Back to list
*Note: Email address will appear as "user domain ext" to prevent harvesting.
RE: Source port 445,80
Sep 06 2007 04:17AM
Wong Yu Liang (wong yuliang vads com)
I suspected so. Possibly a worm propagation and the ips detected the
*return* traffic. But yet the alerts from my ips is very strange. Some
172.16.1.254:80 -> 172.17.17.103:1434 MSSQL buffer overflow detected
172.16.1.254:80 -> 172.17.17.103:1434 MSSQL buffer overflow detec...
[ more ]
Copyright 2010, SecurityFocus