On Mon, Apr 10, 2000 at 10:10:31PM +1200, Del wrote:

> I'm not seeing any follow ups to the pings or 137 probes, but then
> again there are no 'doze boxes on the LAN anywhere.

I've not seen any follow up either, not unless you count the occasional
probes at ports 1243, 2140, 31337 and 31789, all of which are Windows
trojans or other back-door access methods (including Back Orifice).

Maybe it's just people looking for a Windows machine, and if they find
one, they attack it, maybe installing a trojan?  Those of us with
firewalls that simply block this port won't see anything more than the
initial scan, because the attacker won't find any vulnerable machines on
our subnets.

Cheers,

John
-- 
whois [EMAIL PROTECTED]
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to