[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: R41 in draft-ietf-v6ops-cpe-simple-security-07






On Tue, 28 Jul 2009, Iljitsch van Beijnum wrote:

Anyway the bots are preferring some exotic port numbers or portnumber that is usually not firewalled: 80 and 443.

If a bot wants to receive incoming traffic on those ports it would have to signal the CPE that it wants to be de-firewalled for those ports.

(Not that malware spreads by listening on those ports, listening on ports is _so_ 2003.)

Yes we are talking the same. Bots are usually dropped to compromised webservers to provide spreading points
	Best Regards,
		Janos