A show of hands!

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
User avatar
Thorazine
Regular Member
Posts: 353
Joined: Tue Dec 14, 1999 12:00 am
Location: Washington, DC, USA

A show of hands!

Post by Thorazine »

How many of you are still seeing Code Red requests in your firewall logs? I'm at 80 different IP's and still counting.
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

I am and I know Fredra is too! :p
User avatar
onetrueday
Senior Member
Posts: 4796
Joined: Mon Nov 27, 2000 12:00 am
Location: Floating down a river of Dingleberry Juice

Post by onetrueday »

hmm... i'm not. Although what do they look like?
MSI 845 Ultra-ARU
p4 1.8a @ 47 BILLION
radeon8500 (4 HS's)
2 80gig WD se's raid0/120gig WD
30gigWD/15gigMaxtor/1.2gig WD
512megs corsair pc3000xms
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

Originally posted by onetrueday
hmm... i'm not. Although what do they look like?
A very unusually high number of hits on port 80! :)
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Re: A show of hands!

Post by blebs »

Originally posted by Thorazine
How many of you are still seeing Code Red requests in your firewall logs? I'm at 80 different IP's and still counting.
36, since the first of August and 143 through the end of July!
User avatar
ace
Posts: 5207
Joined: Sun Apr 22, 2001 12:00 pm
Location: Emerald Triangle looking for EA and some trainwreck!

Post by ace »

i am getting alot of them, can you tell me what they are from? :mad:
User avatar
W_I_Z_K_I_D
Regular Member
Posts: 363
Joined: Sun Jun 10, 2001 9:33 am
Location: !!!Your Computer-You Just Dont Know It YeT!!!

Post by W_I_Z_K_I_D »

---Hell yeah man i know where ya comin from..
i get code red requests all tha time..
just ignore'em man..they aint shi#
just a buntch off whato bee chinese hackers....
!!!What Man Can Make
Man Can Brake!!! :irate:

Windows XP ( Service Pack 2 )
Pentium 4 (3) GHz
2.00 GB of RAM

** Zone Allarm Pro
** AVG Anti Virus
** Cookie Wall
** Pop Up Stopper
** Spy Bot
** Spy Ware Blasster
** Add Aware se Pro
** Ccleaner
** Clean Up
** Port Bloacker
** Tweek UI WIn XP
** Port Scanner


Dialup 56k
DialUp-Syd.IPrimus....56k(Motorola internal Modem)
User avatar
fredra
Advanced Member
Posts: 847
Joined: Mon Mar 20, 2000 12:00 am
Location: Nepean, On, Canada

Post by fredra »

HEY...folks
There seems to be three (3) separate threads on the same topic here....
Pls go here
Port 80 HTTP scans.....
A man with a watch knows what time it is. A man with two watches is never sure.
User avatar
Thorazine
Regular Member
Posts: 353
Joined: Tue Dec 14, 1999 12:00 am
Location: Washington, DC, USA

Post by Thorazine »

Ace420,

The attacks are most likely coming from boxes around the inet that are infected with Code Red.
MrTRiX
Regular Member
Posts: 104
Joined: Fri Jun 29, 2001 2:47 pm
Location: Saskatoon, SK

Post by MrTRiX »

wizkid they may be wannabe's but that is good code. And is rather advnaced in the way it does what it does. All the way up to attacking whitehouse. I dont undertsnad why it does that.
I think I've done enough conventions to know how to spell Melllvar.
User avatar
Croc
Posts: 7818
Joined: Sat Jan 20, 2001 12:00 pm
Location: Up top East side Downunder

Post by Croc »

Check out what Steve Gibson has to say about his work with CodeRed.
Some interesting reading there at http://www.grc.com.
Allow the first page to take you to the second and you will find the info. Prepare for a big read.

Croc
Croc.
It will be long, it will be hard and there will be no withdrawal.
Winston Churchill
Remember: Wherever you go in life, you take yourself with you.
MrTRiX
Regular Member
Posts: 104
Joined: Fri Jun 29, 2001 2:47 pm
Location: Saskatoon, SK

Post by MrTRiX »

I set my firewall to tell me whenever TCP In Local 80 is checked and I am at 122 since I started my comp an hour ago. I would like to tell them but theres to many and they may already know. I was thinking that maybe the net should restat. I know it sounds big but once a computer is restarted Code Red is gone because it doesnt write anything to disk. So maybe restart and run the patch just before you start the server. Sounds big but from what I am seeing it sounds worth it.
I think I've done enough conventions to know how to spell Melllvar.
Post Reply