Greetings!
Low Lay Hua wrote:
> Recently, I received a lot of attempt from several address using 12345/tcp
> to scan the subnet that was behind some of our firewall.
> Do u have any idea what is 12345/tcp? How dangerous it is?
There are two systems using 12345/tcp by default:
* TrendMicro Virusscanner - auto-update via Network
* NetBus - a backdoor admin/trojan tool similar to BackOrifice
So either everything is fine (virus scanner update running) or it may be (if NetBus
is used by the admins) - or not at all (if NetBus not installed by admins).
Bye
Volker
begin:vcard
n:Tanger;Volker
tel;fax:+49 - 69 - 92901-213
tel;work:+49 - 69 - 92901-570
x-mozilla-html:FALSE
url:http://www.res.globalone.net/
org:Global One;Global Project Engineering
version:2.1
email;internet:[EMAIL PROTECTED]
title:Sr. Security Engineer
adr;quoted-printable:;;Stiftstrasse 23=0D=0A;Frankfurt;;60313;Germany
note;quoted-printable:Room 608=0D=0A
fn:Volker Tanger
end:vcard