Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Code Red Worm Spreading, Set To Flood Whitehouse

Posted by timothy on Thu Jul 19, 2001 05:38 PM
from the code-blue-code-blue dept.
altek writes: "CNET has an article describing a worm that has taken down over 12,000 MS IIS webservers." Bill Kendrick points to another CNET story, which reports that the worm will "cause every infected computer to flood the Whitehouse.gov address with data starting at 5 p.m. PDT," writing "Time to shut down all those IIS servers before the Internet gets flooded."

Slow Internet service due to all those extra packets of malice may not be the worst effect: As sp1n writes: "It appears that due to the way the worm formats its HTTP request and the semi-random way it seeks out vulnerable systems, it is also causing Cisco 67x DSL routers, widely deployed by Qwest, using firmware prior to 2.4.1, as well as some others, such as 3Com LanModems, to crash -- recoverable only by a power cycle. I have yet to see any news outlet cover the affect this is having on DSL service. Qwest's Interprise networking department confirmed they are receiving reports from all 14 states in their territory. Some routers running pre-2.4.1 firmware are crashing even though the web admin is disabled. This has become a huge support nightmare for every ISP in the region."

This discussion has been archived. No new comments can be posted.
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2 | 3 | 4 | 5
  • Infected hosts....the sky is falling! by Anonymous Coward (Score:1) Thursday July 19 2001, @02:14PM
  • Re:Cisco DSL routers by Anonymous Coward (Score:1) Thursday July 19 2001, @02:32PM
  • Re:Why or why.... by Anonymous Coward (Score:1) Thursday July 19 2001, @04:29PM
  • Re:Ah HA! by Anonymous Coward (Score:1) Thursday July 19 2001, @04:57PM
  • Re:Update! by Anonymous Coward (Score:1) Thursday July 19 2001, @04:59PM
  • Re:Why or why.... by Anonymous Coward (Score:1) Thursday July 19 2001, @06:21PM
  • by Anonymous Coward on Thursday July 19 2001, @03:12PM (#73643)
    Which begs the question -- is it "right" to create a sploit that connects back to the attacking machines and "patches" their system so that it is fixed.
  • by Anonymous Coward on Thursday July 19 2001, @02:14PM (#73644)
    It's a conspiracy. Everyone will hit the whitehouse.gov site to see if the alleged worm affected it, and in doing so, we have all been duped into participating in a DDoS attack on the site. Rather clever, actually. Proclaim the effect to create the cause.
  • Re:Cisco DSL routers by narf (Score:1) Thursday July 19 2001, @02:49PM
  • Re:what it looks like by Micah (Score:2) Thursday July 19 2001, @03:19PM
  • Re:So, who's REALLY in charge... by Alan (Score:1) Thursday July 19 2001, @02:06PM
  • Re:If you don't run IIS but.... by Alan (Score:2) Thursday July 19 2001, @02:13PM
  • Pretty good simulation/dry run... by torpor (Score:2) Thursday July 19 2001, @03:07PM
  • Re:So, who's REALLY in charge... by torpor (Score:2) Thursday July 19 2001, @03:11PM
  • high5!~ by torpor (Score:2) Thursday July 19 2001, @03:26PM
  • Re:So, who's REALLY in charge... by torpor (Score:2) Friday July 20 2001, @10:26PM
  • by torpor (458) <jayv.synth@net> on Thursday July 19 2001, @03:29PM (#73653) Homepage Journal
    Almost any integer, eh?

    None of my int's are good enough.
  • You're right by Indomitus (Score:1) Thursday July 19 2001, @02:44PM
  • Re:News flash from cmdrtaco! by shogun (Score:1) Thursday July 19 2001, @07:40PM
  • Re:So, who's REALLY in charge... by Tim Doran (Score:2) Thursday July 19 2001, @02:31PM
  • Re:Why or why.... by Tim Doran (Score:2) Thursday July 19 2001, @02:36PM
  • hmm... could these dialup victims be using Win98's 'Personal Web Server'? It's just IIS 3.x.

    Wonder if that's vulnerable.
  • What about an automatic antidote? by Tim Macinta (Score:2) Thursday July 19 2001, @04:12PM
  • Re:Ah HA! by embobo (Score:1) Thursday July 19 2001, @05:59PM
  • Re:hmm by MoOsEb0y (Score:2) Thursday July 19 2001, @01:50PM
  • Re:hmm -- UPDATE (Score:3)

    by MoOsEb0y (2177) on Thursday July 19 2001, @01:59PM (#73663)
    well, well, I just checked my logs. I have been scanned by lamers for this heh.
    This showed up in my logs. I'm pasting it unadulterated seeing as I've found like 20 copies of it anyways so the script kiddies already have it.

