On Friday, August 29, 2003 3:57 PM, Bryce C wrote:
> I was just running through my fw logs and I noticed ALOT of hits on
> port 901 (SWAT usually) and all from Cox addresses.
A Google search turned up these links:
http://www.dshield.org/pipermail/list/2003-June/008480.php.
http://www.dslreports.com/forum/remark,7041312~root=security,1~mode=flat
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.netdevil.ht
ml
Looks like the kiddiez are playing with something called "NetDevil".
~Jeff