Re: brightstor/arcserve backup client hacked
[email protected] Wed, 2 Mar 2005 07:26:22 -0500
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <OFBBE18881.77B22652-ON85256FB8.0043FF58-05256FB8.00440DAA@mailrouter.net> |
> Message: 1 > Date: Mon, 28 Feb 2005 14:53:35 -0800 (PST) > From: Andrew Daviel <[email protected]> > Subject: [Intrusions] brightstor/arcserve backup client hacked > To: [email protected] > Message-ID: <[email protected]> > Content-Type: TEXT/PLAIN; charset=US-ASCII > > > > Yesterday we had a number of Windows machines hacked via port > 41523. The attacker came in from a cable modem in Portugal then > installed a rootkit from the Czech Republic ... > > This seems to be a vulnerability in Computer Associates BrightStor backup > (ARCserve) > > http://archives.neohapsis.com/archives/bugtraq/2005-02/0123.html > > some tcpdump data availalbe if anyone interested > Hi David, Interested in the capture, particularly if malware is included (as in, you caught the transfer of the rootkit and/or other hacking tools). Thanks _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions