North American Network Operators Group|
Date Prev | Date Next |
Date Index |
Thread Index |
Author Index |
Re: New worm / port 1434?
- From: Marshall Eubanks
- Date: Sat Jan 25 12:43:13 2003
Can you give me any information about which multicast group addresses
were being attacked ?
I have seen very little sign of this worm in interdomain multicast; it
does not seem
to be causing MSDP havoc the way that the RAMEN worm did.
On Saturday, January 25, 2003, at 06:00 AM, email@example.com wrote:
This one seemed to be particularly nasty as it was generating traffic to
multicast addresses too. It caused a nice flood on the switched ethernet
segment I had a vulnerable box on. (And took out a router in the
finger firstname.lastname@example.org for further information
Geek Code V3.12: GCS/M/S d- s+:+ !a C++ UL++++$ P++ L+++ !E W++ !N
!M PS PE V-- Y+ PGP t+@ 5++ X !R tv+@ b+++@ !DI D? G e++ h+ y?
Multicast Technologies, Inc.
10301 Democracy Lane, Suite 410
Fairfax, Virginia 22030
Phone : 703-293-9624 Fax : 703-293-9609
e-mail : email@example.com
Test your network for multicast :
Status of Multicast on the Web :