[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: IDS: Is this laptop at high security risk?


  • To: ids@uow.edu.au
  • Subject: Re: IDS: Is this laptop at high security risk?
  • From: Gaute Gullesen <crazy-b@netcom.no>
  • Date: Sun, 11 Feb 2001 15:40:52 +0100

Archive: http://msgs.securepoint.com/ids
FAQ IDS: http://www.sans.org/newlook/resources/IDFAQ/ID_FAQ.htm
FAQ NIDS: http://www.ticm.com/kb/faq/idsfaq.html
IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
HELP: Having problems... email questions to ids-owner@uow.edu.au
NOTE: Remove this section from reply msgs otherwise the msg will bounce.
SPAM: DO NOT send unsolicted mail to this list.
UNSUBSCRIBE: email "unsubscribe ids" to majordomo@uow.edu.au
-----------------------------------------------------------------------------
On Sunday, February 11, 2001, 1:55:00 AM, Ivan Fox wrote:
> I did a scan on a laptop running W2K Professional for a salesperson using
> SuperScan and obtained the following results. I am wondering why so many
> ports are open?  Some ports sounds scary, e.g., netbus backdoor,
> stone-design-1, back orffice!!  Any info/comments/pointers are badly needed.

many of these ports are known to be used by backdoors. so many that i
would find it more likely the laptop is running some kind of logging
software to expose attack attempts. i wouldn't settle with this
explanation though, you better find out for sure.

================================================================
 Gaute Gullesen <crazy-b@netcom.no>       phone: +47 922 48 107
 Fingerprint: AF90 7B96 9835 AA26 4DCC D4F7 1B82 110C B5DF 00B1
 Support the antiSecurity movement!:   http://anti.security.is/
================================================================