Security Incidents mailing list archives

"Code Red" worm questions


From: "w1re p4ir" <w1rep4ir () disinfo net>
Date: 18 Jul 2001 15:43:59 -0000

I've read practically everything about this worm that has been released. But there are a few questions that I have. 
First off, I know the first exploit was written by hsj and it used the offsets for the japanesse version of IIS. Now in 
this new worm, has the code been modified with US (or other) offsets to attack english versions? I have already had a 
call regarding a possible "break in attempt." with very little other information. I would like to be able to them 
either they are vulnerable to this worm or not. Thank you,
w1re

____________________________________________________
FREE Disinformation E-book - http://www.disinfo.com


----------------------------------------------------------------------------


This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see:

http://aris.securityfocus.com


Current thread: