lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
From: bobsagart500 at hotmail.com (bob sagart) Subject: Which worm? Hey everyone The other night I decided to see what traffic I could capture on tcp port 3127 (MyDoom backdoor) since I have been getting a lot of connection attemps showing up in my firewall logs. I got several dumps of the traffic using nc -l -p 3127 > out.dmp most of them are around 10-20kB which I thought was the about the right size of most of the worms and backdoors using that port. But one of the dumps I got was 150kB and I was just wondering if anyone could tell me what I might be? I cannot send it as an attachment as hotmail says it is a virus. Thanks. _________________________________________________________________ Check out news, entertainment and more @ http://xtra.co.nz/broadband