Security Incidents mailing list archives

Code Red - same IPs or different?


From: Kee Hinckley <nazgul () somewhere com>
Date: Wed, 1 Aug 2001 22:06:33 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I've seen numbers that seem to indicate that we've reached saturation 
about half as many hosts as last time.  The question is--are these 
new hosts, or did 50% of the server admins miss getting notified, 
despite attempts to alert them?  If these were indeed old IP 
addresses, I would have expected worm activity to start out at a much 
larger level than last time, unless folks just rebooted their machine 
and didn't actually install a patch.
- -- 

Kee Hinckley - Somewhere.Com, LLC
http://consulting.somewhere.com/

I'm not sure which upsets me more: that people are so unwilling to accept
responsibility for their own actions, or that they are so eager to regulate
everyone else's.

-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Security 7.0.3

iQA/AwUBO2i8jyZsPfdw+r2CEQIA/gCgstxkC4fz3LGpE6/qHXREnkYyAggAn2qK
dESoorgLlmNLJGjsCkfA6cHo
=JUCR
-----END PGP SIGNATURE-----

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: