Back to list
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Re: HTTP worm?
Aug 28 2007 12:13AM
Joshua J. Talbot (jtalbot securityfocus com)
The DeepSight Threat Management System saw a large spike in similar
activty last weekend. We have seen a large number of hosts
sending SYN|ACK packets with a source port of 80. These packets are
hitting our sensors on ports 1000 - 2000, roughly. This actvity is
consistent with backscat...
[ more ]
Copyright 2010, SecurityFocus