Security Incidents mailing list archives

Re: Code Red -- AGAIN?!?


From: "Jay D. Dyson" <jdyson () treachery net>
Date: Thu, 29 Nov 2001 16:15:15 -0800 (PST)

-----BEGIN PGP SIGNED MESSAGE-----

On Thu, 29 Nov 2001, Steve wrote:

Is anyone else other than me seeing another increase of code red scans
and of course the infected emails?  This morning alone I had 38
different infected messages stopped at my email gateway and looking at
my web logs, there are numerous scans going on as well. 

        I've seen loads of BadTrans, but no Code Red has come up on the
Early Bird radars here or on any other systems I maintain.

        Which IPs are hitting you with Code Red?  Most Code Red scans that
are going on these days are courtesy of APNIC systems that don't have
their clocks appropriately set.

- -Jay

   (    (                                                        _______
   ))   ))   .-"There's always time for a good cup of coffee"-.   >====<--.
 C|~~|C|~~| (>----- Jay D. Dyson -- jdyson () treachery net -----<) |    = |-'
  `--' `--'  `---------- Si vis pacem, para bellum. ----------'  `------'

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: See http://www.treachery.net/~jdyson/ for current keys.

iQCVAwUBPAbBhrlDRyqRQ2a9AQEfKQP+J8CGUmcD72gD7Zu9QNgmPDghW0oPIe9w
beCBWzPK9qAk5PZXAt/LO44PT2oIShBmpmNZpbwb7333UoGQ8ZilJJGWU/ePvmn/
eY6RAOKfqsEYHnuaO7FaLtgMxW3XoUPt+TFJzymymlhnnoyhboQsnmwmd3YMe8Ob
4E3Qk/jw6V4=
=Jaxr
-----END PGP SIGNATURE-----


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: