RE: 'Code Red' does not seem to be scanning for IIS

From: Emre Yildirim (emre@vsrc.uab.edu)
Date: 07/20/01


Message-ID: <1274.138.26.156.240.995587211.squirrel@www.vsrc.uab.edu>
Date: Thu, 19 Jul 2001 19:00:11 -0500 (CDT)
Subject: RE: 'Code Red' does not seem to be scanning for IIS
From: "Emre Yildirim" <emre@vsrc.uab.edu>
To: <bugtraq@securityfocus.com>


> the worm just tries port 80 on ip's. doesnt care if its IIS or not.

This is weird. I just checked the www logs of one of our webservers, and
found about 144 hits in a 5 hours time span. There seems to be no pattern
either; the IPs are all random (although there were a lot of .cn and .tw
as wellas DSL hosts). One thing I've noticed is that the hits only appear at
certaintimes. I.e. from 15:25 to 15:31 we got about 27 hits, and there are some
other noticable times like 16:50 to 17:15. Maybe it's just a coincidence.

--
emre@unix.us.eu.org

(PS: Perhaps this should be posted to incidents@)



Relevant Pages

  • Re: NLB MPs & SMS DB
    ... I agree that IIS traffic would decrease but I wonder about the hit ... on the SMS DB now that all that communication between it and the MP is ... I guess I'm weighing up the reduction of IIS hits ... that NLB MPs is a good idea in that it spreads the load better and adds ...
    (microsoft.public.sms.admin)
  • Re: how many page hits specified date range
    ... logs like a database: ... There are other tools available try looking for "IIS Log Tool" on Google: ... >> Why not analyze the web server log files for thyis information ... >>>> Store individual hits, with timestamp, that way you are more data ...
    (microsoft.public.inetserver.asp.general)
  • RE: Code Red does not seem to be scanning for IIS
    ... 'Code Red' does not seem to be scanning for IIS ... > firewall to hosts that actually run public web servers, ... I've attempted to mail some places that their server is infected. ... there are no hits in its logs (though there were plenty for the cmd.exe ...
    (Bugtraq)
  • Re: Attack on /default.ida
    ... I've had 2 such hits in 2 days. ... Does codeRedCleanUp verify if the server has been affected? ... + is it only IIS ...
    (microsoft.public.inetserver.iis.security)
  • Re: serving static files
    ... million hits a day is an average of 23 hits per second. ... file cache keeps files around for at least 30 seconds. ... The IIS 6 cache keeps ... >>I plan to use a load balancer to balance it across 3 pretty beffy ...
    (microsoft.public.inetserver.iis)