Mailing List Archive

CFS detection?
From the INCIDENTS list:
------------------------------------------------------------------
> I'm looking at some backdoor code that listens on UDP 3049. I can see
> through ARIS TMS that a number of users have recoded scans for that port.

3049 is the CFS - Cryptografic File System - service port. Those scans are
probably probing for some weak - or absent - password for a file system.
------------------------------------------------------------------

CFS is rather old and not widely used AFAIK. Should we test if it's here?
Re: CFS detection? [ In reply to ]
Many of the newer Linux Distributions are touting CFS as an advantageous
file system now packaged with their distros. I for one, just recently
bought the SuSE Linux 8.0 Professional distro, and it too made note of
the CFS filesystem. With the rising of security issues being recognized
over the last 5 years, i would say that CFS and other cryptographic
filesystems may be more widely utilized.

I for one; use it for my network backup shares. IMHO i believe that
others may soon realize it's advantages and begin to look into the
"cryptographic" arena for answers. This given......i would like to see
it integrated.

Thomas Jones

Michel Arboi wrote:

>>From the INCIDENTS list:
>------------------------------------------------------------------
>
>>I'm looking at some backdoor code that listens on UDP 3049. I can see
>>through ARIS TMS that a number of users have recoded scans for that port.
>>
>
>3049 is the CFS - Cryptografic File System - service port. Those scans are
>probably probing for some weak - or absent - password for a file system.
>------------------------------------------------------------------
>
>CFS is rather old and not widely used AFAIK. Should we test if it's here?
>
>
>