    207.68.188.44 - - [19/Jul/2001:15:15:30 -0400] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858% ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%uc bd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531 b%u53ff%u0078%u0000%u00=a HTTP/1.0" 404 273
  • Re:Fake worm warning makes ALL OF US flood website by unitron (Score:2) Thursday July 19 2001, @02:46PM
  • Re:Fake worm warning makes ALL OF US flood website by unitron (Score:2) Thursday July 19 2001, @02:51PM
  • Re:Fake worm warning makes ALL OF US flood website by unitron (Score:2) Thursday July 19 2001, @03:21PM
  • Re:Update! by Zagadka (Score:1) Thursday July 19 2001, @10:46PM
  • Re:Why or why.... by Cato (Score:2) Friday July 20 2001, @01:58AM
  • Re:WhiteHouse.gov? Thank God! by hedley (Score:1) Thursday July 19 2001, @05:11PM
  • We got spanked by this as well. by mooman (Score:1) Thursday July 19 2001, @02:15PM
  • Re:Far east seems to have lots of insecure machine by ansible (Score:1) Thursday July 19 2001, @03:07PM
  • Re:Cisco DSL routers by Phexro (Score:2) Thursday July 19 2001, @01:58PM
  • ha! by Phexro (Score:2) Thursday July 19 2001, @02:01PM
  • It even got microsoft..... by LWolenczak (Score:1) Thursday July 19 2001, @01:56PM
  • Re:It even got microsoft..... by LWolenczak (Score:1) Thursday July 19 2001, @02:59PM
  • URL here! by LWolenczak (Score:1) Thursday July 19 2001, @04:04PM
  • Re:URL here! by LWolenczak (Score:1) Thursday July 19 2001, @04:47PM
  • Re:can't be legit by LWolenczak (Score:1) Friday July 20 2001, @02:09PM
  • Re:WhiteHouse.gov? Thank God! by mitheral (Score:1) Friday July 20 2001, @06:24AM
  • Re:what it looks like by RobM (Score:2) Friday July 20 2001, @01:58AM
  • Traffic by TBC (Score:1) Thursday July 19 2001, @01:44PM
  • Re:what it looks like by esper (Score:1) Friday July 20 2001, @06:21AM
  • Re:Windows Update by IntlHarvester (Score:1) Thursday July 19 2001, @05:53PM
  • Re:Windows Update by IntlHarvester (Score:2) Thursday July 19 2001, @04:22PM
  • And while we're confirming stuff by Sangui5 (Score:2) Thursday July 19 2001, @03:39PM
  • Re:So, who's REALLY in charge... by HeghmoH (Score:1) Thursday July 19 2001, @04:32PM
  • Re:Another update- random IPs by cronio (Score:1) Thursday July 19 2001, @04:31PM
  • Re:Windows Update by ethereal (Score:1) Thursday July 19 2001, @02:19PM
  • Re:Windows Update by ethereal (Score:1) Thursday July 19 2001, @03:18PM
  • Re:Windows Update by ethereal (Score:1) Thursday July 19 2001, @07:58PM
  • Re:flood ?? by Compuser (Score:1) Thursday July 19 2001, @02:51PM
  • Re:WhiteHouse.gov? Thank God! by Compuser (Score:1) Thursday July 19 2001, @05:46PM
  • Re:hmm -- UPDATE by SoftwareJanitor (Score:2) Friday July 20 2001, @09:06AM
  • Re:Dealing with this all day by Bryan Andersen (Score:1) Thursday July 19 2001, @10:50PM
  • Re:Update! by sharkey (Score:2) Thursday July 19 2001, @04:39PM
  • Re:Update! by sharkey (Score:2) Friday July 20 2001, @01:06PM
  • by Eimi Metamorphoumai (18738) on Thursday July 19 2001, @02:17PM (#73697) Homepage
    Right, so, who wants to build a space station with me and leave this BS behind? I'll bring cookies.

    Tempting, but I block cookies whenever I can. If you bring some beer and steak, I'm there.

  • Re:Update! by emc (Score:1) Thursday July 19 2001, @06:54PM
  • time h@X0R by Tiro (Score:2) Thursday July 19 2001, @01:54PM
  • Re:Let's see... /var/log/apache by Black Parrot (Score:1) Thursday July 19 2001, @06:11PM
  • yup, I has hit 26 times. good thing I have apache by slashkitty (Score:1) Thursday July 19 2001, @03:37PM
  • divide by 2 for accurate number by slashkitty (Score:1) Thursday July 19 2001, @03:45PM
  • Proactivity by Jahf (Score:1) Thursday July 19 2001, @02:00PM
  • Re:Proactivity by Jahf (Score:2) Thursday July 19 2001, @02:25PM
  • Re:So, who's REALLY in charge... by Moofie (Score:1) Thursday July 19 2001, @09:25PM
  • Press DOS attack (Score:5)

    by jonathanclark (29656) on Thursday July 19 2001, @02:39PM (#73706) Homepage
    This is acutally the "Press DOS attack." You get some security expert to claim that a worm is spreading all over the internet and will attack X site at 5pm. Then everyone who reads the story will go see if the site is down at 5pm. And of course since everyone is hitting reload to see when it is down, the site gets flooded and goes down while the virus/worm never exsisted!
  • Re:So, who's REALLY in charge... by Sxooter (Score:1) Thursday July 19 2001, @06:58PM
  • Re:Cisco DSL routers by Sxooter (Score:1) Thursday July 19 2001, @07:14PM
  • Re:Update! by Polo (Score:2) Thursday July 19 2001, @08:18PM
  • Re:Windows Update by Zenki (Score:1) Thursday July 19 2001, @04:07PM
  • 100,000 (Score:3)

    by Zildy (32593) on Thursday July 19 2001, @01:45PM (#73711)
    Cnet now says 100,000 servers infected.

    At my company (small midwest ISP), I could feel the effects at around 10am CDT. A couple servers run by customers were infected and were sending out a *constant* stream of requests to random servers trying to infect others.

    Oof.

    FOR THE LOVE OF GOD, FIND GET YOUR Tee Ball at the White House [whitehouse.gov] INFORMATION BEFORE IT'S TOO LATE!!!

  • Re:Dealing with this all day by aenea (Score:2) Thursday July 19 2001, @07:45PM
  • Re:Why M$ ? by gimpboy (Score:2) Friday July 20 2001, @04:27AM
  • Re:Update! by ajs (Score:2) Friday July 20 2001, @01:43AM
  • Re:Another update- random IPs by mpe (Score:2) Friday July 20 2001, @03:05AM
  • Re:what it looks like by macpeep (Score:2) Thursday July 19 2001, @02:32PM
  • Re:Let's see... /var/log/apache by thrig (Score:1) Thursday July 19 2001, @03:04PM
  • Re:Cisco DSL routers by mullein (Score:1) Thursday July 19 2001, @07:46PM
  • Re:Monopoly is not required for worms by SlashDread (Score:1) Friday July 20 2001, @12:11AM
  • Other indicators? by HerrNewton (Score:1) Thursday July 19 2001, @02:01PM
  • Re:Cisco DSL routers by hohosforbreakfast (Score:1) Thursday July 19 2001, @06:29PM
  • Re:Let's see... /var/log/apache by Trifthen (Score:1) Thursday July 19 2001, @04:34PM
  • Re:Dealing with this all day by Hal-9001 (Score:1) Thursday July 19 2001, @02:16PM
  • Re:bashing M$ IS fun... by Hal-9001 (Score:1) Thursday July 19 2001, @02:22PM
  • Re:bashing M$ IS fun... by Hal-9001 (Score:1) Thursday July 19 2001, @02:32PM
  • Re:Update! by Hal-9001 (Score:1) Thursday July 19 2001, @02:34PM
  • Re:Update! by Hal-9001 (Score:1) Thursday July 19 2001, @02:37PM
  • Re:Dealing with this all day by EasyTarget (Score:2) Thursday July 19 2001, @01:56PM
  • Re:Good description here: by ncc74656 (Score:1) Thursday July 19 2001, @08:28PM
  • Re:hmm by ncc74656 (Score:2) Thursday July 19 2001, @07:25PM
  • Re:Update! by cyberdonny (Score:2) Friday July 20 2001, @03:41AM
  • Re:what it looks like by BubbaFett (Score:1) Thursday July 19 2001, @02:38PM
  • by devphil (51341) on Thursday July 19 2001, @01:45PM (#73733) Homepage


    The government cannot take down Microsoft, but Microsoft can take down the government...

