Security Incidents: by date

214 messages starting Mar 04 03 and ending Mar 31 03
Date index | Thread index | Author index


Tuesday, 04 March

Re: Interesting Stephen J. Friedl
TCP 445 Scan? Charles Hamby
Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Salomao Barguil
RE: Possible new backdoor: mspx-smss.exe ? Leonard.Ong
sending out spam through IRC server ? Bronek Kozicki
Re: Interesting Rafael Coninck Teigao
Spammers? Christopher Wagner
UDP port 41170 Patrick Webster
RE: Weird Profile in Documents and Settings Andre Arcand
RE: www.nopop.net m0use
Numerous TCP port 445 scans on 3/2/03 Kevin Patz
Re: Interesting bugtraq
Re: TCP 445 Scan? Adam Bultman
Re: Spammers? jlewis
Re: UDP port 41170 Stephen.
Re: TCP 445 Scan? H C
Re: TCP 445 Scan? Bill McCarty
RE : UDP port 41170 THIERRY Antoine
Re: TCP 445 Scan? Tom_Staskiewicz
Re: Spammers? Denis Dimick
RE: TCP 445 Scan? Lee_Fisher
RE: TCP 445 Scan? kyle

Wednesday, 05 March

SV: TCP 445 Scan? Peter Kruse
RE: Spammers? James C Slora Jr
RE: TCP 445 Scan? Charles Hamby
Re: TCP 445 Scan? Brian McWilliams
RE: TCP 445 Scan? Frank Knobbe
Re: sending out spam through IRC server ? R Andersson
RE: sending out spam through IRC server ? Bill Lavalette
RE: Numerous TCP port 445 scans on 3/2/03 Patrick Webster
Re: sending out spam through IRC server ? Alex Lambert
Re: Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Alexandru Balan
RE: Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Robert
Re: Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 H C
Re: Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Kevin Patz
RE: TCP 445 Scan? kyle
New SecurityFocus article announcement Dan Hanson
RE: sending out spam through IRC server ? Robert

Thursday, 06 March

Re: TCP 445 Scan? Johannes Ullrich
RE: TCP 445 Scan? Thompson, Jason
Re: sending out spam through IRC server ? Bronek Kozicki
Anyone recognize a DDOS tool with the signature "The Matrix" and Catch Me"? Hammer Penguin
Re: Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Robbert Helling
SMTP username dictionary attack Rich Puhek
SecurityFocus article announcement Dan Hanson
Re: SMTP username dictionary attack Garrett Sinfield
RE: TCP 445 Scan? kyle

Friday, 07 March

Re: SMTP username dictionary attack Mike
Re: Backdoor ?? "Girlnextdoor_" TCP Ports 1025/1028 Harlan Carvey
Solved !! "Girlnextdoor_" TCP Ports 1025/1028 Salomao Barguil
Re: Open mail relay surge Jeff Kell
Re: Open mail relay surge Christopher Cramer
Real-world attacks on sendmail CA-2003-07 seen Bennett Todd
New virus outbreak. Danny
new ddos client? Andy Shelley

Monday, 10 March

Re: new ddos client? Alex Lambert
RE: New virus outbreak? Danny
Re: Real-world attacks on sendmail CA-2003-07 seen Mike Tancsa
Port 3335 Robin Lynn Frank
Re: Solved !! "Girlnextdoor_" TCP Ports 1025/1028 Nikunj Virani
Re: new ddos client? Andy Shelley
RE: New virus outbreak. Dave Duke
RE: New virus outbreak. Danny
Bypassing Black Ice PC protection? Curt Wilson
Re: Real-world attacks on sendmail CA-2003-07 seen Curt Wilson
against illegal arp update SB CH
re: New virus outbreak. Harlan Carvey
Re: Real-world attacks on sendmail CA-2003-07 seen jlewis
Re: Real-world attacks on sendmail CA-2003-07 seen Bennett Todd
RE: Port 3335 Danny
Re: Real-world attacks on sendmail CA-2003-07 seen Jeff Kell
Possibly Unknown Virus? Care to help me analyze?!? Jeremy Junginger
RE: Real-world attacks on sendmail CA-2003-07 seen Barry Kokotailo
Re: Solved !! "Girlnextdoor_" TCP Ports 1025/1028 Harlan Carvey
Re: Real-world attacks on sendmail CA-2003-07 seen Bennett Todd
RE: New virus outbreak. Danny
Re: Real-world attacks on sendmail CA-2003-07 seen Bennett Todd
Re: Port 3335 Harlan Carvey
Increase in Scans of Port 445? Compton, Rich
Re: Real-world attacks on sendmail CA-2003-07 seen james
RE: New virus outbreak. KoRe MeLtDoWn
UPDATE: Possibly Unknown Virus? Care to help me analyze?!? Jeremy Junginger
Re: Real-world attacks on sendmail CA-2003-07 seen Juan Gallego
Re: Increase in Scans of Port 445? Thomas Schmitz

