CR Overflows followed up by UDP 2380

From: Thompson, John J (ThompsonJJat_private)
Date: Mon Aug 06 2001 - 07:06:19 PDT

  • Next message: pilot: "scan CodeRed II infected servers"

    Anyone know what 2380 is and why there's a ten count of udp probes to it
    following almost every cr attempt? 2380 is unassigned according to my
    reference lists. 
    
    John
    
    ------------------------------------
    John Thompson
    Network Administrator
    Dept. of Biochemistry
    University of Iowa
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Aug 06 2001 - 10:10:25 PDT