    *ponder*

    Right, so, who wants to build a space station with me and leave this BS behind? I'll bring cookies.

  • Re:Dealing with this all day by 1010011010 (Score:1) Thursday July 19 2001, @03:16PM
  • by TheTomcat (53158) on Thursday July 19 2001, @01:49PM (#73735) Homepage
    scared me at first.. reboot fixes it.. but it comes back..
    upgrade your service packs/critical updates and then run this (http://www.microsoft.com/technet/treeview/default .asp?url=/technet/security/bulletin/MS01-033.asp [microsoft.com]) patch.. should clear it up.. I hope, anyway. (-:
  • Ah HA! (Score:4)

    by underwhelm (53409) <underwhelm@NoSPAM.gmail.com> on Thursday July 19 2001, @02:14PM (#73736) Homepage Journal
    So that's why my DSL router was crapping out every 10 minutes or so this afternoon, after several months of continuous uptime. I knew it couldn't be a configuration problem (there's only so much configuratin' one can do to those things.)

    After reading about the trouble Slashdot ran into with their Cisco routers, and the tongue lashing they got for rebooting it without understanding the problem, I'm glad I powercycled it anyway. It did solve the problem, until I got hit again.

    While I was rebooting the "turtle," as we call it, my girlfriend, Anne, for some reason got really upset, started crying and moved out. Really odd.
  • Re:It even got microsoft..... by pirodude (Score:1) Thursday July 19 2001, @03:39PM
  • Re:time h@X0R by stile (Score:1) Thursday July 19 2001, @02:22PM
  • Re:Another update- random IPs by Old Wolf (Score:1) Friday July 20 2001, @12:43AM
  • Re: Screenshot? [was:Why or why....] by millette (Score:1) Thursday July 19 2001, @07:26PM
  • Re:Let's see... /var/log/apache by blackwizard (Score:1) Thursday July 19 2001, @03:29PM
  • Re:Let's see... /var/log/apache by mbyte (Score:2) Thursday July 19 2001, @02:31PM
  • Re:Good description here: by jhittner (Score:1) Thursday July 19 2001, @02:50PM
  • Re:WhiteHouse.gov? Thank God! by Rev_Hojo (Score:2) Thursday July 19 2001, @03:47PM
  • by heliocentric (74613) on Thursday July 19 2001, @01:48PM (#73745) Homepage Journal
    I don't run IIS, but I've been seeing odd things in my logs. It took me a sec to check security focus and learn what it was. Here is an except of a log file so you if see similar you know what's up.

    65.201.146.103 - - [19/Jul/2001:17:58:49 -0400] "GET /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNN%u9090%u6858% ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%uc bd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531 b%u53ff%u0078%u0000%u00=a HTTP/1.0" 400 323 "-" "-"

    The thing on security focus [securityfocus.com] indicating that "default.ida" thing is IIS probes (and/or possibly already compromised systems rescanning is here [securityfocus.com].
  • umm... are you sure? by Jafa (Score:2) Thursday July 19 2001, @01:47PM
  • Another update- random IPs by Jafa (Score:2) Thursday July 19 2001, @02:11PM
  • problems with the patch by Jafa (Score:2) Thursday July 19 2001, @02:22PM
  • by Jafa (75430) <jafa@@@markantes...com> on Thursday July 19 2001, @01:43PM (#73749) Homepage
    The guys at Eeye [eeye.com] have a good overview here [eeye.com].

    This is basically just the usual buffer overflow attack that's had a patch available for a month, and by following best practices shouldn't be an issue at all. The really interesting thing is where the guns being gathered are pointed: at whitehouse.gov. Should be an interesting night!

    Jason
  • by bmo (77928) on Thursday July 19 2001, @01:53PM (#73750)
    Dick Cheney: SOMEONE SET UP US THE WORM!

    George Bush: MAIN SCREEN TURN ON!

    George Bush: IT'S YOU!!

    Li Peng: YOU HAVE NO CHANCE. MAKE YOUR TIME.

    Li Peng: HAHAHAHAHA

  • Re:hmm -- UPDATE by c-A-d (Score:1) Thursday July 19 2001, @02:31PM
  • Re:Cisco DSL routers by Eric Seppanen (Score:1) Thursday July 19 2001, @02:29PM
  • Re:Cisco DSL routers by Eric Seppanen (Score:2) Thursday July 19 2001, @02:08PM
  • Cisco DSL routers (Score:5)

    by Eric Seppanen (79060) on Thursday July 19 2001, @01:51PM (#73754) Homepage
    I, and many of my co-workers, had our home DSL routers (Cisco 675s) lock up today as this worm scanned them.

    There is common belief that disabling the web interface will prevent this. It's not true; mine's been disabled every since this was first reported a year ago and I still got hit. The problem is that "set web disable" prevents the web server from fiddling the router config, but doesn't actually stop the server from parsing input from port 80, which is what locks up the box.

    An improved workaround is to disable the web-admin interface and change its port number with "set web port 53496" (replace with some random port number). At least that'll stop it for the near term.

