[Snort-users] port 12345

SAHUT Christophe christophe.sahut at ...5412...
Wed Mar 27 06:12:04 EST 2002


[ Mon, 25 Mar 2002 20:40:06 +0100 ]
Craig Woods <root at ...5405...> a écrit :

|  I have done some checking, and will do some more but, in the meanwhile,
|  I was
|  wondering if anyone has seen increased activity with regards to port
|  12345. The
|  assigned service is something called NetBus. Does anyone have some info
|  on this 
|  service and/or port or can they point me in the right direction? I am

NetBus is a famous (a little bit old) trojan. It's BO2k-like, and used
to remotely control a computer (using NIL, or something else). Some scanners
try to connect to this port, hoping a NetBus server is running.

It also could be due to a 'default' port of a soft (Trend Micro Office
 Scan, I think, uses port 12345)...

|  seeing an
|  increasing number of probes for port 12345.
|  
|  Thanks,
|  Dr John,
|  the night tripper

Hope it helps

csahut


|  
|  _______________________________________________
|  Snort-users mailing list
|  Snort-users at lists.sourceforge.net
|  Go to this URL to change user options or unsubscribe:
|  https://lists.sourceforge.net/lists/listinfo/snort-users
|  Snort-users list archive:
|  http://www.geocrawler.com/redir-sf.php3?list=snort-users
|  
|  
|  .
|  
|  
|  
|  
|  .
|  
|  




More information about the Snort-users mailing list