Tuesday, 11 March

RE: Possibly Unknown Virus? Care to help me analyze?!? Arnold, Jamie
Re: UPDATE: Possibly Unknown Virus? Care to help me analyze?!? Darwin
Re: [Full-Disclosure] Bypassing Black Ice PC protection? Darwin
Re: W2K Compromise - PipeCmdSrv Corey Coblentz
Re: Port 3335 Robin Lynn Frank
Re: Real-world attacks on sendmail CA-2003-07 seen gabriel rosenkoetter
Snort Signatures for LSD-PL.NET Exploit Loki
worm/Trojans are taking advantage of default path of Windows kyle
CANADA.EXE program Boyko, Steve
sendmail exploit or ill formatted spam Dominik Samuelis
Re: [Full-Disclosure] Bypassing Black Ice PC protection? Curt Wilson
Re: against illegal arp update Cedric Blancher
Unknown attack, possible trojan? Arjan Hulsebos
Re: [Snort-sigs] Snort Signatures for LSD-PL.NET Exploit Michael Scheidell
Re: CANADA.EXE program Brad Arlt
RE: Possibly Unknown Virus? Kevin Patz
The Return of Code Red II? Stan Burditzman
Re: The Return of Code Red II? Jay D. Dyson
Re: The Return of Code Red II? David C. Lewis
Re: The Return of Code Red II? Kevin Patz
Re: The Return of Code Red II? Roger Thompson
SV: The Return of Code Red II? Peter Kruse
FW: Alert: New Code Red F worming its way through the 'net Robinson, Sonja
RE: Re: Solved !! "Girlnextdoor_" TCP Ports 1025/1028 Levinson, Karl

Wednesday, 12 March

Re: against illegal arp update Greg A. Woods
DeLoder technical analysis kyle
Re: The Return of Code Red II? Christine Kronberg
Hosts File "Girlnextdoor_" Salomao Barguil
Port 109 Mystery Douglas Brown
Defaced website listing... Hay, Duane
Re: Port 109 Mystery Loki
RE: Defaced website listing... Craig Searle

Thursday, 13 March

RE: Defaced website listing... John McCracken
RE: Port 109 Mystery James C Slora Jr
FW: CodeRed Observations. larosa, vjay
CANADA.EXE Findings John H
Re: [unisog] Port 109 Mystery Andy Polyakov
Re: Port 109 Mystery Douglas Brown
RE: CodeRed Observations. Rob Shein
RE: Defaced website listing... Carey, Steve T GARRISON
Re: [unisog] Re: Port 109 Mystery Buck Buchanan
RE: CodeRed Observations. larosa, vjay
tcp/25 (smtp) and tcp/24942 (unk) Matthew Todd
RE: CodeRed Observations. larosa, vjay
RE: CodeRed Observations. Rob Shein
RE: CodeRed Observations. Rob Shein
RE: CodeRed Observations. larosa, vjay
RE: CANADA.EXE Findings Cavey, Jean-Luc
Re: FW: CodeRed Observations. Russell Fulton
RE: CodeRed Observations. Michał Rogala
RE: CodeRed Observations. Rob McCauley
Re: [unisog] Re: Port 109 Mystery Harlan Carvey
Windows Rootkits/API Hooking Harlan Carvey
New article announcement: Open Source Honeypots, Part Two: Deploying Honeyd in the Wild Dan Hanson
Re: Defaced website listing... Rich Puhek
unidentified DOS "bad traffic" DY

Friday, 14 March

Re: unidentified DOS 'bad traffic' Kerry Thompson
RE: unidentified DOS "bad traffic" David Gillett
Re: CodeRed Observations. Þórhallur Hálfdánarson
RE: CodeRed Observations. larosa, vjay
Re: unidentified DOS "bad traffic" Alain Fauconnet
Re: [unisog] Re: Port 109 Mystery David Moisan
Re: [Snort-sigs] Snort Signatures for LSD-PL.NET Exploit Martin Roesch
IRC DDoS bots grwolf
RE: CodeRed Observations. King, Brian
Re: unidentified DOS "bad traffic" Jason Falciola
Final word on WINLOGON David Moisan
RE: CodeRed Observations. Christine Kronberg
Re: IRC DDoS bots Johannes Ullrich
Re: Unknown attack, possible trojan? Jason Falciola
RE: CodeRed Observations. King, Brian
Re: unidentified DOS "bad traffic" -- SOLVED DY
RE: IRC DDoS bots James C Slora Jr

