Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: RE: Apache Worm / ddos

RE: Apache Worm / ddos

From: Golden_Eternity <bhodi_jabir_at_yahoo.com>
Date: Mon, 8 Jul 2002 09:00:39 -0700

> many ppl talking about a "sloppy fashion" the worm was coded, and
> that it is quite "harmless" because "it causes no damage"...
>
> What about the udp flood? Can anyone explain that?

There are some strings that indicate that it is also designed for DoS (see
below). Domas Mituzas reported that the worm attempts to listen on 2001/udp.
I don't know why a compromised host would be the target of an attack,
though. Perhaps someone who has looked over the source could give a better
answer.

        Cannot packet local networks
        Udp flooding target
        Tcp flooding target
        Sending packets to target
        Dns flooding target

http://www.bhodisoft.com/Sec/apache-worm.txt

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Jul 08 2002

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos