From owner-freebsd-security Thu Mar 7 21:56:46 2002 Delivered-To: freebsd-security@freebsd.org Received: from web14805.mail.yahoo.com (web14805.mail.yahoo.com [216.136.224.221]) by hub.freebsd.org (Postfix) with SMTP id 2571E37B402 for ; Thu, 7 Mar 2002 21:56:40 -0800 (PST) Message-ID: <20020308055639.62629.qmail@web14805.mail.yahoo.com> Received: from [68.60.199.48] by web14805.mail.yahoo.com via HTTP; Thu, 07 Mar 2002 21:56:39 PST Date: Thu, 7 Mar 2002 21:56:39 -0800 (PST) From: krzysztof Strzelczyk Subject: Code Red?? To: freebsd-security@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hello, I've been going through docs and all signs indicate that this is a system infected with code red. [Fri Mar 8 00:00:50 2002] [error] [client 195.218.232.26] File does not exist: /usr/local/www/data/default.ida [Fri Mar 8 00:06:47 2002] [error] [client 217.128.238.66] File does not exist: /usr/local/www/data/default.ida [Fri Mar 8 00:09:46 2002] [error] [client 24.61.208.188] File does not exist: /usr/local/www/data/default.ida [Fri Mar 8 00:17:40 2002] [error] [client 61.132.208.81] File does not exist: /usr/local/www/data/default.ida [Fri Mar 8 00:26:55 2002] [notice] caught SIGTERM, shutting down If so, does anybody know how to break this down? Back to docs for me...... Thanks in advance -Chris __________________________________________________ Do You Yahoo!? Try FREE Yahoo! Mail - the world's greatest free email! http://mail.yahoo.com/ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message