Re: Fwd: bugtraq.c httpd apache ssl attack
Noah L. Meyerhans wrote:
There are two worms. One is old, one is new. The one at
http://188.8.131.52/bugtraq.c.txt is the new one. It communicates via
UDP port 2002, though I'm not actually sure what data gets sent on that
Thanks for the information.
I most probably have a tcpdump log of those packets (hopefully). I'm
still trying to get it here, but I'm not sure if the log still exists.
It has been done yesterday during the attack on an intermediate linux