[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <018101c3604f$cae53e10$0100a8c0@newmarkr>
From: harqman at btopenworld.com (harq deman)
Subject: msblast
yawn.. OK.. the worm.. again
It scans a randon b class based on the current hosts address
it does not kill any AV products or firewalls
it does not hide processes, files or network activity from the kernel
when it packets windowsupdate.com on the 16th, it spoofs the last 2 octets of the source ip address, and continues to scan
D-.. must try harder
--harq
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20030811/8af02611/attachment.html
Powered by blists - more mailing lists