OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: ftpd: the advisory version
From: Elias Levy (aleph1SECURITYFOCUS.COM)
Date: Thu Jul 06 2000 - 12:19:17 CDT


Date: Wed, 5 Jul 2000 22:13:21 +0100
From: David Malone <dwmalonemaths.tcd.ie>
To: Ron DuFresne <dufresneWINTERNET.COM>
Cc: BUGTRAQSECURITYFOCUS.COM
Subject: Re: ftpd: the advisory version
Message-ID: <20000705221321.A60535walton.maths.tcd.ie>
References: <Pine.GSO.4.05.10007031512580.12698-100000tundra.winternet.com>

On Mon, Jul 03, 2000 at 03:14:34PM -0500, Ron DuFresne wrote:
> While others are stating no noticed increase in scans and attempts to
> exploit this newfound root shell, we are seeing some evidence of such
> attempts these last few days.

I've seen two scans of our subnets recently, one a few days before
the problem was announced on bugtraq and one a few days after. The
scans just seemed to connect and go away again, so I presume they
were just collecting ftpd banners.

        David.