image
image

Go Back   macosx.com > Mac Help Forums > Mac OS X System & Mac Software

Reply
 
LinkBack Thread Tools
  #1  
Old September 18th, 2001, 05:08 PM
fiznutz's Avatar
mind bender
 
Join Date: Jun 2001
Posts: 74
Thanks: 0
Thanked 0 Times in 0 Posts
fiznutz is on a distinguished road
Code Red III

any one seen this,The logs are going crazy its supposedly called Nimda makes Code Red look like the folks on the retirement home ive gotten like 5 hits a min in contrast to Code Reds 68 per day this is for sure going to screw up M$ servers.
Ive tried with no succes to modify,was it whitesaints scripts to count this new bastard.But my unix skills are limited.
Check your logs its crazy!
__________________
Been through more shit than the toilet
Reply With Quote
  #2  
Old September 18th, 2001, 07:21 PM
Registered User
 
Join Date: Jun 2001
Posts: 16
Thanks: 0
Thanked 0 Times in 0 Posts
offets is on a distinguished road
What's the message in the log?
Reply With Quote
  #3  
Old September 18th, 2001, 07:36 PM
Red Phoenix's Avatar
Registered User
 
Join Date: Mar 2001
Location: Columbus, OH
Posts: 605
Thanks: 0
Thanked 0 Times in 0 Posts
Red Phoenix is on a distinguished road
I get the same thing. It's full of things like

GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307

Fortunately, the latest BetterConsole has transparency and doesn't pop up all the way to the front when this happens.
__________________
CD MHz B&W GIII Rev I; DLXXVI MB RAM; MacOS X.I.IV, IX.II.II; Give me liberty, or at least a large order of fries.
Reply With Quote
  #4  
Old September 18th, 2001, 08:25 PM
Registered User
 
Join Date: Aug 2001
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
kegger64 is on a distinguished road
CERT message on new scanner

Go to:

http://www.cert.org/current/current_...ty.html#port80

for details...
Reply With Quote
  #5  
Old September 18th, 2001, 09:19 PM
Red Phoenix's Avatar
Registered User
 
Join Date: Mar 2001
Location: Columbus, OH
Posts: 605
Thanks: 0
Thanked 0 Times in 0 Posts
Red Phoenix is on a distinguished road
I also found something at Norton's website. The interesting thing is they don't say that Norton Antivirus for the PC can even detect it. I guess it's too early for that.
__________________
CD MHz B&W GIII Rev I; DLXXVI MB RAM; MacOS X.I.IV, IX.II.II; Give me liberty, or at least a large order of fries.
Reply With Quote
  #6  
Old September 18th, 2001, 10:11 PM
Registered User
 
Join Date: Aug 2001
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
kegger64 is on a distinguished road
CERT Advisory on Nimda worm a.k.a. "Concept Virus"

http://www.cert.org/body/advisories/..._FA200126.html

(Looks like it'll be a bad week for Windoze)
Reply With Quote
  #7  
Old September 19th, 2001, 02:34 AM
fiznutz's Avatar
mind bender
 
Join Date: Jun 2001
Posts: 74
Thanks: 0
Thanked 0 Times in 0 Posts
fiznutz is on a distinguished road
im sorry in the rush i said whitesaints scripts!
but i reallly meant davidbrit2 scripts!
__________________
Been through more shit than the toilet
Reply With Quote
  #8  
Old September 19th, 2001, 10:38 AM
Darkshadow's Avatar
wandering shadow
 
Join Date: Jul 2001
Location: DE, USA
Posts: 1,532
Thanks: 0
Thanked 0 Times in 0 Posts
Darkshadow is on a distinguished road
That <b>GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 307</b> is actually the backdoor hack that Code Red II implements ... this thing tries 16 different ways to infect a server, the backdoor Code Red II made being one of 'em. Freakin annoying, I've already gotten over 100 hits from this in the past hour and a half! And I'm only on a dialup connection. I'd hate to have an all-the-time connection, your log would get to monstrous proportions (Let me gloat, it's not like I usually get to say "Yeah, my 56K modem that only connects at 31200 bps is better than your T1/Cable/DSL." Heh)

I'm thinking I'll add to the daily script to clean out my http logs until this one blows over...
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Doom III first previewed in 2001? wdw_ Apple News, Rumors & Discussion 4 May 25th, 2002 07:38 PM
That annoying little code red davidbrit2 Mac OS X System & Mac Software 28 September 7th, 2001 09:23 PM
Code Red Live Tracking! theed Apple News, Rumors & Discussion 1 August 8th, 2001 04:17 AM
Code Red: Pc users get screwed again!!! Nachohat Apple News, Rumors & Discussion 4 August 1st, 2001 07:51 AM
code red vic Bob's Place 1 July 26th, 2001 11:01 PM


All times are GMT -5. The time now is 03:59 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0 RC1
Copyright 2000-2010 DigitalCrowd, Inc.