RE: Nimda Probes Stopped

From: Jonathan Rickman (jonathanat_private)
Date: Tue Sep 18 2001 - 19:02:41 PDT

  • Next message: Jim Forster: "RE: nimda tries to send mail after reboot"

    On Tue, 18 Sep 2001, Andrew Blevins wrote:
    
    > We are still seeing a large amount of probes on the west coast. As of 6:30
    > Eastern Time
    
    Same here. 21:56 EST Seems to come in waves. Several hundred probes in
    less than a minute, then nothing for sometimes as long as 20 minutes.
    Seeing more "repeat offenders" now though. We must be getting close to
    saturation...
    
    One of the organizations I alerted was a public utility company who's
    billing cycle ends on the 20th. A quick scan of their logs for older user
    agents reveals that MANY of their customers probably we're infected while
    trying to pay their bills. They have quite a mess to clean up...both on
    the technical side, and the public relations side.
    
    -- 
    Jonathan Rickman
    X Corps Security
    http://www.xcorps.net
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Tue Sep 18 2001 - 20:12:58 PDT