Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » DSL Reports At Code Red Forefront » Busy busy busy
Uniqs:
163
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
Cisco 6xx DSL router vulnerability -- and fix. »
« Code Red II & PacBell  

Steve
I'm a PC, so shut up
Consultant
join:2001-03-10
Yorba Linda, CA

Busy busy busy

The first public report that I've been able to find of the Code Red II web server log signature was found right here at DSL Reports in this thread: http://www.dslreports.com/forum/remark,1224346;root=security,1;mode=flat . Since I had just written my websnarf tool, I checked my own system and found not only the web signature but a copy of the worm itself. Then it all started.

I knew that others would be doing the detailed analysis -- the boys at eEye are really good at this -- but I decided to do an ongoing update as well. BugTraq was strangely quiet for 12 hours on this, so DSLReports was one of the better places to go for Code Red II information for most of Saturday.

What a weekend.

Steve
--
Stephen J. Friedl / Software Consultant / Tustin, California USA / »www.unixwiz.net

mjf
" "
Premium,Mod
join:2000-08-05
New Orleans, LA
clubs:

Re: Busy busy busy

All I can say is that it is great to have you with us!

mr sean
Professional Infidel
Premium,ExMod 2001-07
join:2001-04-03
N. Absentia
clubs:

Re: Busy busy busy

A job well done Steve. Nice to have that kind of knowledge and dedication made available.
--
furiosus et melancholicus
Anon Thank you thank you thank you.

As a technical support supervisor for a broadband company, I have already dealt with several customers who have been infected by the latest round of the CRWv2. Thanks for the indepth analysis which I made a manditory read by my techs.

Excellent write up!

Thanks again

jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
·Speakeasy


Take off a little time for a good game of tennis. You've been hard at work for the benefit of many. Now it's time to rest a little on your laurels and relax for a moment or 2. Thanks for the great education and all the hard work.
[text was edited by author 2001-08-06 20:30:03]
Forums » DSL Reports At Code Red ForefrontCisco 6xx DSL router vulnerability -- and fix. »
« Code Red II & PacBell  


Saturday, 28-Nov 08:26:10 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [121] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [71] TiVo Sees Record Customer Losses
· [69] In-Flight Internet Headed For Bumpy Landing?
· [67] Verizon CEO: Hulu Will Be Dead Soon
· [62] Thanksgiving Open Thread
· [51] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Use MagicJack on Linux, PPC Mac [MagicJack]
· What to use while demonoid is down? [Filesharing Software]
· Nvidia Forceware for Windows XP\2000\03 195.62 [Software]
· speedtouch 516 -- frequent DSL drops [TekSavvy]
· Why does it take so long? Mail question [General Questions]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]