In article <[email hidden]>, myarse247 @hotmail.com says...
Quoted message said:Technician said:Ok, i know this is very off topic, please forgive me.
Those that have windows, specifically 2000, and possibly XP, if you do not intend to host a
website from your computer, uninstall the IIS service. if you need/want it, then make sure you
have the latest security patch for it.
Jeez Trav, you're just about as sharp as a button, and only two years behind on all the IIS
exploits.
I'm not behind, the people that are still vulnerable are behind.
Quoted message said:
Also, people shouldn't need to 'uninstall' IIS, because IIS is not installed by default in Win 2K
Pro or XP.
Already pointed out in another post.
Quoted message said:
Quoted message said:Within just this year, i have so far received 82 connections probing for an unpatched IIS
server. what it found was a non-vulnerable (to this attack) apache server running on Linux.
82 hits really isn't that much...
It is when they are 99% of my total connections.
Quoted message said:
Quoted message said:Among the network security community, these attacks are believed to be from a worm. I can't
remember what one, but it is either Nimda, Codered, or the new Codered II.
"New" Code Red II? Code Red II came out in August 2001.
Codered II changed into a slightly different variation within that last few months and has been
dubbed the new Codered II by several other network security analyst i have been in contact with. it
is not yet an entirely new version, just a slight variation.
Quoted message said:
You should be able to tell which worm it is, by analysing the command strings.
Well, i tried to post the packet data, but my ISPs news server seemed to take it as a binary post
(obviously the admin needs a swift kick in the butt as ASCII text surrounded by more ASCII text is
NOT binary). see megalink.netpacket data.txtOpen ↗ for packet data.
in any case, it is Codered II. i think it is even the newer variation, but i can't remember the
differences off the top of my head)
Quoted message said:
Quoted message said:So run virus scans and patch those IIS services if you must run them.
The Sources so far are fairly random. Lets see, i have gte.net, snet.net, direcpc.com,
swbell.net, megapath.net, cox-internet.com, verestar.net, interquest.net, cablerocket.net,
covad.net, rr.com, nuvox.net, astound.net, tds.net, bellsouth.net, aei.ca, arrival.net,
charter.com, and the list goes on.
They're usually infected machines that are just propogating the worm. As such, there'll be no real
pattern.
I knew there was no pattern, just listing some of the source ISPs. Though approximately 90% of the
hits come from broadband connections (though that could also be the percentage of users in the us
that have broadband).
Quoted message said:
Quoted message said:Again, i apologize for posting a message so blatantly off-topic, but i figured it was a notice
worth posting.
Although well meaning, you'd be better off advising about general pc security. Open NetBIOS shares
are far more commonly left open, and far more commonly exploited than an unpatched IIS.
Very true, but if you are using open shares you pretty much invite trouble (you don't rent a storage
unit and then leave the door unlocked). I think one of the more common problems now though are open
WiFi gateways. a friend of mine with a laptop and a WiFi card drove around with a WiFi War program
(with GPS) and managed to map out a very nice array of open gateways. he usually only makes use of
them by finding an openly shared printer and popping out a message like "warning, your wireless
network is insecure. I am printing this from my car while i drive by".
Nothing worse than a corporate network, locked down with a high grade firewall, and the latest
security patches everywhere, and some idiot installs a WiFi gateway so he/she can work from home,
thus removing the protection the firewall provides.
~Travis
--
To reply by email, remove clothes.
travis5765.homelinux.net, Primary Administrator TF Custom Electronic, Owner/Founder/Developer
(current project: Automotive exhaust flame-thrower)