Re: why the nimda upsurge again?

From: Dug Song (dugsong@monkey.org)
Date: 12/04/01


Date: Mon, 3 Dec 2001 23:10:30 -0500
From: Dug Song <dugsong@monkey.org>
To: Jose Nazario <jose@biocserver.BIOC.cwru.edu>

On Mon, Dec 03, 2001 at 01:27:27PM -0500, Jose Nazario wrote:

> in the past week or two i have noticed a strong upsurge in nimda probes
> and requests, and i know i'm not alone in this. while the bulk of the
> requests are local (given the mechanism it uses for addressing), several
> are from outside our network. there is no similar rise appearant in code
> red v1 or v2.

are you sure it's Nimda you're looking at?

we did see a slight surge in Nimda activity on our blackhole monitor,
but much smaller than when Nimda.E was introduced at the end of October:

        http://www.monkey.org/~dugsong/wormplot.png

-d.

---
http://www.monkey.org/~dugsong/

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Unexpected requests in IIS Logs
    ... you'd probably be seeing lots of other log entries that ... were very obviously Nimda. ... The fact that this request came from a client and went to your web ... requests right after and/or before these requests from the same IP address ...
    (microsoft.public.inetserver.iis.security)
  • Re: An unusual log entry
    ... >> I found this in my Apache log, among all the Nimda GET requests: ... Shaolin ...
    (comp.os.linux.security)
  • Unexpected requests in IIS Logs
    ... requests... ... After some research I had found two possible explanations... ... Although we have been patched for ages against Nimda, ... from one of our clients offices, if it is indeed some form of Nimda, it ...
    (microsoft.public.inetserver.iis.security)
  • Re: Unexpected requests in IIS Logs
    ... Install urlscan to filter all bad requests. ... > recently when I was doing security audits on my Web server I noticed these ... > Although we have been patched for ages against Nimda, ... > from one of our clients offices, if it is indeed some form of Nimda, it ...
    (microsoft.public.inetserver.iis.security)
  • why the nimda upsurge again?
    ... in the past week or two i have noticed a strong upsurge in nimda probes ... and requests, and i know i'm not alone in this. ...
    (Incidents)

Loading