interesting items here not mentioned elsewhere at http://www.fedcirc.gov/incidentPrevention/infoNotices/infoNotice20030801.ht ml
in particular... port 111 / 707 DHS/FedCIRC Informational Notice 2003-08-01 "Monitor your network for unusual levels of ICMP traffic, and traffic for port 707 also reportedly used by the worm". "Federal civilian government agencies should Report any relevant activity (port 111 probing or activity, etc.) to your agency Incident Response Capability, and to FedCIRC using the form at http://www.fedcirc.gov/report.html or via telephone" DonnieWerner http://e2-labs.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
