Back to TF Net

From: Daniel O'Leary <Daniel_O'Leary@
To: All
Subject: Code Red Worm Blocked
Date:Fri, August 03, 2001 12:13 PM


Current News 08-2-2001 01:17 A.M:

Code Red Worm Blocked and logged.

Strange Web server log entries have been appearing with increasing frequency over the past several days. Thes have been traced to systems infected with the CODE RED worm. As usual, this system is mostly unaffected by the attacks plauging the most insecure platform on the planet WINDOWS! There is however, a Distributed Denial of Service (DDOS) impact caused by all those worm-ridden windows servers port scanning the internet for more Windows CPU's to exploit.

The log entries look similar to the following (taken from the logs from 08/02/2001:

8/02/01 23:07:52 ERR! mail.ecobit.hu. /default.ida?NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNu9090u6858ucbd3u7801u9090u6858ucbd3u7801u9090u6858ucbd3u7801u9090u9090u8190u00c3u0003u8b00u531bu53ffu0078u0000u00=a 0

These are designed to force a buffer overflow in the server and execute the code contained in the later part of the URL. If this is not enough to make you think twice about using WINDOWS on the internet, there is no hope for you - you will be a victim - It is only a matter of time.

These attacks are now being automatically logged separately from other errors and a web page has been developed and made available to view the current log. The administration here finds this most entertaining. The log can be found at the following URL:

http://kz.eaze.net/Code_Red.html
---
Daniel O'Leary, Admin/WebMaster KloneZone - A TeleFinder 5.7 BBS
Voice=> 817-367-2558 Dial-In=> 817-367-2517 Fidonet=> 1:130/1015
TFNet=> klonezone.tfnet.org Internet=> kz.eaze.net WWW=> http://kz.eaze.net


40


Running TeleFinder Server v5.7.
© Copyright Spider Island Software