[Dshield] port 80 "on the high side"

Witt, Allen DAVID.A.WITT at saic.com
Tue Mar 25 16:19:35 GMT 2003

The increase may be partly due to Code Red II. I'm still detecting attempts
on various web servers using the new variety with the xxxxx nop slide. Code
Reds go dormant after the 20'th of the month, but maybe something changed
besides the url..... Anyone else seeing this?


-----Original Message-----
From: Johannes Ullrich [mailto:jullrich at euclidian.com]
Sent: Monday, March 24, 2003 5:15 PM
To: list at dshield.org
Subject: [Dshield] port 80 "on the high side"

Its a bit early to call it a problem, but port 80 scans, in particular
the number of sources, are a bit on the high site if you look at it
as percentage of total submissions:


Given that a WebDAV exploit was released today, please take a quick look
at your web logs if you see anything odd.

jullrich at euclidian.com             Collaborative Intrusion Detection
                                         join http://www.dshield.org

list mailing list
list at dshield.org
To change your subscription options (or unsubscribe), see:

More information about the list mailing list