Security Incidents mailing list archives
Re: Strange behaviour
From: core.lists.incidents () CORE-SDI COM (Iván Arce)
Date: Tue, 18 Jan 2000 14:05:20 -0300
Richard Bejtlich wrote:
Hi Anthony, Poking around the web, I found out port 2766 is typically part of an sscan, as reported by CERT, here: http://www.cert.org/incident_notes/IN-99-01.html That doc reports port 2766 tcp is "Solaris listen/nlps_server."
As to the vulnerability, I'm not sure.
a buffer overflow in nlps_server is present at least up to version 2.5.1 of Solaris, this is more than a year old and i stumbled accross an exploit for Solaris x86 many months ago, i have no idea if its reported, i just did a quick search on securityfocus, sunsolve, and other places an didnt find any references to nlps_server/listen except for a y2k patch. -ivan -- "Understanding. A cerebral secretion that enables one having it to know a house from a horse by the roof on the house, It's nature and laws have been exhaustively expounded by Locke, who rode a house, and Kant, who lived in a horse." - Ambrose Bierce ==================[ CORE Seguridad de la Informacion S.A. ]========= Iván Arce Presidente PGP Fingerprint: C7A8 ED85 8D7B 9ADC 6836 B25D 207B E78E 2AD1 F65A email: iarce () core-sdi com http://www.core-sdi.com Pte. Juan D. Peron 315 Piso 4 UF 17 1038 Capital Federal Buenos Aires, Argentina. Tel/Fax : +(54-11) 4331-5402 Casilla de Correos 877 (1000) Correo Central ===================================================================== --- For a personal reply use iarce () core-sdi com
Current thread:
- Re: Strange behaviour Dante Mercurio (Jan 17)
- <Possible follow-ups>
- Re: Strange behaviour Iván Arce (Jan 18)
