Vulnerability Development mailing list archives

Re: INZIDER!


From: BlueBoar () THIEVCO COM (Blue Boar)
Date: Wed, 17 Nov 1999 22:27:36 -0800


Wolfgang Gassner wrote:

INZIDER???

This prog isnt working good, maybe its a kind of new
Trojan or Virus!!!!!

Any reason to suspect that, or is this wild speculation?

I tested it running Netbus and Back Orifice on it and it doesnt
detected it!!

... Implying that you thought it was a carrier for Netbus or BO?


It only gives some Information on Port 135, 139 ....

Which is what it's supposed to do, right?  Did it miss some ports?


I believe the best an reliable way to determine which port is open
is              netstat -an !!!


How about posting a comparison output from the two on your machine?

                                                BB


Current thread: