Archive for June, 2008

HP StorageWorks Scanning

June 6, 2008 by Jose Nazario

The Tipping Point ZDI initiative recently published a security advisory about pre-authentication overflows in HP StorageWorks (CVE-2008-1661). Shortly after the vulnerability was announced, exploit code became public via the Metasploit project. Within a few days, we started seeing an increase in scanning for the two TCP ports the vulnerable daemon listens on: TCP ports 1100 [...]

Read More

Malcode and DDoS Locations: May 2008

June 5, 2008 by Jose Nazario

We’ve been very busy here in the offices, especially after a week or so away in Asia. Here’s some quick stats for May, 2008. It’s interesting to see who is hosting the malware and the attack botnets. First up, a set of major malcode distribution points for May, 2008, by country, ASN, and even by [...]

Read More