nobody
RE: Increase in Source to Port 445 James C Slora Jr
RE: Logon.dll? Possible root-kit? Amarante, Rodrigo P.
UDP scans from AOL NS boxes? Mike Mills
RE: Logon.dll? Possible root-kit? Rob Shein
Re: Logon.dll? Possible root-kit? Harlan Carvey
Re: Logon.dll? Possible root-kit? Nick Jacobsen
RE: UDP traffic to net and broadcast addresses Joshua Wright
Re: Increase in Source to Port 445 aladin168
RECAP: possible rootkit, maybe partial? Benjamin Tomhave
RE: Logon/Logoff Failure Events John Ives
RE: Logon/Logoff Failure Events Russell Morrison

Friday, 04 April

SMTP probes Rich Puhek
Re: Logon.dll? Possible root-kit? Nick Jacobsen
Re: Logon.dll? Possible root-kit? Harlan Carvey
RE: Logon.dll? Possible root-kit? Rob Shein
RE: Logon.dll? Possible root-kit? Jason Pagano

Saturday, 05 April

Re: SMTP probes Neil Dickey
Re: SMTP probes Bojan Zdrnja

Sunday, 06 April

Does anyone recognize the scanner that causes this pattern ? dean

Monday, 07 April

Re: Does anyone recognize the scanner that causes this pattern ? Laurent Luyckx
RE: Does anyone recognize the scanner that causes this pattern ? Jerry Shenk
RE: Does anyone recognize the scanner that causes this pattern ? Justin Coffi
Re: SMTP probes Christine Kronberg
unknown rootkit found in the wild Jerome
Re: Does anyone recognize the scanner that causes this pattern ? dean
Re: Does anyone recognize the scanner that causes this pattern ? Gene
ATD OpenSSL Mass Exploiter Analysis (another "/sumthin" scan tool) Joe Stewart

Wednesday, 09 April

New SecurityFocus article: Specter: A Commercial Honeypot Solution for Windows Dan Hanson
New SecurityFocus article: Steganography Revealed Dan Hanson

Thursday, 10 April

New trojan? Old trojan with new characteristics? Anyone seen this? Mike Parkin

Monday, 14 April

Re: New trojan? Old trojan with new characteristics? Anyone seenthis? Alex Lambert
Port 17300 probes? incidents

Tuesday, 15 April

Re: Port 17300 probes? Gerd Feiner
Re: Port 17300 probes? Kevin Patz
Re: Port 17300 probes? MARLON BORBA
Re: New trojan? Old trojan with new characteristics? Anyone seenthis? vex86 () rogers com
Port 3366 activity defaillance
Logging of connects to port 6346 kbergen

Thursday, 17 April

Re: New trojan? Old trojan with new characteristics? Anyone seenthis? Mike Parkin
Re: Port 17300 probes? Joris De Donder
Re: Port 17300 probes? Joe Stewart
RE: Logging of connects to port 6346 LordInfidel
port 5168 Molony, Duncan
Re: Logging of connects to port 6346 Nicolas Couture
Trojan found... Les Ault
Port 6666 Scans Thomas Vincent
Intresting problem concerning libresolv.so.2 Sam Evans

Saturday, 19 April

Anyone seen this UDP source port 7001 traffic? Faron . Golden
IP Spoofs in the log - not sure what to do next Chris Corbett
Re: Intresting problem concerning libresolv.so.2 Kevin Reardon
Company being War Dialed Fred Kreitzberg
Re: Trojan found... Les Ault
Strange, scary, subtle trojan Jeff Kell
re: port 5168 Harlan Carvey
Re: Trojan found... Harlan Carvey
port 139 syn-fin scans Skip Carter
Re: Intresting problem concerning libresolv.so.2 Paul Gear
Mo'Logs sf
Re: Company being War Dialed Brett Glass

