[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-Disclosure] RE: Outbreak warning: possibly Mydoom.C



Dshield also lists an abnormal rise of scans on port 3127.

http://www.dshield.org/port_report.php?port=3127

Particularly within the last 36 hours.

http://www.dshield.org/port_report.php?port=3127&days=1



Regards
Thor Larholm

SegLegal -- Discussion of legal issues related to security research 
http://seclegal.jscript.dk/



-----Original Message-----
From: Gadi Evron [mailto:ge@egotistical.reprehensible.net] 
Sent: Monday, February 09, 2004 8:20 AM
To: bugtraq@securityfocus.com
Cc: full-disclosure@lists.netsys.com
Subject: Outbreak warning: possibly Mydoom.C


Uses the Mydoom backdoor to upload itself (over Mydoom ports).

Seeded over the weekend, it is out now and spreads fast.

Blocking: block Mydoom ports.

        Gadi Evron.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html