From owner-freebsd-isp Thu Sep 20 11: 6:42 2001 Delivered-To: freebsd-isp@freebsd.org Received: from mailsrv.otenet.gr (mailsrv.otenet.gr [195.170.0.5]) by hub.freebsd.org (Postfix) with ESMTP id 29DE737B405 for ; Thu, 20 Sep 2001 11:06:37 -0700 (PDT) Received: from hades.hell.gr (patr530-b027.otenet.gr [195.167.121.155]) by mailsrv.otenet.gr (8.11.5/8.11.5) with ESMTP id f8KI6VS25207; Thu, 20 Sep 2001 21:06:32 +0300 (EEST) Received: (from charon@localhost) by hades.hell.gr (8.11.6/8.11.6) id f8KHlBB23628; Thu, 20 Sep 2001 20:47:11 +0300 (EEST) (envelope-from charon@labs.gr) Date: Thu, 20 Sep 2001 20:47:10 +0300 From: Giorgos Keramidas To: Rob Secombe Cc: freebsd-isp@FreeBSD.ORG Subject: Re: Code Red?! Message-ID: <20010920204710.B23424@hades.hell.gr> References: <3.0.5.32.20010919104530.00795ca0@secombe> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="envbJBWh7q8WU6mo" Content-Disposition: inline In-Reply-To: <3.0.5.32.20010919104530.00795ca0@secombe> User-Agent: Mutt/1.3.22.1i X-GPG-Fingerprint: DB89 935F 85FC B995 91CA 4AEA 9F1D F31A C6B2 F5FC X-URL: http://labs.gr/~charon/ Sender: owner-freebsd-isp@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --envbJBWh7q8WU6mo Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Rob Secombe wrote: >=20 > These worms appear only to attack using the ip address of the server on > port 80 and not using a name, so at this stage they are not hitting the > virtual webs, ... No, using smbclient to browse infected hosts that ``attacked'' my dialup FreeBSD at home, I discovered nimda traces in virtual directories too. - giorgos --envbJBWh7q8WU6mo Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) iD8DBQE7qiuenx3zGsay9fwRAks2AJ9iaTMnosdpSX6rLGmHfot38SxWiQCgzkLq j9tBolgNa1RlUqe8yns6ZZE= =eIDB -----END PGP SIGNATURE----- --envbJBWh7q8WU6mo-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-isp" in the body of the message