Monday, 21 April

Re: Company being War Dialed Kurt Seifried
Re: Intresting problem concerning libresolv.so.2 Paul Gear
Re: port 139 syn-fin scans Scott A. McIntyre
Re: SMTP Scans Hoof Hearted
RE: IP Spoofs in the log - not sure what to do next Curt Purdy
RE: Company being War Dialed Curt Purdy
RE: port 139 syn-fin scans Kevin Hodle
Re: port 139 syn-fin scans Muchacki Robert
RE: port 139 syn-fin scans Toby Miller
msamba Steve Bromwich
Re: Company being War Dialed public list
Re: Company being War Dialed James . Phillips
RE: IP Spoofs in the log - not sure what to do next David Klotz
Re: FW: IP Spoofs in the log - not sure what to do next crawford charles
RE: Strange, scary, subtle trojan Dowling, Gabrielle
Re: msamba Paulo Abrantes
Tracking proxies on port 1180/1182 Joe Stewart
Re: Tracking proxies on port 1180/1182 George Bakos
RE: Company being War Dialed James . Jackson
Re: Tracking proxies on port 1180/1182 Michael Scheidell

Tuesday, 22 April

RE: SMTP Scans Rob Shein
Re: msamba William Salusky
Re: msamba Nikola Pepelishev
Re: FW: IP Spoofs in the log - not sure what to do next David Hawley
Re: msamba Steve Bromwich
RE: SMTP Scans Mally Mclane
Re: msamba noconflic

Wednesday, 23 April

Re: msamba noconflic
RE: SMTP Scans Luc Somers
RE: Company being War Dialed nospam
protocol watcher Justin Pryzby
Re: POP3 logon attempts Steve Cody
Re: protocol watcher Jose Nazario

Thursday, 24 April

RE: SMTP Scans Jimi Thompson
Re: Trojan found... aladin168
Re: IP Spoofs in the log - not sure what to do next aladin168

Friday, 25 April

Re: SMTP Scans Kurt Seifried
Re: Trojan found... Patrick Nolan
New attack or old Vulnerability Scanner? Mark Embrich
Re: msamba Tobias Klein
Scans on TCP port 9631 + other unknown ports Kevin Patz

Monday, 28 April

RE: New attack or old Vulnerability Scanner? James C. Slora, Jr.
Re: SMTP Scans Hoof Hearted
RE: SMTP Scans paul
Re: New attack or old Vulnerability Scanner? Jason Falciola
Re: Anyone seen this UDP source port 7001 traffic? Michael Lau
New CodeRed strain? Frank Knobbe
Re: New CodeRed strain? Frank Knobbe
lots of port 0 scannings SB CH
RE: New attack or old Vulnerability Scanner? Keith
Re: New attack or old Vulnerability Scanner? rhandwerker

Tuesday, 29 April

Re: New CodeRed strain? -- UPDATE Frank Knobbe
Re: SMTP Scans Chris Boyd
Odd IIS log entries Hahn, Jacob
Re: lots of port 0 scannings Brad Doctor
RE: Anyone seen this UDP source port 7001 traffic? Taz
Re: lots of port 0 scannings Neil Dickey
undetected DDOS Chris Cahill
Re: Anyone seen this UDP source port 7001 traffic? Tina Bird
Re: Anyone seen this UDP source port 7001 traffic? Jose Nazario
Re: New attack or old Vulnerability Scanner? jac
Re: New CodeRed strain? -- UPDATE Justin Pryzby
Re: New attack or old Vulnerability Scanner? Mark Embrich

Wednesday, 30 April

Administrivia: SPAM control, vacation messages, and the like. Dan Hanson
RE: New CodeRed strain? -- UPDATE larosa, vjay
RE: Odd IIS log entries James C. Slora, Jr.
Logs showing GET /.hash=... Keith Bergen
UDP packets towards port 38293 (NAV) Alan B. Clegg
Re: New attack or old Vulnerability Scanner? Jason Falciola
Re: New attack or old Vulnerability Scanner? Jason Falciola
Re: Logs showing GET /.hash=... Chris Mann
Re: UDP packets towards port 38293 (NAV) Russell Fulton
Re: UDP packets towards port 38293 (NAV) Nexus