On Tue, 16 Apr 2002, Dmitri Smirnov wrote: > need an advice. I've got more them 20 "HTTP CONNECT" IDS alerts (BugTraq > id 4131) from 3 diff. sources for today and yesterday. Looks like some > tool is out and people started to use it. The only problem is: I don't > understand why people are trying to use port 80 to connect to port 443 > (which is usually open to a world in my case). Spammers or irc kiddies looking for proxies, perhaps? -- _____________________________________________________ Michal Zalewski [lcamtufat_private] [security] [http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};: =-=> Did you know that clones never use mirrors? <=-= http://lcamtuf.coredump.cx/photo/ ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Wed Apr 17 2002 - 08:59:44 PDT