Re: brightstor/arcserve backup client hacked

[email protected] Wed, 2 Mar 2005 07:26:22 -0500
Newsgroups gmane.comp.security.intrusions
Message-ID <OFBBE18881.77B22652-ON85256FB8.0043FF58-05256FB8.00440DAA@mailrouter.net>
> Message: 1
> Date: Mon, 28 Feb 2005 14:53:35 -0800 (PST)
> From: Andrew Daviel <[email protected]>
> Subject: [Intrusions] brightstor/arcserve backup client hacked
> To: [email protected]
> Message-ID: <[email protected]>
> Content-Type: TEXT/PLAIN; charset=US-ASCII
> 
> 
> 
> Yesterday we had a number of Windows machines hacked via port
> 41523. The attacker came in from a cable modem in Portugal then
> installed a rootkit from the Czech Republic ...
> 
> This seems to be a vulnerability in Computer Associates BrightStor 
backup
> (ARCserve)
> 
> http://archives.neohapsis.com/archives/bugtraq/2005-02/0123.html
> 
> some tcpdump data availalbe if anyone interested
> 
Hi David,

Interested in the capture, particularly if malware is included (as in, you 
caught the transfer of the rootkit and/or other hacking tools).

Thanks
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions