Security Incidents mailing list archives
Code Red - same IPs or different?
From: Kee Hinckley <nazgul () somewhere com>
Date: Wed, 1 Aug 2001 22:06:33 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I've seen numbers that seem to indicate that we've reached saturation about half as many hosts as last time. The question is--are these new hosts, or did 50% of the server admins miss getting notified, despite attempts to alert them? If these were indeed old IP addresses, I would have expected worm activity to start out at a much larger level than last time, unless folks just rebooted their machine and didn't actually install a patch. - -- Kee Hinckley - Somewhere.Com, LLC http://consulting.somewhere.com/ I'm not sure which upsets me more: that people are so unwilling to accept responsibility for their own actions, or that they are so eager to regulate everyone else's. -----BEGIN PGP SIGNATURE----- Version: PGP Personal Security 7.0.3 iQA/AwUBO2i8jyZsPfdw+r2CEQIA/gCgstxkC4fz3LGpE6/qHXREnkYyAggAn2qK dESoorgLlmNLJGjsCkfA6cHo =JUCR -----END PGP SIGNATURE----- ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Code Red - same IPs or different? Kee Hinckley (Aug 01)