Security Incidents mailing list archives

RE: .ida Intrusion Attempt


From: "Yom, Francis" <fyom () symmsys com>
Date: Thu, 19 Jul 2001 14:08:34 -0400

Hi all,

I have a question regarding this .ida intrusion.

I had installed MS's hot fix last month.  I have detected this exploit
attempt over the past few days via the IIS log files.  The HTTP status
code for these attempts is 200 which is 'OK' or 'SUCCESSFULL'

I have not detected that the worm did infect my systems.  Are the above
status codes normal for the hotfix or did I truly get infected?

Many thanks,
Francis


----------------------------------------------------------------------------


This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see:

http://aris.securityfocus.com


Current thread: