RE: Code Red -- AGAIN?!?

From: Grimes, Shawn (NIA/IRP) (GrimesShat_private)
Date: Fri Nov 30 2001 - 05:15:59 PST

  • Next message: Grimes, Shawn (NIA/IRP): "Proxy Scans to dail up hosts..."

    	I had a few this morning coming from 156.101.1.5.  Blocked the IP at
    our firewall but maybe if I get some free time today I'll give them a call
    and tell them.
    
    
    Thank You,
    Shawn Grimes
    Computer Specialist
    NCTS - Gerontology Research Center
    410-558-8007
    grimesshat_private 
    
    -----Original Message-----
    From: Steve [mailto:steveat_private]
    Sent: Thursday, November 29, 2001 4:47 PM
    To: incidentsat_private
    Subject: Code Red -- AGAIN?!?
    
    
    Is anyone else other than me seeing another increase of code red scans and 
    of course the infected emails?  This morning alone I had 38 different 
    infected messages stopped at my email gateway and looking at my web logs, 
    there are numerous scans going on as well.
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Nov 30 2001 - 13:24:07 PST