[Malvern] Advice needed.

Geoff Bagley geoff.bagley at btinternet.com
Wed Feb 14 00:27:00 GMT 2007


As some of you may know, I have been playing with security software.

I have installed (amongst others)  nmap.   Great fun !

I recently found that the older of my two Netgear DG834 ADSL 
firewall/routers has
a spurious port open -  TCP/5190  which is open, and is linked to  aol.

There exists a trojan called MBomber.100 which usually resides on aol 
port TCP/5190.

Is there a more innocent use for this port like "AOL Messenger",  and 
would it leave open a port in my  ADSL box ?

I tried to close the port, but was informed that it was used by another 
program ( presumably
the trojan if that should be the case ).

I note that both these Netgear boxes use Linux, and the newer one came 
with a printed copy of the GPL.

They both appear to work OK.


I guess I would need to log into the OS part of the box, and obtain root 
status in order
to delete the trojan.

Any good advice, other than buying another new one,  appreciated !

Hwyl fawr,

Geoff.



More information about the Malvern mailing list