nanog mailing list archives

Re: Port 139 scans


From: Jared Mauch <jared () puck Nether net>
Date: Wed, 27 Sep 2000 15:10:48 -0400


On Wed, Sep 27, 2000 at 11:35:23AM -0700, Ben Browning wrote:
My current suspicion is that a backdoor trojan (pause here to decline the 
port 139 attempt that just zipped by me) is on the loose and being 
propagated like mad. This would certainly fit with the rumour of a huge 
DDoS attack in the works, as m@d l33t h@x0rs get as many machines as 
possible compromised and ready to help the attack.

        It would be interesting to see if this crops up at this nanog
meeting as it did at the San Jose meeting.

        - Jared

--
Jared Mauch  | pgp key available via finger from jared () puck nether net
clue++;      | http://puck.nether.net/~jared/  My statements are only mine.
END OF LINE  | Manager of IP networks built within my own home



Current thread: