»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Off Topic Community

Reply
 
LinkBack Thread Tools Display Modes
Old 03-13-2003, 07:55 AM   #1 (permalink)
Registered User
 
U-96's Avatar
 
Join Date: Oct 2001
Location: Silently running through the English Channel
Posts: 1,373
U-96 is on a distinguished road
Anyone notice increased Code Red scans

In the last few days my server firewall has gone mental. Most scans seem to originate in Taiwan and Korea. Of course I could be mean and say if Code Red gets your server this late in the day, find another job

Shields up kids!

U-96 is offline   Reply With Quote
Old 03-13-2003, 09:46 AM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Uh, Oregon . . . . y
Posts: 1,441
sharder8 is on a distinguished road
Send a message via ICQ to sharder8
Quote:
TrendLabs has received a significant number of infection reports on this worm from Japan and Italy. As of 4:59 AM March 12, 2003 (US Pacific Time), Trend has declared a Yellow Alert to control the spread of this malware.

This worm, similar to the other variants of CodeRed, makes use of a remote buffer overflow vulnerability in Microsoft's Internet Information Server (IIS) that can give system level privileges to an attacker. It drops a backdoor program on an infected Web server, giving an attacker full access to this Web server thereby compromising network security.

This worm poses no risk to Windows 95, 98, and ME users. Windows NT and 2000 users who do not have Microsoft's IIS Web Server installed are also at no risk. This worm only affects computers running Microsoft IIS that have not been patched with the Microsoft MS01-033 patch.

The only difference between this variant and the .C variant is that the older variant executes its reboot payload if the year is greater than 2002. This .F variant executes its payload if the year is greater than 34952.

This worm code only resides in memory, and there are no file counterparts. Because of this, antivirus scanners that do not support memory scanning will not be able to detect the code.

Further analysis is currently being done on this malware.

For more information on CODERED.F please visit our Web site at:
CODERED.F


Harder
sharder8 is offline   Reply With Quote
Old 03-13-2003, 10:00 AM   #3 (permalink)
Registered User
 
U-96's Avatar
 
Join Date: Oct 2001
Location: Silently running through the English Channel
Posts: 1,373
U-96 is on a distinguished road
thanks sharder8, useful to know. I'm getting 4-5 scans an hours at the moment
U-96 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:11 PM.