[Dshield] Code Red Host Scans (and more)

John Hardin johnh at aproposretail.com
Sat Aug 4 17:57:20 GMT 2001

On Sat, 4 Aug 2001, John Groseclose wrote:

> It *looks* like the second worm is trying to reboot the machine via an
> exploit for cmd.exe, but since I don't have any Windows machines
> around to work with, I can't really do any experimentation with it.  
> Perhaps someone wrote a "counter-worm."

Gawd, I hope not.

"Why does my webserver reboot itself every five minutes?"

        John Hardin
        Internal Systems Administrator
        Apropos Retail Management Systems, Inc.
        <johnh at aproposretail.com>

More information about the list mailing list