lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <021601c512e4$dbad5360$646f1299@HURON>
Date: Mon, 14 Feb 2005 14:30:58 -0800
From: "David Gillett" <gillettdavid@...a.edu>
To: <baldwinL@...etwatchman.com>, <incidents@...urityfocus.com>,
	<bugtraq@...urityfocus.com>
Subject: RE: Exploit on tcp/4128?


  3128 is a commonly-scanned proxy port.  Maybe it's a typo?

David Gillett


> -----Original Message-----
> From: Lawrence Baldwin [mailto:baldwinL@...etwatchman.com]
> Sent: Monday, February 14, 2005 2:00 PM
> To: incidents@...urityfocus.com; bugtraq@...urityfocus.com
> Subject: Exploit on tcp/4128?
>
>
> Anyone know what this is:
>
> D:\nc>nc -n -v 64.132.205.69 4128
> (UNKNOWN) [64.132.205.69] 4128 (?) open
>
> 'ÖP?    ?      Version?   1.3?   Error?   ?   ?   Msg?
> Invalid Packet
> 'ÖP?    ?      Version?   1.3?   Error?   ?   ?   Msg?
> Invalid Packet
> 'ÖP?    ?      Version?   1.3?   Error?   ?   ?   Msg?
> Invalid Packet
> 'ÖP?    ?      Version?   1.3?   Error?   ?   ?   Msg?
> Invalid Packet
>
> 'ÖP?    ?      Version?   1.3?   Error?   ?   ?   Msg?
> Invalid Packet
> 'ÖP?
>    ?      Version?   1.3?   Error?   ?   ?   Msg?   Invalid
> Packet    ^C
>
>
> The same host above is scanning the *world* for this port:
>
> http://www.mynetwatchman.com/LID.asp?IID=146159119
>
> Regards,
>
> Lawrence Baldwin
> myNetWatchman.com
>



Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