    Long term you need to get updated firmware, but of course Cisco won't distribute firmware directly to customers, even though they have public announcements of the existence of bugs and bugfixes. To actually get the firmware you have to get it from your DSL line provider (Qwest, in my case), and Qwest couldn't care less about security with respect to home users, so they've never bothered to offer fixed versions of CBOS.
    --

  • Re:Write Your Congressman NOW! by giz (Score:1) Thursday July 19 2001, @08:55PM
  • Re:Windows Update by KenSeymour (Score:1) Thursday July 19 2001, @02:07PM
  • Re:Another update- random IPs by kootch (Score:2) Thursday July 19 2001, @04:36PM
  • Re:Dealing with this all day by Moonshadow (Score:2) Thursday July 19 2001, @03:09PM
  • Re:Obligatory reference: by willis (Score:1) Thursday July 19 2001, @05:04PM
  • You can see the packets in your web log... by smoondog (Score:1) Thursday July 19 2001, @01:49PM
  • Scriptkiddies... by haeger (Score:1) Thursday July 19 2001, @10:23PM
  • This is why! (Score:3)

    by AirLace (86148) on Thursday July 19 2001, @04:51PM (#73762)
    Perhaps this is why [robertedmonds.net] the patch is not on windows update. Fixed now though.
  • Re:So, who's REALLY in charge... by nconway (Score:1) Thursday July 19 2001, @02:00PM
  • Re:So, who's REALLY in charge... by nconway (Score:2) Friday July 20 2001, @03:49AM
  • Re:Good description here: by Mononoke (Score:1) Thursday July 19 2001, @05:07PM
  • by Joel Rowbottom (89350) on Thursday July 19 2001, @01:49PM (#73766) Homepage
    This won't just cause problems for whitehouse.gov, but also quite a lot of problems for the very fabric of the Internet - the routers. The traffic generated within colocation facilities for instance is likely to overcome routing kit and deplete memory very very quickly.

    There have been quite a lot of posts on NANOG [merit.edu] about this already, and depletion of memory on Cisco routers causing them to crash.

    --

  • Re:Press DOS attack by nobodyman (Score:1) Thursday July 19 2001, @07:16PM
  • Re:Cisco DSL routers by tconnors (Score:1) Thursday July 19 2001, @05:55PM
  • Let's see... /var/log/apache by magi (Score:2) Thursday July 19 2001, @01:52PM
  • Re:Cisco DSL routers by letchhausen (Score:1) Thursday July 19 2001, @05:13PM
  • whitehouse.gov. IN CNAME hongkonggov.cn by xodiak (Score:1) Thursday July 19 2001, @01:45PM
  • what it looks like (Score:5)

    by tedtimmons (97599) on Thursday July 19 2001, @01:47PM (#73772) Homepage
    For those of you that tend flocks of web servers, here's what a request would look like:

    GET /default.ida?NNNNNNNNNNNNNNNNNNNNNN ...

    There are tons of N's (can you say buffer overflow?) and then stuff after the N's. I've left that out to make it harder for script kiddies.

    -ted

  • Re:So, who's REALLY in charge... by edibleplastic (Score:1) Friday July 20 2001, @03:34AM
  • Re:If you don't run IIS but.... by radish (Score:1) Friday July 20 2001, @01:22AM
  • Re:So, who's REALLY in charge... by Peter Harris (Score:1) Friday July 20 2001, @12:09AM
  • Re:Why or why.... by Fjord (Score:2) Friday July 20 2001, @08:51AM
  • Re:So, who's REALLY in charge... by Lacutis (Score:1) Thursday July 19 2001, @08:32PM
  • Re:Should have open sourced it... by athmanb (Score:2) Thursday July 19 2001, @03:40PM
  • That is funny! by acacia (Score:1) Thursday July 19 2001, @04:05PM
  • flood ?? by n3m6 (Score:1) Thursday July 19 2001, @01:58PM
  • Re:Cisco DSL routers by c o r e (Score:1) Thursday July 19 2001, @02:25PM
  • Re:Cisco DSL routers by c o r e (Score:1) Thursday July 19 2001, @04:43PM
  • Re:Cisco DSL routers: not the latest by c o r e (Score:1) Thursday July 19 2001, @04:46PM
  • Re:Cisco DSL routers: which file?? by c o r e (Score:1) Thursday July 19 2001, @04:49PM
  • Re:Cisco DSL routers by c o r e (Score:1) Friday July 20 2001, @06:33AM
  • Re:Should have open sourced it... by Jovian (Score:1) Thursday July 19 2001, @10:32PM
  • by Raymond Luxury Yacht (112037) on Thursday July 19 2001, @01:47PM (#73787) Homepage
    ... but really, what would have been helpful to many IT readers would have been the link [microsoft.com] to the Microsoft bulletin and patch download in the /. article.
  • Re:Good description here: by josecuervo (Score:1) Thursday July 19 2001, @01:47PM
  • Re:Update! (Score:5)

    by Smitty825 (114634) on Thursday July 19 2001, @01:50PM (#73789) Homepage Journal
    While I don't disagree with your bug report, I want to point out that at 5PM PST, it offically becomes July 20th on GMT. Unless the attack begins on the 21st, I'm still assuming whitehouse.gov will be inaccessable tonight :-)
  • Time to shut down all those IIS servers? by realdpk (Score:1) Thursday July 19 2001, @01:56PM
  • Re:Update! by realdpk (Score:1) Thursday July 19 2001, @02:21PM
  • Re:Update! by realdpk (Score:1) Thursday July 19 2001, @03:00PM
  • Re:Why or why.... (Score:5)

    by realdpk (116490) on Thursday July 19 2001, @02:00PM (#73793) Homepage Journal
    It's not the RIAA or MPAA, but you might like these IPs:

    207.46.123.13
    207.46.152.122
    207.46.153.9
    207.46.171.237
    207.46.171.61
    207.46.171.68
    207.46.173.25
    207.46.175.96
    207.46.186.252
    207.46.187.123
    207.46.196.55
    207.46.196.58
    207.46.203.39
    207.46.227.38
    207.46.230.64
    207.46.239.116
    207.46.239.117
    207.46.239.44
    207.46.252.139
    207.46.28.158

    Each of them has hit default.ida on one server I'm watching. From what I can tell from whois -a, 207.46 is all Microsoft corp! They can't even keep up with their patches.

