Re: scan for 109, new worm-variant or simple scan?

From: Russell Fulton (r.fultonat_private)
Date: Wed Apr 25 2001 - 16:54:12 PDT

  • Next message: Andreas Östling: "Re: TCP/1008 port scans"

    On Wed, 25 Apr 2001 16:01:40 -0700 Jeff Nieusma
    <nieusmaat_private> wrote:
    
     > Anyone heard of any new POP2 exploits? Or is this just a tired old
    hacker
    > nothing better to do than waste bandwidth...
    
    This question has been asked at least every 6 months on this list
    since the list began.  So far as I can remember noone has ever put
    forward any plausible explaination other than "there are still RH5.x
    boxes out there which had the washington POP2 daemon installed by
    default".
    
    New organisations are joining the Internet all the time (particularly
    in Asia) and many have old boxes on their networks and lax security.
    
    Russell Fulton, Computer and Network Security Officer
    The University of Auckland,  New Zealand
    



    This archive was generated by hypermail 2b30 : Thu Apr 26 2001 - 07:32:26 PDT