On Mon, 20 Jan 2003 01:10:19 +1100 Trevor Rhodes <[EMAIL PROTECTED]> wrote:
> The following is a third of my logfile. Is this not normal for you > folks? Why do so many people get so worried when something shows up. Why? well just read what I added to almost all your submitted port attacks. Sorry to say this, but this is ignorance. You are being probed from all sides my trojans, and you don't realise it. > It did, it does and it always will while ever the Script Kiddies that > Stephen loves so much are around. Therse aren't scrip-kiddies, but documented trojans, probably most are from Windows, but like the one I had... Redhat Linux. It's not normal for people to try ftp into you, or fetch mail from your server... but look at the list of trojans... there are many for those 2 ports. > From my DI-704P Ethernet Broadband Routers Log: port 137 = (UDP) - Bugbear, Msinit, Opaserv, Qaz port 1433 = Voyager Alpha Force port 1524 = Trinoo port 21 = ADM worm, Back Construction, Blade Runner, BlueFire, Bmail, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, FreddyK, Invisible FTP, KWM, MscanWorm, NerTe, NokNok, Pinochet, Ramen, Reverse Trojan, RTB 666, The Flu, WinCrash, Voyager Alpha Force port 22 = InCommand, Shaft, Skun port 25 = Antigen, Barok, BSE, Email Password Sender , Gip, Laocoon, Magic Horse, MBT , Moscow Email trojan, Nimda, Shtirlitz, Stukach, Tapiras, WinPC port 3128 = Reverse WWW Tunnel Backdoor , RingZero port 3389 = <nothing I can find> port 443 = Slapper port 445 = Nimda port 515 = MscanWorm, Ramen port 6346 = <nothing I can find, I believe it's the giFT port> Just thought I would let you know ;-) Let's just hope you have the non-logged ports closed ;-) Greetings Ralph -- http://tuxpower.f2g.net/ http://axljab.homelinux.org:8080/ "I have opinions of my own, strong opinions, but I don't always agree with them." - George H. W. Bush
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com