Security Incidents mailing list archives

RE: UDP scans from CodeRed-infected hosts


From: Tony Langdon <tlangdon () atctraining com au>
Date: Wed, 8 Aug 2001 13:13:07 +1000

I am beginning to see UDP probes coming from servers which I 
had earlier 
identified as servers infected with CodeRed II.

Looks like things are about to become interesting.....

Any information?  Port numbers, etc?

So far, no indications here of UDP scans yet.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: