Re: Large ISP response to Code Red?

From: David Hickman (dhickman@yahoo.com)
Date: 07/31/01


Message-Id: <a05101000b78c83a74f69@[216.162.113.114]>
Date: Tue, 31 Jul 2001 10:49:13 -0500
To: Christian Kuhtz <ck@gnu.org>, incidents@securityfocus.com
From: David Hickman <dhickman@yahoo.com>
Subject: Re: Large ISP response to Code Red?

As an OpSec engineer, one of the bigger problems is getting the
downstreams to fix their systems. About 80% of the time, I have to
threaten null routing and admining down pvcs in order to get someone
to fix something.

dhh

At 20:45 -0400 7/30/01, Christian Kuhtz wrote:
>"Jon O ." wrote:
>> Have these ISPs confirmed they have taken action to prevent
>> an even worse reinfection phase than the first time and if not
>> why?
>
>Anything in particular that you have in mind for an SP to do 'to prevent an
>even worse reinfection phase' which is specific to Code Red? It's probably
>important to remember that there's a distinction to be made here between the
>SP's infrastructure and SP's customers.
>
>Cheers,
>Chris
>
>--
>Christian Kuhtz <ck@arch.bellsouth.net> -wk, <ck@gnu.org> -hm
>Sr. Architect, Engineering & Architecture, BellSouth.net, Atlanta, GA, U.S.
>"I speak for myself only."
>
>----------------------------------------------------------------------------
>This list is provided by the SecurityFocus ARIS analyzer service.
>For more information on this free incident handling, management
>and tracking system please see: http://aris.securityfocus.com

-- 

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Basic query tracing and profiling question...
    ... create all statistics. ... Well, that isn't a db problem, that's a management problem. ... out what is wrong requires a methodology. ... So in the sense of "fix your platform first," you seem to understand ...
    (comp.databases.oracle.server)
  • Re: SVCHost running at 99.9%
    ... Do you remember how you found the fix? ... The Virus checker is update to ... C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe ... I deleted the print driver via control panel - Server ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Project proposal -- Forth project organiser
    ... moderate time, that would benefit the Forth community? ... already has management, a culture, and tools, and you'll learn by using ... This is all not difficult to write for a single algorithm, ... My fear is that the fix to x in some way 'trips up' FPM ...
    (comp.lang.forth)
  • RE: Consulting Question
    ... As far as your management, I would write it up in an e-mail to the IT ... to help fix the problem. ... Subject: Consulting Question ... Considering some draft about how to publish a vulnerability, ...
    (Security-Basics)
  • Re: Is well written code a rare species ?
    ... It is sad that some employers need/want fast fixes ... > I usually only change the minimum necessary to fix a bug or to implement ... bugs will tend to repeat themselves. ... Sadly management often sees this as ...
    (comp.programming)