> many ppl talking about a "sloppy fashion" the worm was coded, and > that it is quite "harmless" because "it causes no damage"... > > What about the udp flood? Can anyone explain that? There are some strings that indicate that it is also designed for DoS (see below). Domas Mituzas reported that the worm attempts to listen on 2001/udp. I don't know why a compromised host would be the target of an attack, though. Perhaps someone who has looked over the source could give a better answer. Cannot packet local networks Udp flooding target Tcp flooding target Sending packets to target Dns flooding target http://www.bhodisoft.com/Sec/apache-worm.txt ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Mon Jul 08 2002 - 10:42:52 PDT