|
|||||||||||
|
RE: code red---- on system that is already (and has been) patched
From: Sandy Ryan <SRyan(at)seewolf.com>
Date: Mon Mar 03 2003 - 19:44:03 EST
Well I don't
There are other logs that showed the system was being scanned looking for /c+ and /cmd.exe but those had a 404 indicator or a 500 - it was only the get /default.ida that had the 200 indicator... and it happened on one day 6 times. Since that day it hasn't showed up.... Strange and mysterious. Thanks for all your help Sandy Ryan
-----Original Message-----
Response 200 is an "OK-Request completed"
-----Original Message-----
I'm not 100% sure Sandy, but when I see Code Red hits (my server is patched, and patched on top of patched...) I see a 404 reply instead of a 200...
mike heitz ** sr it manager ** UPSHOT
-----Original Message-----
well - I doubt that the log is right - because I think the 200 implies that its not infected - by when my customer sees his report - and path taken through the site he sees worm.com here's the log (simplified to get through the moderator) GET /default.ida NN----NN%u9090%u6858%ucbd3%u7801...%u9090%u9090%u8190%u00c3%u0003%u8b00% u531b%u53ff%u0078%u0000%u00=a 200 0 206 4039 266 HTTP/1.0 [you know the url]- - - Received on Tue Mar 4 10:32:47 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:27 EDT |
||||||||||
|
|||||||||||