  TK421 Premium join:2004-12-19 Canada
| Veritas Backup Exec Alert
Heads up for anyone using Veritas Backup Exec! A easily exploitable flaw in the software could be responsible for increasing TCP port 10000 scans over the weekend.
From source: Veritas security flaw attacked said by TechSpot.Com: "Veritas Backup Exec Software has a nasty security flaw, and one that may well be being attacked on a big scale as we speak. The software has network enabled recovery and backup functionality that listens on TCP port 10000 for incoming connections, and a flaw in the software means that a buffer overflow condition exists. Now, security outfit iDefense have claimed that they have detected a large increase in port scanning on port 10000, meaning that hackers may be poised to launch a considerable attack on internet connected systems that use this vulnerable software.
"This increase is believed to be attempts to locate vulnerable systems running the Veritas Backup Exec Remote Agent," the alert states."
|
|
  Link Logger Premium,MVM join:2001-03-29 Calgary, AB
·Shaw
| I posted a sample capture of this attack at »www.linklogger.com/TCP10000Capture.htm
There is a sample capture of the other Veritas exploit on TCP port 6101 here »www.linklogger.com/TCP6101Attack.htm
Typically I see one or two attempts of each per day.
Blake -- Vendor: Firewall Logging Software »www.SonicLogger.com - SonicWall and 3Com »www.LinkLogger.com - Linksys, Netgear and Zyxel |
|