Full Disclosure mailing list archives
Re: Web counter in the new Swen/Gibe.F worm
From: Cael Abal <lists () onryou com>
Date: Fri, 19 Sep 2003 11:52:48 -0400
I was tracking the number of infected computers, but around 4:30am Pacific the counter was replaced with a GIF image reading: WARNING: Your computer may be infected by W32/Swen@MM worm. It's no joke. See mcaffee.com for info. The last good number I have for the hit count was 1,576,803 at 4:30am. It's a shame the counter was replaced, this gave us a good idea of how many hosts were infected and could reveal real numbers of the rate of infection - I'm still recieving these emails, over 100 overnight. Maybe the admins of vutbr.cz would open their web logs to give us more accurate information about the point of origin and rate of spread. If anyone wants the numbers I collected (I have data from the 18th at 13:56 through 4:30am today) I'd be happy to provide them.
Correction -- it *would've* been valuable, if the url hadn't been publicized. As it is, the only useful information would have to come from the vutbr.cz web logs. Without stripping out all the polluting GETs from web browsers the data is meaningless... Thankfully we've got user agents to filter by.
Incidentally, it might be valuable to carefully scrutinize those web logs -- there's an excellent chance that the first non-worm-originated hit of that web counter came from the worm's creator.
Cael _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Web counter in the new Swen/Gibe.F worm Richard M. Smith (Sep 18)
- Re: Web counter in the new Swen/Gibe.F worm B.K. DeLong (Sep 18)
- Re: Web counter in the new Swen/Gibe.F worm S G Masood (Sep 18)
- Swen/Gibe.F Worm - Some New Info (was RE: Web counter in the new Swen/Gibe.F worm) S G Masood (Sep 18)
- Re: Web counter in the new Swen/Gibe.F worm security (Sep 19)
- Re: Web counter in the new Swen/Gibe.F worm J. Race (Sep 19)
- Re: Web counter in the new Swen/Gibe.F worm Cael Abal (Sep 19)
- Re: Web counter in the new Swen/Gibe.F worm security (Sep 20)
- <Possible follow-ups>
- Re: Web counter in the new Swen/Gibe.F worm Timo Schoeler (Sep 18)
- Re: Web counter in the new Swen/Gibe.F worm security (Sep 19)
- Re: Web counter in the new Swen/Gibe.F worm B.K. DeLong (Sep 18)