The buzz on the boards is that this is a variation of the lion worm

-MJL

-----Original Message-----
From:   Ivan More [SMTP:[EMAIL PROTECTED]]
Sent:   Wednesday, May 16, 2001 6:49 AM
To:     [EMAIL PROTECTED]
Cc:     [EMAIL PROTECTED]
Subject:        [FW1] port 10008


Hi all you Gurus,

I have seen quite a number of drop packets using port
10008 in the FW-1 log. Some of these packets are
coming from unknown IPs when I do NSlookup. 

The logs look like this

service    source            Destination 
10008      211.168.167.199   255.255.255.255
10008      193.233.83.66     255.255.255.255

Anyone got an explaination?


Cheers,
I. More
 

_______________________________________________________
Do You Yahoo!?
Get your free @yahoo.ca address at http://mail.yahoo.ca


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to