could it be a Hack'a'tack or BO running on non-default ports ? The ports
cited are close to the ports for both these trojans.
===================================================================
Larry Chin {[EMAIL PROTECTED]} Technical Specialist - ISC
Sprint Canada 2550 Victoria Park Avenue
Phone: 416.496.1644 ext. 4693 Suite 200, North York, Ontario
Fax: 416.498.3507 M2J 5E6
===================================================================
On Mon, 30 Aug 1999, Dave Gillett wrote:
> Somebody recently scanned our address range using UDP; all packets had
> source port #31790 and dest port #31789. That looks likely to be a trojan,
> but I don't recognize it as the default port numbers of any one I have info
> on. ANybody recognize it?
>
>
> David G
> -
> [To unsubscribe, send mail to [EMAIL PROTECTED] with
> "unsubscribe firewalls" in the body of the message.]
>
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]