    (btw, on this same server I'm seeing a new unique IP default.ida hit every second)
  • Re:This is why! by petard (Score:2) Thursday July 19 2001, @07:45PM
  • Re:Windows Update by DrSkwid (Score:1) Friday July 20 2001, @05:53AM
  • Humm... ZDnet once again get's it wrong... by Astralmind (Score:1) Thursday July 19 2001, @01:49PM
  • Detection by kill_9_1 (Score:1) Thursday July 19 2001, @02:02PM
  • Re:Windows Update by SuiteSisterMary (Score:2) Thursday July 19 2001, @01:53PM
  • Re:Windows Update by SuiteSisterMary (Score:2) Thursday July 19 2001, @03:12PM
  • Re:Detection (Score:3)

    by SuiteSisterMary (123932) <slebrun@NoSPaM.gmail.com> on Thursday July 19 2001, @03:58PM (#73800) Homepage Journal
    Run task manager. Select 'processes.' Open the view menu. Select 'choose columns.' Activate 'thread count.' Then look for a process with 100 threads. At least, from what I've read about the worm. My firewall's been turning these away left, right, and centre.
  • Re:If you don't run IIS but.... by jallen02 (Score:1) Thursday July 19 2001, @04:27PM
  • Re:If you don't run IIS but.... by jallen02 (Score:1) Thursday July 19 2001, @07:37PM
  • Re:Another update- random IPs by jallen02 (Score:2) Thursday July 19 2001, @04:24PM
  • Re:Update! (Score:4)

    by friscolr (124774) on Thursday July 19 2001, @03:36PM (#73804) Homepage
    one more thing to note-

    it attacks 198.137.240.92 not www.whitehouse.gov
    that is, it doesn't need to reference the dns server (i was hoping to just add an entry for whitehouse.gov to our dns server since i dont have access to the router side of things)

    -f

  • Re:So, who's REALLY in charge... by RevAaron (Score:2) Thursday July 19 2001, @05:49PM
  • Re:So, who's REALLY in charge... by RevAaron (Score:2) Friday July 20 2001, @03:30PM
  • Re:So, who's REALLY in charge... by RevAaron (Score:2) Tuesday July 24 2001, @09:58AM
  • Got em here too by cide1 (Score:1) Thursday July 19 2001, @05:56PM
  • Re:Got em here too by cide1 (Score:1) Friday July 20 2001, @04:48PM
  • Re:Cisco DSL routers by _Bean_ (Score:1) Thursday July 19 2001, @10:06PM
  • Re:what it looks like by Dahan (Score:1) Thursday July 19 2001, @11:53PM
  • Why or why.... (Score:5)

    by Wintermancer (134128) on Thursday July 19 2001, @01:44PM (#73812)
    ....can't it be the RIAA's and MPAA's webservers?

    Sigh. Windows IIS: It's like walking around with a handfull of twenties and giving a loaded gun to any criminal you meet.
  • Re:Dealing with this all day by RottenDeadite (Score:1) Friday July 20 2001, @06:11AM
  • Holy Shit. by BiggestPOS (Score:1) Thursday July 19 2001, @01:57PM
  • Re:Another update- random IPs by Andrewkov (Score:2) Thursday July 19 2001, @05:16PM
  • Re:So, who's REALLY in charge... by Andrewkov (Score:2) Thursday July 19 2001, @05:31PM
  • Re:Another update- random IPs by Andrewkov (Score:2) Friday July 20 2001, @04:27AM
  • Re:Dealing with this all day by SealBeater (Score:2) Thursday July 19 2001, @01:59PM
  • by SealBeater (143912) on Thursday July 19 2001, @01:43PM (#73819) Homepage
    We have been dealing with this all day at my job (colo/hosting). Apprently, it's totally memory resident, so a reboot should clear it. However, its really spreading like wildfire. Also will hang Cisco 675s and 678s, so if you have one of those routers (cable/dsl), disable web access. Also is hanging HP printers with web frontends. The traffic alone is choking some of our smaller routers. The patch is availible here [microsoft.com].

    SealBeater
  • Mystery port by Sheetrock (Score:1) Thursday July 19 2001, @07:44PM
  • Re:So, who's REALLY in charge... by bonzoesc (Score:1) Thursday July 19 2001, @02:51PM
  • Re:hmm by Jester998 (Score:1) Thursday July 19 2001, @01:57PM
  • Could Slashdot get... Slashdotted? by Jester998 (Score:1) Thursday July 19 2001, @02:10PM
  • Cookies? Code Red? Hitch-hike to Mars? by Morbid Curiosity (Score:1) Thursday July 19 2001, @04:58PM
  • Re:Let's see... /var/log/apache by Saint Aardvark (Score:1) Thursday July 19 2001, @02:25PM
  • Re:hmm -- UPDATE by IronChef (Score:2) Thursday July 19 2001, @04:06PM
  • Re:Proactivity by IronChef (Score:2) Thursday July 19 2001, @04:58PM
  • Re:Probes coming from dial-up connections too! by IronChef (Score:2) Thursday July 19 2001, @05:00PM
  • Re:Why or why.... (Score:3)

    by IronChef (164482) on Thursday July 19 2001, @04:44PM (#73829) Homepage

    22 hits to me, though my overworked cable modem serves about 1000 unique visitors a day.

    Then again traffic shouldn't matter... according to the articles the IP addresses to attack are produced by a pseudo-random algorithm... so those of us with a handful of hits have IPs that are way down on the algorithm's list.

    My first hit was at 9:20 AM, the last was at 4:04 PM.
  • Tons of scans by amitv (Score:1) Thursday July 19 2001, @02:14PM
  • hmm by Dzejwi (Score:1) Thursday July 19 2001, @01:41PM
  • by cant_get_a_good_nick (172131) on Thursday July 19 2001, @01:56PM (#73832)
    Ironic. I read an article on ZdNet [zdnet.com] on how Microsoft was not only gonna pull it's JVM, but was going to disable some Java applets because it viewed them as a security risk. I wondered aloud whether this would have disabled Outlook, IIS, IE (ActiveX vulnerabilities) and .vbs files.

    Microsoft Outlook: Making the Goodtimes virus real.

  • Re:WhiteHouse.gov? Thank God! by krappie (Score:1) Thursday July 19 2001, @04:34PM
  • Re:So, who's REALLY in charge... by denshi (Score:2) Thursday July 19 2001, @02:50PM
  • Great, now you tell me by dark_panda (Score:2) Thursday July 19 2001, @01:52PM
  • Also crashing certian Cisco routers by Bender_ (Score:1) Thursday July 19 2001, @01:47PM
  • Update! (Score:4)

    by Bender_ (179208) on Thursday July 19 2001, @01:43PM (#73837)
    The information about the whitehouse.gov attack was wrong. (Well - its still up :)) In fact the attack is going to start tommorrow, july 20th.

    Here is the snippet from bugtraq:

    Thanks to Eric from Symantec for tossing us a note about the worm being Date
    based and not Time based.

    We made an error in our last analysis and said the worm would start
    attacking whitehouse.gov based on a certain time. In reality its based on a
    date (the 20th UTC) which is tomorrow.