Sunday, 16 March

RE: CodeRed Observations. Bojan Zdrnja
RE: CodeRed Observations. larosa, vjay
RE: [unisog] Re: Port 109 Mystery Patrick R. Sweeney
RE: unidentified DOS "bad traffic" -- SOLVED kyle
RE: unidentified DOS "bad traffic" -- SOLVED kyle
RE: CodeRed Observations. Rob Shein
Re: CodeRed Observations. Andrew Bates
RE: [unisog] Re: Port 109 Mystery Rob Shein

Monday, 17 March

Re: IRC DDoS bots Jon Nelson

Tuesday, 18 March

RE: CodeRed Observations. ## root
RE: CodeRed Observations. ## Christine_Kronberg () genua de root
Animal Rights Hacktivist Group? ciso
SPM2000$ Rouge Share Robinson, Jonathon

Wednesday, 19 March

Re: CodeRed Observations. ## Andrew Bates
RE: SPM2000$ Rouge Share Robinson, Jonathon
RE: CodeRed Observations. ## Rob Shein
Re: Animal Rights Hacktivist Group? Jay D. Dyson
Re: SPM2000$ Rouge Share Harlan Carvey
RE: SPM2000$ Rouge Share Robinson, Jonathon
RE: CodeRed Observations. Christine Kronberg
RE: SPM2000$ Rouge Share Harlan Carvey
RE: SPM2000$ Rouge Share Jonathan Rickman

Thursday, 20 March

Re: SPM2000$ Rouge Share - Information Leon Havin
Nimda.E/unknown memory resident, internet-aware processes Matt Hornsby
Re: Nimda.E/unknown memory resident, internet-aware processes Johannes Ullrich

Friday, 21 March

"webmoney" trojan and COM interface analysis Pierre Vandevenne
Trojan attacking our switches Charles Polisher
Re: Trojan attacking our switches dreamwvr () dreamwvr com
Re: Trojan attacking our switches Mike Hoskins

Saturday, 22 March

California State Bill SB1386 Steve Zenone
Re: Trojan attacking our switches Kris Saw
Chinese source: some web attack tool Paul

Sunday, 23 March

AW: Chinese source: some web attack tool Tobias Lachmann

Monday, 24 March

RE: California State Bill SB1386 Jonathan A. Zdziarski
RE: California State Bill SB1386 Steve Zenone

Wednesday, 26 March

RE: California State Bill SB1386 Jonathan A. Zdziarski
RE: California State Bill SB1386 Rohrer, Mark E
Re: California State Bill SB1386 Rodrigo Barbosa
RE: California State Bill SB1386 System Administrator
Dead Thread: California State Bill SB1386 Dan Hanson
Re: California State Bill SB1386 Anders Reed Mohn
Re: [Fwd: FW: California State Bill SB1386] digigal11
RE: Dead Thread: California State Bill SB1386 Steve Zenone

Thursday, 27 March

SecurityFocus Article Announcement: Incident Response Tools For Unix, Part One: System Tools Dan Hanson
FTimes 3.2.1 Release (Includes Dig, HashDig, and Map Tools) Klayton Monroe
strange DNS behavior over the last 2 days steve baker
Re: strange DNS behavior over the last 2 days Chris Wilkes
Re: strange DNS behavior over the last 2 days jinyean tan

Friday, 28 March

Re: California State Bill SB1386 Cliff Gilley (System Admin, HolyElvis.com)

Saturday, 29 March

RE: strange DNS behavior over the last 2 days Levinson, Karl
Re: strange DNS behavior over the last 2 days Jacob
Re: strange DNS behavior over the last 2 days Jacco Tunnissen

Monday, 31 March

SQL Slammer Variant? Wilson, Aaron J.
new attack tool combining SMB and WebDAV? Matt Power
RE: strange DNS behavior over the last 2 days John S. Pitts
POP3 logon attempts Tom Fischer
RE: new attack tool combining SMB and WebDAV? James C Slora Jr