|
#1
| ||||
| ||||
| Code Red III
any one seen this,The logs are going crazy its supposedly called Nimda makes Code Red look like the folks on the retirement home ive gotten like 5 hits a min in contrast to Code Reds 68 per day this is for sure going to screw up M$ servers. Ive tried with no succes to modify,was it whitesaints scripts to count this new bastard.But my unix skills are limited. Check your logs its crazy!
__________________ Been through more shit than the toilet |
|
#2
| |||
| |||
|
What's the message in the log?
|
|
#3
| ||||
| ||||
|
I get the same thing. It's full of things like GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307 Fortunately, the latest BetterConsole has transparency and doesn't pop up all the way to the front when this happens.
__________________ CD MHz B&W GIII Rev I; DLXXVI MB RAM; MacOS X.I.IV, IX.II.II; Give me liberty, or at least a large order of fries. |
|
#4
| |||
| |||
| CERT message on new scanner |
|
#5
| ||||
| ||||
|
I also found something at Norton's website. The interesting thing is they don't say that Norton Antivirus for the PC can even detect it. I guess it's too early for that.
__________________ CD MHz B&W GIII Rev I; DLXXVI MB RAM; MacOS X.I.IV, IX.II.II; Give me liberty, or at least a large order of fries. |
|
#6
| |||
| |||
| CERT Advisory on Nimda worm a.k.a. "Concept Virus" |
|
#7
| ||||
| ||||
|
im sorry in the rush i said whitesaints scripts! but i reallly meant davidbrit2 scripts!
__________________ Been through more shit than the toilet |
|
#8
| ||||
| ||||
|
That <b>GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307</b> is actually the backdoor hack that Code Red II implements ... this thing tries 16 different ways to infect a server, the backdoor Code Red II made being one of 'em. Freakin annoying, I've already gotten over 100 hits from this in the past hour and a half! And I'm only on a dialup connection. I'd hate to have an all-the-time connection, your log would get to monstrous proportions (Let me gloat, it's not like I usually get to say "Yeah, my 56K modem that only connects at 31200 bps is better than your T1/Cable/DSL." Heh)I'm thinking I'll add to the daily script to clean out my http logs until this one blows over... |
![]() |
| Bookmarks |
| Thread Tools | |
|
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Doom III first previewed in 2001? | wdw_ | Apple News, Rumors & Discussion | 4 | May 25th, 2002 07:38 PM |
| That annoying little code red | davidbrit2 | Mac OS X System & Mac Software | 28 | September 7th, 2001 09:23 PM |
| Code Red Live Tracking! | theed | Apple News, Rumors & Discussion | 1 | August 8th, 2001 04:17 AM |
| Code Red: Pc users get screwed again!!! | Nachohat | Apple News, Rumors & Discussion | 4 | August 1st, 2001 07:51 AM |
| code red | vic | Bob's Place | 1 | July 26th, 2001 11:01 PM |