Re: Re : Large scale scan of port 2401

From: axess (axessat_private)
Date: Thu Aug 23 2001 - 11:31:40 PDT

  • Next message: Valdis.Kletnieksat_private: "Re: Smurf Broadcast DoS attack"

    On Thu, 23 Aug 2001, John Marquart wrote:
    
    
    Sorry if my mail was was abit confusing.
    
    Last Stage of Delirium Research Group is a non-profit informal organization
    that released some remote and local (POC) proof of concept exploits codes
    for AIX some time ago.
    
    These are now widely used to penetrate AIX systems by defacers and
    other individuals that want access to systems around the internet.
    
    > Mr Olsson,
    > 	Could you elaborate on your comments below - i.e. what AIX uses
    > the port for, what the LSDRG is/does what POC is?   Presumably an exploit
    > of some sort?
    >
    > thanks,
    > -john
    >
    >
    > On Thu, 23 Aug 2001, axess wrote:
    >
    > >
    > > 2401/tcp  cvspserver
    > >
    > > This port is used by AIX and with the recent contribution from
    > > Last Stage of Delirium Research Group with many POC codes to the world.
    > > Im sure those scans was aimed to locate servers running AIX in a
    > > fast and easy way.
    > >
    > > --
    > > Mikael Olsson
    > > axess - axessat_private
    > > system administrator
    > >
    > > IT-Security Information Network
    > > http://www.alldas.de
    > >
    > >
    > > ----------------------------------------------------------------------------
    > > This list is provided by the SecurityFocus ARIS analyzer service.
    > > For more information on this free incident handling, management
    > > and tracking system please see: http://aris.securityfocus.com
    > >
    > >
    >
    >
    > John "Jamie" Marquart		|     This message posted 100% MS free.
    > Digital Library SysAdmin	|  Work: 812-856-5174   Pager: 812-334-6018
    > Indiana University Libraries	|  ICQ: 1131494	 	D'net Team:  6265
    >
    
    -- 
    Mikael Olsson
    axess - axessat_private
    system administrator
    
    IT-Security Information Network
    http://www.alldas.de
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Thu Aug 23 2001 - 15:18:29 PDT