    If the worm infects your system between the 1st and the 19th it will attempt
    to deface the infected servers web page or try to propogate itself to other
    systems. On the 20th all infected threads will attempt to attack
    www.whitehouse.gov. This seems to continue until the worm is removed from
    the infected system.

    Any new infection that happens between the 20th and 28th will most likely be
    someone "hand infecting" your system as all other worms should be attacking
    whitehouse.gov. If for some reason you are infected between the 20th and the
    28th then the worm will begin attacking whitehouse.gov without trying to
    infect other systems. This attack will continue indefinitly.

    The following are rough numbers, but we felt that it was important to
    illustrate the affects this worm can _possibly_ have.

    The worm has a timeline like this:

    day of the month:
    1-19: infect other hosts using the worm
    20-27: attack whitehouse.gov forever
    28-end of month: eternal sleep

    Presumably, this could restart at any point in a new month again.

    Also, some stats for the attack:

    Each infection has 100 threads
    Each thread is going to send about 100k, a byte at a time, which means you
    have a (40 for ip + 1 for each byte) which means you have 4.1 megs of data
    per thread
    100 threads * 4.1megs = 410 Megabytes
    This will be repeated again every 4.5 hours or so

    Remember, each host can be infected multiple times, meaning that a single
    host can send 410MB * # of infections.

    We have had reports between 15 thousand and 196 thousand unique hosts
    infected with the "Code Red" worm. However, there has been cross infection
    and we have heard reports of at least 300+ thousand infections/instances
    (machines with multiple infections etc..) of this worm.

    If there are 300 thousand infections then that means you have (300,000 * 410
    megabytes) that is going to be attempted to be flooded against
    whitehouse.gov every 4 and a half hours. If this is true and the worm "works
    as advertised" then the fact that whitehouse.gov goes offline is only the
    begining of what _can_ possibly happen...

  • by Bender_ (179208) on Thursday July 19 2001, @01:50PM (#73838)
    Here [google.com] is a full analysis of the worm. (including source!)
  • Re:Dude... Get a clue! by hal200 (Score:1) Friday July 20 2001, @04:45AM
  • No worries by CaptainZapp (Score:1) Friday July 20 2001, @12:54AM
  • by Erasmus Darwin (183180) on Thursday July 19 2001, @02:52PM (#73841)
    There are tons of N's (can you say buffer overflow?)

    If the DDoS doesn't bother spoofing the source address (and I didn't see anything to indicate that it did) and if it doesn't bother closing the hole, I find it interesting that the target of the attack could hypothetically "hack back".

    (20 hits for default.ida in the logs at one job, 26 at the other. I (heart) Apache.)

  • Re:Affects IIS? (Score:3)

    by Erasmus Darwin (183180) on Thursday July 19 2001, @03:01PM (#73842)
    Don't all worms take advantage of security flaws in Microsoft software?

    It's been done [software.com.pl].

    (It's a link to information on RTM's worm, for those who don't feel like clicking the link.)

  • by Erasmus Darwin (183180) on Thursday July 19 2001, @05:43PM (#73843)
    Er, 99.99999% of the sources are zombies. Dumbass.

    Oh nos! You've called me a dumbass. My penis will now shrink, and I'll forever be a hollow shell of a man.

    And assuming I'm understanding you correctly, by zombies you're referring to just an arbitrary exploited machine, running the DDoS on behalf of a third party. I was aware of this fact when I posted my comment. I certainly was under no misapprehension that a given DDoS machine was being run by the person who created the worm.

    But that doesn't change the fact that, under the conditions I stated, the person on the receiving end of the attack could hypothetically reexploit each machine to (if they're nice) disable the worm or (if they're mean) wipe the system altogether. Besides, the owners of the machines in question share some culpability in their failure to properly administer and secure their systems.

  • Re:WhiteHouse.gov? Thank God! by adoll (Score:1) Thursday July 19 2001, @07:48PM
  • There is the fix: move the IP address by adoll (Score:2) Thursday July 19 2001, @08:00PM
  • Re:hmm by shokk (Score:2) Thursday July 19 2001, @04:38PM
  • Re:So, who's REALLY in charge... by shokk (Score:2) Thursday July 19 2001, @05:25PM
  • Re:Why or why.... by Liquor (Score:1) Friday July 20 2001, @10:57AM
  • Re:"IT People" != informed people by Liquor (Score:1) Tuesday July 24 2001, @03:44PM
  • China? by Sebastopol (Score:1) Thursday July 19 2001, @01:50PM
  • by BigBlockMopar (191202) on Thursday July 19 2001, @04:40PM (#73851) Homepage

    I got a little worried there for a sec!

    I'm still worried!

    Write your congressman. I want to see using a Microsoft server being treated as an act of criminal negligence, like drunk driving.

    Haven't we all had enough of this bullspit?

    My own webserver had been hit by several thousand of these attempts. When I got Slashdotted for putting up pictures of Bobo [glowingplate.com], it was bad. But this worm has been saturating my DSL with HTTP GET requests.

  • by BigBlockMopar (191202) on Thursday July 19 2001, @07:18PM (#73852) Homepage

    It's just because Microsoft is the number one webserver that the worm is targetted towards it. If Linux were the number one webserver the worm would target it.

    Hmmm... Uhhh. Microsoft primarily makes operating systems which repeatly prove themselves marginal for desktop use, and criminally inadequate for anything requiring stability or security.

    I think you're attempting to imply that IIS server, which comes free - though hobbled to various degrees - with all versions of NT and 2000, is the number one webserver.

    That's mighty good crack that you're smoking [netcraft.com].

    P.S. Drunk driving is not as bad an activity as you describe.

    I love drunk driving. It's a lot of fun. A friend of mine used to work in an automotive wrecking yard, and we used to love cracking open a few beers and driving around the yard in one of the junkers that came in under its own power. It was a great way of spending a Friday evening when I was in high school. I assure you, 50-foot-tall mountains of crushed cars are a lot harder to avoid after 6 beers. Even worse, 50-foot-tall mountains of crushed cars are a lot harder than uncrushed cars. They don't collapse well in accidents after they've been through the Al-jon. One might even suggest that they have less crush space. Especially the silly little Hondas.

    You know what? I love my cars, and I love my beer. But the two don't mix. I don't drive (on public roads, anyway) if I've had even one beer.

    Old people kill more people just because of senility, than drunk drivers.

    Uh-huh. Yeah. You fascinate me.

