Security Incidents mailing list archives
Re: The Return of Code Red II?
From: Roger Thompson <rthompson111 () sprintpcs com>
Date: Tue, 11 Mar 2003 14:02:43 -0500
At 11:24 AM 3/11/2003 -0600, you wrote:
Is anyone else seeing traffic generated by Code Red II. I thought it wasn't supposed to propagate after 10/01? Unfortunately I don't have the whole string but here is the RealSecure Event.
Yeah. It's two bytes different. The two bytes control the 'stop' year. This one won't ever stop, although it will still take a vacation from October to December each year. I'm calling it CodeRed.F.
See... www.wormwatch.org Roger Regards Roger Thompson Technical Director of Malicious Code Research TruSecure Corporation www.trusecure.com www.wormwatch.org ---------------------------------------------------------------------------- <Pre>Lose another weekend managing your IDS? Take back your personal time. 15-day free trial of StillSecure Border Guard.</Pre> <A href="http://www.securityfocus.com/stillsecure"> http://www.securityfocus.com/stillsecure </A>
Current thread:
- The Return of Code Red II? Stan Burditzman (Mar 11)
- Re: The Return of Code Red II? Jay D. Dyson (Mar 11)
- SV: The Return of Code Red II? Peter Kruse (Mar 11)
- Re: The Return of Code Red II? Christine Kronberg (Mar 12)
- <Possible follow-ups>
- Re: The Return of Code Red II? David C. Lewis (Mar 11)
- Re: The Return of Code Red II? Kevin Patz (Mar 11)
- Re: The Return of Code Red II? Roger Thompson (Mar 11)