Re: Summary of large-scale portscanning detects
"Jason \"JC\" Monroe" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 2005-01-20 at 19:26, [email protected] wrote: > The following extracts show the beginning and ending of scan activity > was detected on my network. The number following each set is the total > number of probes for that source. Timestamps are GMT-0600. > > Jan 19 06:01:54 68.164.218.138:2433 -> xxx.yyy.1.1:3306 SYN ******S* > Jan 19 06:01:54 68.164.218.138:2434 -> xxx.yyy.1.2:3306 SYN ******S* The only tools that I've located have been mysqlf**k and another brute forcer. Has anyone else found evidence of a MySQL based worm? Thanks, JC _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions