> the worm just tries port 80 on ip's. doesnt care if its IIS or not. This is weird. I just checked the www logs of one of our webservers, and found about 144 hits in a 5 hours time span. There seems to be no pattern either; the IPs are all random (although there were a lot of .cn and .tw as wellas DSL hosts). One thing I've noticed is that the hits only appear at certaintimes. I.e. from 15:25 to 15:31 we got about 27 hits, and there are some other noticable times like 16:50 to 17:15. Maybe it's just a coincidence. -- emreat_private (PS: Perhaps this should be posted to incidents@)
This archive was generated by hypermail 2b30 : Thu Jul 19 2001 - 18:21:14 PDT