Re: Code Red -- AGAIN?!?

From: Eric Hall (incidents.securityfocusat_private)
Date: Fri Nov 30 2001 - 13:34:46 PST

  • Next message: Bill_Roydsat_private: "Re: Proxy Scans to dial up hosts..."

    On Thu, Nov 29, 2001 at 11:10:36PM -0600, Emre Yildirim wrote:
    > Chip McClure wrote:
    > 
    > > -----BEGIN PGP SIGNED MESSAGE-----
    > > Hash: SHA1
    > > 
    > > I haven't had a CR scan in a few days. On both my home subnet of
    > > 24.219.x.x and a few of the class C address ranges I admin (216.52.x.x). I
    > > still see the occasional Nimda, though.
    > 
    > 
    > I've been getting alot of both lately.  Is there a new worm out or 
    > something?  This just happened very recently.
    > 
    
    	Its the 1st of the month again, at least in Asia
    right now (~21:30 GMT as I write this).  By tommorrow
    morning it should be going full-bore again.
    
    
    			-eric
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Sat Dec 01 2001 - 13:36:32 PST