[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <8B32EDC90D8F4E4AB40918883281874D35AD97@pivxwin2k1.secnet.pivx.com>
Date: Mon, 9 Feb 2004 11:24:52 -0800
From: "Thor Larholm" <thor@...x.com>
To: "'Gadi Evron'" <ge@...tistical.reprehensible.net>,
<bugtraq@...urityfocus.com>
Cc: <full-disclosure@...ts.netsys.com>
Subject: RE: Outbreak warning: possibly Mydoom.C
Dshield also lists an abnormal rise of scans on port 3127.
http://www.dshield.org/port_report.php?port=3127
Particularly within the last 36 hours.
http://www.dshield.org/port_report.php?port=3127&days=1
Regards
Thor Larholm
SegLegal -- Discussion of legal issues related to security research
http://seclegal.jscript.dk/
-----Original Message-----
From: Gadi Evron [mailto:ge@...tistical.reprehensible.net]
Sent: Monday, February 09, 2004 8:20 AM
To: bugtraq@...urityfocus.com
Cc: full-disclosure@...ts.netsys.com
Subject: Outbreak warning: possibly Mydoom.C
Uses the Mydoom backdoor to upload itself (over Mydoom ports).
Seeded over the weekend, it is out now and spreads fast.
Blocking: block Mydoom ports.
Gadi Evron.
Powered by blists - more mailing lists