|
Security Incidents
mailing list archives
RE: Apache Worm / ddos
From: "Golden_Eternity" <bhodi_jabir () yahoo com>
Date: Mon, 8 Jul 2002 09:00:39 -0700
many ppl talking about a "sloppy fashion" the worm was coded, and
that it is quite "harmless" because "it causes no damage"...
What about the udp flood? Can anyone explain that?
There are some strings that indicate that it is also designed for DoS (see
below). Domas Mituzas reported that the worm attempts to listen on 2001/udp.
I don't know why a compromised host would be the target of an attack,
though. Perhaps someone who has looked over the source could give a better
answer.
Cannot packet local networks
Udp flooding target
Tcp flooding target
Sending packets to target
Dns flooding target
http://www.bhodisoft.com/Sec/apache-worm.txt
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
By Date
By Thread
Current thread:
|