[Dshield] Code Red Host Scans (and more)
johnh at aproposretail.com
Sat Aug 4 17:57:20 GMT 2001
On Sat, 4 Aug 2001, John Groseclose wrote:
> It *looks* like the second worm is trying to reboot the machine via an
> exploit for cmd.exe, but since I don't have any Windows machines
> around to work with, I can't really do any experimentation with it.
> Perhaps someone wrote a "counter-worm."
Gawd, I hope not.
"Why does my webserver reboot itself every five minutes?"
Internal Systems Administrator
Apropos Retail Management Systems, Inc.
<johnh at aproposretail.com>
More information about the list