RE: Nimda Worm

From: Sam Ferrell (ferrellat_private)
Date: Wed Sep 19 2001 - 11:54:33 PDT

  • Next message: Lists: "RE: nimda tries to send mail after reboot"

    On Wed, 19 Sep 2001, Patrick McBrien wrote:
    
    > Yes, our 3550 here is going nuts.  Sudden connectivity drops.
    
    Is the 3550 running http?
    
    I have had a 3620 and a 3640 decide to reboot on their own, and yes
    they are running http but access should be controlled with ACL. However,
    if someone behind the firewall, where access is granted, becomes infected
    then I suppose I could have some real problems!
    
    After code red came out, I remember seeing that there were certain cisco
    routers that ran a variation of IIS and were vulnerable, but I don't know
    which ones. I haven't seen cisco say anything about nimda.
    
    
    
    > -----Original Message-----
    > From: Sam Ferrell [mailto:ferrellat_private]
    > Sent: Wednesday, September 19, 2001 12:31 PM
    > To: incidentsat_private
    > Subject: Re: Nimda Worm
    >
    >
    >
    > Has anybody seen anything about this worm disrupting cisco routers?
    >
    > -s
    >
    >
    >
    > ----------------------------------------------------------------------------
    > This list is provided by the SecurityFocus ARIS analyzer service. For more
    > information on this free incident handling, management
    > and tracking system please see: http://aris.securityfocus.com
    >
    
    
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Wed Sep 19 2001 - 12:19:49 PDT