Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 10 Oct 1999 15:39:37 -0700 (PDT)
From:      Brooks Davis <brooks@one-eyed-alien.net>
To:        "Nicole H." <nicole@unixgirl.com>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: scanning of port 12345
Message-ID:  <Pine.GSO.4.10.9910101538390.28009-100000@orion.ac.hmc.edu>
In-Reply-To: <XFMail.991010142341.nicole@unixgirl.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 10 Oct 1999, Nicole H. wrote:

>  Why on earth would someone be scanning port 12345?  Is this a new backdoor
> port?
>    
> Oct 10 02:25:26 krell portsentry[14796]: attackalert: Connect from host:
> 195.235.210.171/195.235.210.171 to TCP port: 12345

That's the default port for netbus, a BackOriface like tool (the only real
difference is that it's shareware instead of free).

--Brooks



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.GSO.4.10.9910101538390.28009-100000>