CrystalLion
Programmer
I have a client who runs Crystal Reports. It seems that when they open a report, it creates the following activities:
TCP: MEWS2006:4508 192.168.10.106:microsoft-ds SYN_SENT
TCP: MEWS2006:4509 192.168.10.106:netbios-ssn SYN_SENT
There is no reason for any internet activity when simply opening a Crystal report. In fact, when they shut down internet access, the reports open properly.
I have seen indications that this could be related to a vulnerability on port 445 which allows a "bot army" attack.
Before I alarm my client, can anyone tell me more based on the little info I have provided?
Thanks for your help.
TCP: MEWS2006:4508 192.168.10.106:microsoft-ds SYN_SENT
TCP: MEWS2006:4509 192.168.10.106:netbios-ssn SYN_SENT
There is no reason for any internet activity when simply opening a Crystal report. In fact, when they shut down internet access, the reports open properly.
I have seen indications that this could be related to a vulnerability on port 445 which allows a "bot army" attack.
Before I alarm my client, can anyone tell me more based on the little info I have provided?
Thanks for your help.