RE: brightstor/arcserve backup client hacked

"Eric Hines" <[email protected]> Tue, 1 Mar 2005 09:00:25 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Andrew,

Does the Tcpdump contain packets from the actual attack? Would like to
create some Snort signature based on it. 


Best Regards,


Eric Hines, GCIA, CISSP
CEO, President, Chairman
Applied Watch Technologies, LLC
1134 N. Main St.
Algonquin, IL 60102
Tel: (877) 262-7593 x327
Fax: (877) 262-7593
Web: http://www.appliedwatch.com
 
-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Andrew Daviel
Sent: Monday, February 28, 2005 4:54 PM
To: [email protected]
Subject: [Intrusions] brightstor/arcserve backup client hacked



Yesterday we had a number of Windows machines hacked via port 41523. The
attacker came in from a cable modem in Portugal then installed a rootkit
from the Czech Republic ...

This seems to be a vulnerability in Computer Associates BrightStor backup
(ARCserve)

http://archives.neohapsis.com/archives/bugtraq/2005-02/0123.html

some tcpdump data availalbe if anyone interested


--
Andrew Daviel, TRIUMF, Canada
Tel. +1 (604) 222-7376  (Pacific Time)
[email protected]
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions