Notices
Non Scooby Related Anything Non-Scooby related

Code Red II

Thread Tools
 
Search this Thread
 
Old 06 August 2001, 07:42 PM
  #1  
SL2
Scooby Regular
Thread Starter
 
SL2's Avatar
 
Join Date: May 2000
Posts: 319
Likes: 0
Received 0 Likes on 0 Posts
Post

This is a new worm that uses the exploit that code red uses, so make sure your servers are patched. I'm getting alot more of these attempts on my servers at work then the code red worm. Started seeing this one on saturday.
Old 06 August 2001, 07:58 PM
  #2  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

I'm all patched up at work.

A very useful free tool to check your servers over with to ensure you aren't vunerable.
Old 06 August 2001, 08:30 PM
  #3  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Unhappy

Anyone else had a buggered W2K SQL 7.0 server??? It had W2K SP2 & 7.0 SP3 & after applying the W2k anti-code red patch, on re-boot knackered SQL database Shafted dll...

May be a co-incidence but this is Microsoft we're talking about

Anyhow, its all back together & IIS is no-longer avail on that server (previous default install ) - just tedious
Old 06 August 2001, 08:43 PM
  #4  
WillieF
Scooby Regular
 
WillieF's Avatar
 
Join Date: Oct 1999
Posts: 778
Likes: 0
Received 0 Likes on 0 Posts
Talking

Personally Puff I wouldn't mix W2K and SQL 7 bit of a 'orrible Microsoft mix IMO.

Am I right in saying that you are a beta site for the latest DA systems masterpiece? If so and you have the time I would appreciate a wee chat offline if you don't mind...

[This message has been edited by WillieF (edited 06 August 2001).]
Old 06 August 2001, 10:37 PM
  #5  
kryten
Scooby Regular
 
kryten's Avatar
 
Join Date: May 2000
Posts: 869
Likes: 0
Received 0 Likes on 0 Posts
Post

Puff, what is it about you and computers?!
I've got Win2k, SQL 2000, Oracle plus lots of other stuff and the patches applied fine!

For anyone who's responsible for a server, I'd suggest getting the MS HOTFIX checker (don't think that windows update gets you ALL the fixes: it doesn't!) as well as subscribing to at least the MS security mailing list.

I've had 40 code red attempts per day on one of my machines (increasing each day since the first) and despite knowing I'd patched it, still panicked when I realised I'd not removed the .ida mappings from one website!
Old 06 August 2001, 10:57 PM
  #6  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

One of our web servers runs Win 2000 AS and SQL 2000 and no problems with the patch.

Not tried SQL 7 + W2000 with the patch though.

<BLOCKQUOTE><font size="1" face="Verdana, Arial">quote:<HR>I'd suggest getting the MS HOTFIX checker (don't think that windows update gets you ALL the fixes: it doesn't!) <HR></BLOCKQUOTE>

We've modified it to send e-mail alerts when missing hotfixes are found. I'll trade a copy for a beer or two.

ChrisB.

[This message has been edited by ChrisB (edited 06 August 2001).]
Old 06 August 2001, 11:51 PM
  #7  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Talking

Willie

Yup - no worries m8

Anytime (well work hrs )

020 7702 9900
07976 327 679

Heard that you'd surprised Sandra!!

Old 07 August 2001, 06:22 PM
  #8  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Question

Does anyone know what the real impact of the latest Code Red II is having on the Internet?

I am getting loads of HTTP access attempts (stealth blocked by my firewall), typically from 212.*.*.* addresses. The first batch (they are typically in threes) came two minutes into me connecting via dial-up.

Bloody kids!!

mb
Old 07 August 2001, 06:38 PM
  #9  
SL2
Scooby Regular
Thread Starter
 
SL2's Avatar
 
Join Date: May 2000
Posts: 319
Likes: 0
Received 0 Likes on 0 Posts
Post

It is spreading very quickly. You will mostly see the attacks, from computers on the same isp's network.

check this website
Old 07 August 2001, 09:54 PM
  #10  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Post

anyone know what requests would hit the firewall if an attack was taking place from the outside on a web server in the dmz?
Old 07 August 2001, 10:27 PM
  #11  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

SL2,

thanks for the GRC pointer (i should of thought of that in the first place )

It looks very worrying, because "part time" system managers won't know how to put all the bits back, once it's broken.

Why-oh-why do Microsoft write such (un-necessarily) complex code (with not enough error traps)

mb
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
Sam Witwicky
Engine Management and ECU Remapping
17
13 November 2015 10:49 AM
Ganz1983
Subaru
5
02 October 2015 09:22 AM



Quick Reply: Code Red II



All times are GMT +1. The time now is 09:24 PM.