Security Incidents mailing list archives
RE: Apache Worm / ddos
From: "Golden_Eternity" <bhodi_jabir () yahoo com>
Date: Mon, 8 Jul 2002 09:00:39 -0700
many ppl talking about a "sloppy fashion" the worm was coded, and that it is quite "harmless" because "it causes no damage"... What about the udp flood? Can anyone explain that?
There are some strings that indicate that it is also designed for DoS (see below). Domas Mituzas reported that the worm attempts to listen on 2001/udp. I don't know why a compromised host would be the target of an attack, though. Perhaps someone who has looked over the source could give a better answer. Cannot packet local networks Udp flooding target Tcp flooding target Sending packets to target Dns flooding target http://www.bhodisoft.com/Sec/apache-worm.txt ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- Apache Worm / ddos Thorsten Schroeder (Jul 08)
- RE: Apache Worm / ddos Golden_Eternity (Jul 08)
- Re: Apache Worm / ddos Alexander Bochmann (Jul 08)
- Re: Apache Worm / ddos Dave Mitchell (Jul 11)