Security Incidents mailing list archives

Re: The Return of Code Red II?


From: "Jay D. Dyson" <jdyson () treachery net>
Date: Tue, 11 Mar 2003 11:05:16 -0800 (PST)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, 11 Mar 2003, Stan Burditzman wrote: 

Is anyone else seeing traffic generated by Code Red II.  I thought it
wasn't supposed to propagate after 10/01?  Unfortunately I don't have
the whole string but here is the RealSecure Event. 

        Code Red (1 and 2) never really went away.  It pops up on occasion
over here as well.  Bear in mind that people who don't patch their systems
against 2+ year-old vulnerabilities aren't likely to have their system's
clock set correctly either.

        The last Code Red attempt I saw came down the pipeline about four
months ago.  It originated from Youngshin High School in Korea.

- -Jay

  (    (                                                        _______
  ))   ))   .-"There's always time for a good cup of coffee"-.   >====<--.
C|~~|C|~~| (>----- Jay D. Dyson -- jdyson () treachery net -----<) |    = |-'
 `--' `--'  `-Better to die with honor than live without it.-'  `------'

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (TreacherOS)
Comment: See http://www.treachery.net/~jdyson/ for current keys.

iD8DBQE+bjNwTqL/+mXtpucRAmJTAKDhajFg4n0s58W7JWOp5VEX+2fX0ACg4jAr
An+4Ob9U+aOmWhYoxzLvktM=
=JQou
-----END PGP SIGNATURE-----


----------------------------------------------------------------------------

<Pre>Lose another weekend managing your IDS?
Take back your personal time.
15-day free trial of StillSecure Border Guard.</Pre>
<A href="http://www.securityfocus.com/stillsecure";> http://www.securityfocus.com/stillsecure </A>



Current thread: