Security Incidents mailing list archives

udp/1434


From: Jens Hektor <hektor () rz rwth-aachen de>
Date: 25 Jan 2003 11:30:10 -0000



Hi,

I see here large amounts of udp/1434 (ms-sql-m) traffic
starting from 01/25 5:30 GMT. Looks a bit wormy. Two
sources in our network have been isolated.

Is this seen elsewhere?

Bye, Jens Hektor

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: