AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.html?storyid=3093
Last Updated: 2007-07-03 22:28:54 UTC ~ "…Some outlets have reported on the major increase in port 5901 scanning we're seeing in our (your) logs. This increase is not uncollaborated. Others* are reporting very similar increases. Port 5901 is generally used as the first VNC (Virtual Network Computing) display on Linux machines, and the second one on Windows hosts. There are a number of popular implementations of VNC, of which the most popular are UltraVNC, TightVNC and RealVNC. A number of recent security vulnerabilities have added incentive for attackers to start indexing hosts running this service… It likely indicates attackers may have been successful in compromising a number of hosts using vulnerabilities in this service, increasing their belief in VNC as a viable attack vector. It could also indicate the release of new attack tools…"
* http://asert.arbornetworks.com/2007/07/net…-tcp-port-5405/
(Graphics available at both URL's above.)

- http://isc.sans.org/diary.html?storyid=3093
Last Updated: 2007-07-03 22:28:54 UTC ~ "…Some outlets have reported on the major increase in port 5901 scanning we're seeing in our (your) logs. This increase is not uncollaborated. Others* are reporting very similar increases. Port 5901 is generally used as the first VNC (Virtual Network Computing) display on Linux machines, and the second one on Windows hosts. There are a number of popular implementations of VNC, of which the most popular are UltraVNC, TightVNC and RealVNC. A number of recent security vulnerabilities have added incentive for attackers to start indexing hosts running this service… It likely indicates attackers may have been successful in compromising a number of hosts using vulnerabilities in this service, increasing their belief in VNC as a viable attack vector. It could also indicate the release of new attack tools…"
* http://asert.arbornetworks.com/2007/07/net…-tcp-port-5405/
(Graphics available at both URL's above.)