Koepi
1st October 2002, 10:53
Hi,
since it's not video related I'll post here ;)
Since ~3-4 days I can find many netbios-ssn (port 139) connection attempts in our networks from the outside. I know that e.g. Nimda infected windows shares but it never actively scanned the "entire" internet - it just used the "windows neighbourhood" for this.
So this must be some new virus/worm scanning in the wild for potential victim systems.
I don't know if it's a samba exploit or if just windows is affected (I upgraded to latest stable samba 2.2.5 and blocked that port within the firewall additionally to my old smb.conf denying connects from there... just to be "sure" ;) ).
My question is: has anyone further informations about this? I can't find anything on bugtraq or in the emergency-virii-announcements of the antivirii-companies...
Thanks,
regards,
Koepi
since it's not video related I'll post here ;)
Since ~3-4 days I can find many netbios-ssn (port 139) connection attempts in our networks from the outside. I know that e.g. Nimda infected windows shares but it never actively scanned the "entire" internet - it just used the "windows neighbourhood" for this.
So this must be some new virus/worm scanning in the wild for potential victim systems.
I don't know if it's a samba exploit or if just windows is affected (I upgraded to latest stable samba 2.2.5 and blocked that port within the firewall additionally to my old smb.conf denying connects from there... just to be "sure" ;) ).
My question is: has anyone further informations about this? I can't find anything on bugtraq or in the emergency-virii-announcements of the antivirii-companies...
Thanks,
regards,
Koepi