RE: UDP scans from CodeRed-infected hosts

From: Tony Langdon (tlangdonat_private)
Date: Tue Aug 07 2001 - 20:13:07 PDT

  • Next message: Antonio Vasconcelos: "Re: New Method for Blocking Code Red and Similar Exploits"

    > I am beginning to see UDP probes coming from servers which I 
    > had earlier 
    > identified as servers infected with CodeRed II.
    > 
    > Looks like things are about to become interesting.....
    
    Any information?  Port numbers, etc?
    
    So far, no indications here of UDP scans yet.
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Aug 08 2001 - 11:35:11 PDT