Incidents
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: HTTP worm? Aug 28 2007 12:13AM
Joshua J. Talbot (jtalbot securityfocus com)

Hi Steve,

The DeepSight Threat Management System saw a large spike in similar
activty last weekend. We have seen a large number of hosts
sending SYN|ACK packets with a source port of 80. These packets are
hitting our sensors on ports 1000 - 2000, roughly. This actvity is
consistent with backscat...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus