On Wed, Aug 17, 2005 at 11:07:26AM -0700, [EMAIL PROTECTED] wrote: > > > > On Tue, 16 Aug 2005 [EMAIL PROTECTED] wrote: > > http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.CBQ > > Symantec: Win32.Zotob.E > > McAfee: exploit-dcomrpc > > Kaspersky: Net-Worm.Win32.Small.d > > The IRC server this worm uses is 72.20.27.115, #tbp -- does anyone know > what port? Is the host down from the virus's DoS of the IRC server? >
It looks like many major ISPs have null routed or prohibited access to this address. -- Mike Sawicki ([EMAIL PROTECTED]) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
