Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Incidents
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
RE: Odd worm traffic? Aug 26 2003 07:42PM
Jerry Heidtke (jheidtke fmlh edu)

This is probably a Blaster-infected machine with an incorrect date, or
just rebooted, trying it's DOS against windowsupdate.com. The ISP
probably added a DNS entry pointing windowsupdate.com to 127.0.0.1.
Blaster sends a packet to 127.0.0.1:80 with a spoofed source address
within the local address ...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus