Security Incidents mailing list archives
Re: CodeRed
From: Ryan Russell <ryan () securityfocus com>
Date: Thu, 19 Jul 2001 21:50:53 -0600 (MDT)
Yes, responding to my own post, I know (actually, I left incidents on the post below by mistake...) As several people have pointed out, the person who made the 1.17M claim later revised it to "only" about 200K or so. And that's just him. I have no real difficulty believing that we've in the 100's of thousands neighborhood at this point. This is the most "successful" worm I've ever seen. Parts of the code are damn clever as well (take a real close look at how it "hacks" the web pages.) The worm would also be dead simply to modify, as well. All that you would need for simple mods is a hex editor. I'm pretty sure we'll see copycats in the next few days. Things could get pretty bad in the short term. Ryan On Thu, 19 Jul 2001, Ryan Russell wrote:
I'm a bit stunned at the moment by a note to Bugtraq from a guy at LBL who claims that 1.17 Million different IP addresses have tried his address space, meaning that at least that many different IIS boxes have been nailed. I'm rather amazed.
---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- CodeRed Ryan Russell (Jul 19)
- Re: CodeRed James T Kirk (Jul 20)
- <Possible follow-ups>
- Re: CodeRed Ryan Russell (Jul 19)
- Re: CodeRed Ryan Russell (Jul 19)
- RE: CodeRed Ivan (Jul 19)
- RE: CodeRed Fulton L. Preston Jr. (Jul 19)
- Re: CodeRed Ryan Russell (Jul 20)
- RE: CodeRed Tulchinskiy, Sasha (Jul 20)
- SIRCAM WORM? borakovej (Jul 24)
- Re: SIRCAM WORM? acz [iSecureLabs] (Jul 24)
- SIRCAM WORM? borakovej (Jul 24)
- CodeRed terminator (Jul 21)