Security Incidents mailing list archives

Re: HTTP connections


From: Ryan Russell <ryan () securityfocus com>
Date: Thu, 19 Jul 2001 17:39:35 -0600 (MDT)

On Thu, 19 Jul 2001, Gillard, Paul wrote:


Has anybody any ideas on why this should increase so suddenly? Maybe
attempts from "code red" infected machines?


Most likely.  On my home machine, I've gone from usually about 0 port 80
per day, to 19 in the last 3 hours.  I started listening on port 80 with
netcat, and it's CodeRed so far in every case.  This thing is running
pretty rampant.

                                        Ryan



----------------------------------------------------------------------------


This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see:

http://aris.securityfocus.com


Current thread: