Re: [SLUG] Hmmmmm

From: Russell Hires (rhires@earthlink.net)
Date: Sat Apr 20 2002 - 01:18:45 EDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Below is taken from portsdb.org...I don't have a clue what ms-slipstream is.
Does that help?

You should also have a look at grc.com...great site (not very linux, sadly),
but decent at the security analysis...

Russell

3132
TCP
ms-slipstream

MS-Slipstream
3132
UDP
ms-slipstream
IANA
IANA
MS-Slipstream

On Saturday 20 April 2002 00:49 am, you wrote:
> My router lights looked like a science fiction computer just before I left
> for work yesterday afternoon, but a quick check of the logs didn't turn up
> anything scary. I bounced every one of the servers I am running and nothing
> changed so I went off to work. When I got home a half hour ago, the same
> situation was still occuring.
>
> This time I saw the ip address 209.61.157.231 coming in on port 3132 / 3133
> and being responded to via http off my wifes Win 98 machine (running Zone
> Alarm). So I checked that address out with nmap and almost instantly the
> wild lights on the router immediately went silent. Whois says the IP
> address is owned by a bloke in Sault Ste. Marie, ON.
>
> To the best of my knowledge, my wifes machine does not have any form of
> HTTP installed.
>
>
> Any thoughts on this would be welcomed.
>
> Bill

- --
Linux -- the OS for the Renaissance Man
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8wPo4AqKGrvVshJQRAt5dAJ9lJWJlOnXNBIcNkd3BxygNo+OBxACg3JEN
rrgaaa/gT6eYUX4xDU+MqBM=
=z+ma
-----END PGP SIGNATURE-----



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 20:19:11 EDT