  • Re:If you don't run IIS but.... by ZanshinWedge (Score:2) Thursday July 19 2001, @07:02PM
  • Re:So, who's REALLY in charge... by 7-Vodka (Score:2) Thursday July 19 2001, @08:32PM
  • ngrep '' by zoftie (Score:1) Thursday July 19 2001, @02:06PM
  • Re:Let's see... /var/log/apache by elefantstn (Score:1) Thursday July 19 2001, @03:05PM
  • Re:Why or why.... by linzeal (Score:1) Thursday July 19 2001, @09:11PM
  • Re:Affects IIS? by Prof. Pi (Score:2) Thursday July 19 2001, @02:59PM
  • Re:So, who's REALLY in charge... by delfstrom (Score:1) Thursday July 19 2001, @06:52PM
  • Re:So, who's REALLY in charge... by GroovBird (Score:1) Thursday July 19 2001, @08:45PM
  • Re:bashing M$ IS fun... by GroovBird (Score:1) Thursday July 19 2001, @08:52PM
  • Re:So, who's REALLY in charge... by graveyhead (Score:2) Friday July 20 2001, @05:43AM
  • Monopoly is not required for worms by BlowCat (Score:2) Thursday July 19 2001, @04:32PM
  • Mistake? by MWoody (Score:2) Thursday July 19 2001, @03:23PM
  • Re:Tons of scans by jobber-d (Score:1) Thursday July 19 2001, @04:01PM
  • Re:So, who's REALLY in charge... by Darth_Burrito (Score:1) Thursday July 19 2001, @04:07PM
  • Slow on the FPs by SpaceLifeForm (Score:1) Thursday July 19 2001, @01:44PM
  • Re:Affects IIS? by American AC in Paris (Score:2) Friday July 20 2001, @05:30AM
  • "IT People" != informed people by whizzmo (Score:1) Tuesday July 24 2001, @01:23AM
  • Code Red is NOT A THREAT!!! by azizu (Score:1) Thursday July 19 2001, @02:10PM
  • Re:Press DOS attack by nirvdrum (Score:1) Thursday July 19 2001, @07:25PM
  • Re:Why or why.... by akh (Score:2) Thursday July 19 2001, @07:01PM
  • Re:Good description here: by jkmiecik (Score:1) Thursday July 19 2001, @09:41PM
  • Re:Fake worm warning makes ALL OF US flood website by ConsumedByTV (Score:2) Thursday July 19 2001, @04:16PM
  • Re:Obligatory reference: by delorean (Score:1) Friday July 20 2001, @06:39AM
  • can't be legit by delorean (Score:1) Friday July 20 2001, @07:05AM
  • Re:another cross platform virus by cryptoslut (Score:1) Thursday July 19 2001, @01:58PM
  • Re:Dealing with this all day by H310iSe (Score:2) Thursday July 19 2001, @04:46PM
  • Re:Write Your Congressman NOW! by dasunt (Score:2) Friday July 20 2001, @04:59AM
  • Re:DCMA by Classic Ted (Score:1) Thursday July 19 2001, @04:30PM
  • Re:Cisco DSL routers by raju1kabir (Score:2) Thursday July 19 2001, @09:08PM
  • Re:divide by 2 for accurate number by raju1kabir (Score:2) Thursday July 19 2001, @09:17PM
  • Is this what it does? by weinholt (Score:2) Thursday July 19 2001, @01:52PM
  • Re:Obligatory reference: by SilverWeed (Score:1) Thursday July 19 2001, @04:12PM
  • Re:Obligatory reference: by SilverWeed (Score:1) Thursday July 19 2001, @08:41PM
  • Re:Write Your Congressman NOW! by imipak (Score:2) Friday July 20 2001, @02:57AM
  • Re:hmm -- UPDATE by Fizzlewhiff (Score:1) Thursday July 19 2001, @08:40PM
  • Re:Write Your Congressman NOW! by Argnarf (Score:1) Friday July 20 2001, @05:25AM
  • another cross platform virus by Proud Geek (Score:1) Thursday July 19 2001, @01:43PM
  • Re:Why or why.... by mythr (Score:1) Thursday July 19 2001, @05:06PM
  • Oh Boy! by darkov (Score:1) Thursday July 19 2001, @02:07PM
  • Re:So, who's REALLY in charge... by kilgore_47 (Score:1) Thursday July 19 2001, @03:00PM
  • Re:what it looks like by kilgore_47 (Score:2) Thursday July 19 2001, @03:03PM
  • Re:Is this what it does? by skiingyac (Score:1) Thursday July 19 2001, @02:02PM
  • Computer experts by skiingyac (Score:2) Thursday July 19 2001, @01:53PM
  • Re:Cisco DSL routers by CeramicNuts (Score:1) Thursday July 19 2001, @02:05PM
  • I noticed! by CeramicNuts (Score:2) Thursday July 19 2001, @01:47PM
  • Re:another cross platform virus by CeramicNuts (Score:2) Thursday July 19 2001, @02:09PM
  • by CeramicNuts (265664) on Thursday July 19 2001, @02:19PM (#73899) Journal
    here's the link to upgrade to the latest firmware:

    http://www.qwest.com/dsl/customerservice/win675ups .html [qwest.com]

  • Re:So, who's REALLY in charge... by Ayende Rahien (Score:1) Thursday July 19 2001, @02:42PM
  • Re:flood ?? by Ayende Rahien (Score:1) Thursday July 19 2001, @02:51PM
  • Re:Is this what it does? by Ayende Rahien (Score:2) Thursday July 19 2001, @02:47PM
  • Re:So, who's REALLY in charge... by Ayende Rahien (Score:2) Thursday July 19 2001, @08:22PM
  • Re:Windows Update (Score:3)

    by mech9t8 (310197) on Thursday July 19 2001, @03:43PM (#73904)
    Microsoft doesn't put most security patches on Windows Update. They have a Corporate Windows Update (http://corporate.windowsupdate.microsoft.com), but it's basically just another download site... it doesn't automatically tell you what you need or install it for you.

    Not that keeping up to date on patches is very difficult (subscribe to their Security Bulletin at http://www.microsoft.com/technet/security/bulletin /notify.asp), but since they obviously have the Update technology down pat, I don't know why they don't have a version of Windows Update with *all* the hotfixes, not just the "consumer-friendly" ones. It would certainly make setting up new machines easier... instead of downloading and installing twenty files, you should be able to just go to their site and have it do the work for you.

