Security Incidents mailing list archives
Re: CodeRed
From: Ryan Russell <ryan () securityfocus com>
Date: Thu, 19 Jul 2001 21:50:53 -0600 (MDT)
Yes, responding to my own post, I know (actually, I left incidents on the
post below by mistake...)
As several people have pointed out, the person who made the 1.17M claim
later revised it to "only" about 200K or so. And that's just him. I have
no real difficulty believing that we've in the 100's of thousands
neighborhood at this point.
This is the most "successful" worm I've ever seen. Parts of the code are
damn clever as well (take a real close look at how it "hacks" the web
pages.)
The worm would also be dead simply to modify, as well. All that you would
need for simple mods is a hex editor. I'm pretty sure we'll see copycats
in the next few days.
Things could get pretty bad in the short term.
Ryan
On Thu, 19 Jul 2001, Ryan Russell wrote:
I'm a bit stunned at the moment by a note to Bugtraq from a guy at LBL who claims that 1.17 Million different IP addresses have tried his address space, meaning that at least that many different IIS boxes have been nailed. I'm rather amazed.
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- CodeRed Ryan Russell (Jul 19)
- Re: CodeRed James T Kirk (Jul 20)
- <Possible follow-ups>
- Re: CodeRed Ryan Russell (Jul 19)
- Re: CodeRed Ryan Russell (Jul 19)
- RE: CodeRed Ivan (Jul 19)
- RE: CodeRed Fulton L. Preston Jr. (Jul 19)
- Re: CodeRed Ryan Russell (Jul 20)
- RE: CodeRed Tulchinskiy, Sasha (Jul 20)
- SIRCAM WORM? borakovej (Jul 24)
- Re: SIRCAM WORM? acz [iSecureLabs] (Jul 24)
- SIRCAM WORM? borakovej (Jul 24)
- CodeRed terminator (Jul 21)
