|
|||||||||||
|
Re: New CodeRed strain? -- UPDATE
From: Justin Pryzby <justinpryzby(at)users.sourceforge.net>
Date: Tue Apr 29 2003 - 18:13:53 EDT Note that this may simply be a confusion about the word 'packet'. I have interpretted said word to mean a single transmission from one host to another, such that there is a TCP SYN packet, then a TCP SYN,ACK packet, then a TCP ACK packet. Correct me if I'm wrong. > The packet itself appears to be classic CodeRed (II I believe), but
You said 'No TCP 3-way'. Do you mean that the initial GET is incomplete because of a TCP-layer problem? Is there any attempt at all by the remote host to send it? Do you maybe have a firewall which is watching the packets, noticing the first packet is C-R, and then blocking it? Obviously, the C-R detectors that are out there need to be improved, if simply sending the first GET.. Justin Pryzby
On Mon, Apr 28, 2003 at 01:13:00PM -0500, Frank Knobbe wrote:
Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the world's premier event for IT and network security experts. The two-day Training features 6 hand-on courses on May 12-13 taught by professionals. The two-day Briefings on May 14-15 features 24 top speakers with no vendor sales pitches. Deadline for the best rates is April 25. Register today to ensure your place. http://www.securityfocus.com/BlackHat-incidents Received on Tue Apr 29 18:39:03 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:04 EDT |
||||||||||
|
|||||||||||