    They haven't really changed Windows Update since it was introduced with Windows 98 - they've really dropped the ball... Redhat's up2date and Ximian's Red Carpet are both quite a bit better than the current implementation of Windows Update.
    --
    Convictions are more dangerous enemies of truth than lies.
  • Re:Windows Update (Score:3)

    by mech9t8 (310197) on Thursday July 19 2001, @04:55PM (#73905)
    Yeah, but for each one you have to click through 3 times just to get the file. Which means:

    a) it's really annoying, and lots of people just won't bother, and...
    b) it's really easy to miss one or two

    And there's no real way to check (there's a dinky little script available somewhere that'll check for IIS patches, but it's buggy and hard to find).

    The Corporate Windows Update site makes them easier to download, but it takes weeks for patches to be put up on it after they've been released, and there's no real way to match them with the associated Bulletins (to know if they need to be re-downloaded, if you've missed any, etc.) And it doesn't allow searching by Service Pack.

    In this case, Microsoft's system is just sloppy and unprofessional. There's absolutely no reason for this to be such a pain other than Microsoft isn't putting enough money and attention into its support structure.

    Sure, they now allow Patches to be joined together so you only have to reboot once for multiple patches and they allow you to search by Service Pack, but those are baby steps that should've been done years ago... patches today should be instantly updated over the web and shouldn't require reboots in 99% of cases (for all IIS patches, it should just shut down IIS, update the files, and restart). Microsoft's behind the curve, and if I was a corporate system admin, I'd be tempted to switch to Red Hat just because they have a much better update structure.

    (For instance, with Red Hat, you type up2date, it launches a graphical wizard which automatically tells you what you need updated, downloads, and installs them. It's like four mouse clicks to completely update your system to latest versions of everything on it.)
    --
    Convictions are more dangerous enemies of truth than lies.
  • Re:Press DOS attack by fors (Score:2) Thursday July 19 2001, @09:58PM
  • Re:Update! by SmallTooth (Score:1) Thursday July 19 2001, @02:24PM
  • Re:Why or why.... by alcmena (Score:2) Thursday July 19 2001, @05:30PM
  • by Eryq (313869) on Thursday July 19 2001, @02:34PM (#73909) Homepage
    While I was working for the feds,
    I met a worm they called Code Red...
    And Code Red hit 100K hosts,
    And every host had 3 infections
    And every infection had 100 threads
    And every thread sent 100k
    And every k had a thousand bytes [*]
    And every byte was sent in 1 packet
    And every packet had a 40-byte header
    Headers, packets,
    Bytes, k,
    Infections, hosts and threads...
    Once every month, just to piss off the Feds.

    [*] 1024 just doesn't scan well. :-)
  • Re:China? by Nurgster (Score:1) Thursday July 19 2001, @02:04PM
  • Re:Affects IIS? by meta-monkey (Score:1) Thursday July 19 2001, @02:28PM
  • Impossible!! by Aerog (Score:1) Thursday July 19 2001, @01:59PM
  • by NewtonsLaw (409638) on Thursday July 19 2001, @02:08PM (#73913)
    My firewall is getting it about once every four or five minutes with probes coming mainly from servers based in countries along the Asian rim (Japan, Korea, etc).

    Fortunately, a trace of the sources indicate that the servers involved are being shut down pretty quickly by their admins.

    One alarming aspect is the number of these probes that are obviously coming from servers connected through PPP dial-up accounts.

    I wonder how many people have installed IIS on PCs running IIS and don't even know it's running?

    News With Attitude [7amnews.com]

  • by srvivn21 (410280) on Thursday July 19 2001, @01:52PM (#73914)
    From http://news.cnet.com/news/0-1003-200-6604515.html [cnet.com]
    ...each instance of the worm will attack the same computers in the same order, according to eEye's analysis. Maiffret said that while the addresses of the computers attacked by the worm seem to be random, because the worm uses the same starting point, or "seed," to generate the list, the "random" lists that any two worms generate are identical...
    You know that if this worm had been open sourced, that mistake would have been caught, and this would be an even better epidemic.
  • Heh: by TeraCo (Score:1) Thursday July 19 2001, @03:29PM
  • Re:So, who's REALLY in charge... by TeraCo (Score:1) Thursday July 19 2001, @03:37PM
  • Re:So, who's REALLY in charge... by TeraCo (Score:1) Thursday July 19 2001, @08:53PM
  • Re:If you don't run IIS but.... by PW2 (Score:1) Thursday July 19 2001, @07:35PM
  • by Guppy06 (410832) on Thursday July 19 2001, @02:25PM (#73919) Journal
    Seriously though, I hope this convinces the attourney general and the new district judge that Microsoft's monopoly has serious detriments on the internet as well as the industry.
  • Re:Windows Update by Sponge Bath (Score:1) Thursday July 19 2001, @02:07PM
  • Re:100,000 by Sponge Bath (Score:1) Thursday July 19 2001, @02:17PM
  • Re:what it looks like by 6EQUJ5 (Score:2) Thursday July 19 2001, @02:21PM
  • Re:So, who's REALLY in charge... by chemical55 (Score:1) Friday July 20 2001, @04:21AM
  • Re:what it looks like by jdavidb (Score:1) Thursday July 19 2001, @02:18PM
  • News flash from cmdrtaco! by jdavidb (Score:1) Thursday July 19 2001, @02:33PM
  • Re:Infrastructure Issues by MWLongworth (Score:2) Thursday July 19 2001, @02:12PM
  • Affects IIS? (Score:4)

    by ryanwright (450832) on Thursday July 19 2001, @01:52PM (#73927)
    a new Internet worm that takes advantage of a security flaw in Microsoft software

    Is this even worth mentioning? I mean, really! Don't all worms take advantage of security flaws in Microsoft software? Why can't someone write a worm to take advantage of Apache for a change? All of these Microsoft servers being compromised are making me jealous. If only I could afford a license of Win2k Server, then I could participate in the excitement as well...

    some day....
  • Re:So, who's REALLY in charge... by F00Fmaster (Score:1) Thursday July 19 2001, @03:42PM
  • Re:Update! by F00Fmaster (Score:2) Thursday July 19 2001, @03:37PM
  • Re:Probes coming from dial-up connections too! by moncyb (Score:1) Thursday July 19 2001, @05:30PM