RE: Apache Worm / ddos

From: Golden_Eternity (bhodi_jabirat_private)
Date: Mon Jul 08 2002 - 09:00:39 PDT

  • Next message: Alexander Bochmann: "Re: Apache Worm / ddos"

    > many ppl talking about a "sloppy fashion" the worm was coded, and
    > that it is quite "harmless" because "it causes no damage"...
    >
    > What about the udp flood? Can anyone explain that?
    
    There are some strings that indicate that it is also designed for DoS (see
    below). Domas Mituzas reported that the worm attempts to listen on 2001/udp.
    I don't know why a compromised host would be the target of an attack,
    though. Perhaps someone who has looked over the source could give a better
    answer.
    
    	Cannot packet local networks
    	Udp flooding target
    	Tcp flooding target
    	Sending packets to target
    	Dns flooding target
    
    http://www.bhodisoft.com/Sec/apache-worm.txt
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Jul 08 2002 - 10:42:52 PDT