Port UDP 3049

From: Ryan Russell (ryanat_private)
Date: Sat Mar 09 2002 - 15:40:37 PST

  • Next message: Chris Faulhaber: "Re: sshd: PAM pam_set_item: NULL pam handle passed"

    I'm looking at some backdoor code that listens on UDP 3049.  I can see
    through ARIS TMS that a number of users have recoded scans for that port.
    I'm wondering if anyone has capture one of the packets, and if they could
    send me a copy?
    
    				Ryan
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sun Mar 10 2002 - 17:06:50 PST