RE: Code Red -- AGAIN?!?

From: Grimes, Shawn (NIA/IRP) (GrimesSh@grc.nia.nih.gov)
Date: 11/30/01


Message-ID: <A7870A39A685D41195A200508BEF1345010EDE0B@c30.grc.nia.nih.gov>
From: "Grimes, Shawn (NIA/IRP)" <GrimesSh@grc.nia.nih.gov>
To: 'Steve' <steve@securesolutions.org>, incidents@securityfocus.com
Subject: RE: Code Red -- AGAIN?!?
Date: Fri, 30 Nov 2001 08:15:59 -0500


        I had a few this morning coming from 156.101.1.5. Blocked the IP at
our firewall but maybe if I get some free time today I'll give them a call
and tell them.

Thank You,
Shawn Grimes
Computer Specialist
NCTS - Gerontology Research Center
410-558-8007
grimessh@grc.nia.nih.gov

-----Original Message-----
From: Steve [mailto:steve@securesolutions.org]
Sent: Thursday, November 29, 2001 4:47 PM
To: incidents@securityfocus.com
Subject: Code Red -- AGAIN?!?

Is anyone else other than me seeing another increase of code red scans and
of course the infected emails? This morning alone I had 38 different
infected messages stopped at my email gateway and looking at my web logs,
there are numerous scans going on as well.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • RE: Malicious web sites
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: [incident] IIS defacement through FTP, possible DoS
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... > For more information on this free incident handling, management ... > and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Distributed ICMP/UDP scan or attack?
    ... This list is provided by the SecurityFocus ARIS analyzer service. ... and tracking system please see: http://aris.securityfocus.com ... For more information on this free incident handling, management ...
    (Incidents)
  • Re: strange attacks - flood udp packets from 1030 to msql
    ... > This list is provided by the SecurityFocus ARIS analyzer service. ... For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • RE: Can anyone identify this backdoor?
    ... > and tracking system please see: http://aris.securityfocus.com ... This list is provided by the SecurityFocus ARIS analyzer service. ... For more information on this free incident handling, management ...
    (Incidents)