GazNET

Contents
Props
Hosted By
DreamHost
Powered By
Movable Type
6:28 PM
« Back | Main | Next »


I've been noticing a steady flurry of probes to port 17300 on my machine over the past month or so. Until now I've just passed it off as some random port scan by a bored script kiddie. Today, however, I noticed a surge of probes to that port, so I decided to do a little research to see what the cause could be.

Well, it turns out that these probes are caused by someone using a client program to probe port 17300 for the presence of a backdoor program dropped by the W32.Weird virus - otherwise known as Kuang. Of course, my machine isn't infected by this virus, but that doesn't stop people from seeing if it is.

The solution to dealing with this threat is to make sure you have decent, up to date anti-virus software, so that the virus is stopped before it drops the backdoor program. And if you really want to go overboard, create a firewall rule to block ingress access to TCP port 17300, so the client program has no way in.