[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-users] The Code-Red Worm is attacking... GOD it's attacking.
- Subject: RE: [cobalt-users] The Code-Red Worm is attacking... GOD it's attacking.
- From: Michael <mike@xxxxxxxxxx>
- Date: Fri Jul 20 02:39:34 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
The worm does not infect unix systems, it only TRYS thats all. It is intended for microsoft servers.
At 11:04 AM 7/20/2001 -0400, you wrote:
>> I tried that command line and it came back zero.
>> Is this worm looking for US based servers by IP address or is it a world
>> wide phenomenon?
>>
>> Phil
>>
>
>It's supposed to be quasi-random in that all machines infected will generate
>the same set of random addresses (bad seed choice). I don't know whether it
>then filtered to ensure only US ips got hit (Why would they? In their minds
>the more machines they control the better)
>
>You may have been hit and are not seeing anything because your logs rotated.
>The worm turns its attention to whitehouse.gov when it sees a date of July
>20.
>
>I had 228 hits yesterday. 0 today.
>
>Cavan Kelly
>
>_______________________________________________
>cobalt-users mailing list
>cobalt-users@xxxxxxxxxxxxxxx
>To Subscribe or Unsubscribe, please go to:
>http://list.cobalt.com/mailman/listinfo/cobalt-users