Code Red - same IPs or different?

From: Kee Hinckley (nazgulat_private)
Date: Wed Aug 01 2001 - 19:06:33 PDT

  • Next message: Sebastian Ip: "Re: Possible method to prevent spread of CodeRed and other simila r wo rms"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    I've seen numbers that seem to indicate that we've reached saturation 
    about half as many hosts as last time.  The question is--are these 
    new hosts, or did 50% of the server admins miss getting notified, 
    despite attempts to alert them?  If these were indeed old IP 
    addresses, I would have expected worm activity to start out at a much 
    larger level than last time, unless folks just rebooted their machine 
    and didn't actually install a patch.
    - -- 
    
    Kee Hinckley - Somewhere.Com, LLC
    http://consulting.somewhere.com/
    
    I'm not sure which upsets me more: that people are so unwilling to accept
    responsibility for their own actions, or that they are so eager to regulate
    everyone else's.
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP Personal Security 7.0.3
    
    iQA/AwUBO2i8jyZsPfdw+r2CEQIA/gCgstxkC4fz3LGpE6/qHXREnkYyAggAn2qK
    dESoorgLlmNLJGjsCkfA6cHo
    =JUCR
    -----END PGP SIGNATURE-----
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Aug 01 2001 - 21:09:10 PDT