Hi all, I see this morning activity from several Public address try to scan many of my firewalls using the source ports 9898 and 5454, I belived that this activity is related to the DABBER worm, I try to find this activity in my Network Sensors but I don't see any signature reporting this, I only see TCP_service_sweep alert.
Somebody knows if ISS release signatures to see this kind of trafic ? Thanks, Geldard Valle Meza ----------------------------------------------------- CSIRT/cc SOC-Scitum [EMAIL PROTECTED] mobil. 21238975 _______________________________________________ ISSForum mailing list [EMAIL PROTECTED] TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to [EMAIL PROTECTED] The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328. _______________________________________________ ISSForum mailing list [EMAIL PROTECTED] TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to [EMAIL PROTECTED] The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
