RE: Wave of Nimda-like hits this morning?

From: Christopher L. Morrow (chris@UU.NET)
Date: 02/27/02


Date: Wed, 27 Feb 2002 01:44:43 +0000 (GMT)
From: "Christopher L. Morrow" <chris@UU.NET>
To: Brian Mooney <brian@medcontrax.com>


On Tue, 26 Feb 2002, Brian Mooney wrote:

> I have been seeing those scans pretty nonstop since the outbreak of
> Nimda. AT&T tells me that they have blocked Code Red, CRII, and Nimda
> upstream, but I still get this traffic 15 times a day or so. Yesterday,
> I had one IP hit my machine, looking for cmd.exe 27 times...
>

How did AT&T block these upstream from you? Unless they installed a proxy
firewall, or a router that can effectively do layer 4+ filtering I can't
see this being accomplished for all customers off a AT&T edge router.

Perhaps did they block this traffic on a firewall they manage for you?

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: Nimda E virus
    ... I have known Nimda come in through a dial up connection to IIS. ... was showing Nimda attacks every 5 minutes at its height. ... As I understand, a firewall is not ... >>| helpful messages from WIndowsUpdate. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Publishing Nimda Logs
    ... > by NIMDA and rewrites NIMDA to start patching the systems it infects. ... > were rudely hung up on, this after over 6 months of notifications to them ... > and their upstream ISP Sprint. ...
    (Vuln-Dev)
  • Blocking Nimda and kin
    ... quick fix for Apache which instantly blocks Nimda, ... It's more efficient to firewall the ... SetEnvIf Request_URI "/scripts/root\.exe" nimda ...
    (Bugtraq)
  • Re: Hacked.. AGAIN!!!!
    ... Sounds like Nimda to me. ... Why don't you get a Firewall like BlackIce ... Defender, ...
    (microsoft.public.inetserver.iis.security)
  • Missing something here.....
    ... Ok, we are having a problem with our external firewall, a Symantec Firewall ... I put the email server out in a DMZ. ... we were hit with the Nimda and Klez virus (damn users (well maybe damn ... blocked access to our site. ...
    (comp.security.firewalls)