site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


guyver01
In Brightest Day

join:2001-01-04
Littleton, CO

reply to Steve

Re: Code Red II worm analysis

On the RR/NYC network here... my firewall has been going crazy the last day or two, with port 80 hits. So much so that i disabled popup notification. I was closing out literally dozens a minutes.

When will this thing go away
--
One only appreciates the beauty of the mountain top when one has experienced the agony of the climb
Said by DSLR member HAZE in the RoadRunner forum.


Steve
I know your IP address
Consultant
join:2001-03-10
Yorba Linda, CA
kudos:5

I'm still trying to wade through the IP address calculations, but I have a pretty good idea that the whole process starts with the current IP address of the machine. Depending on the munging that goes on, this could easily explain the scanning of "near" machines (which I'm of course seeing in my logs also).

It also excludes all IP addresses ending in .0 or .255 -- no surprise here

Steve
--
Stephen J. Friedl / Software Consultant / Tustin, California USA / »www.unixwiz.net


Sunday, 27-May 14:52:37 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics