Getting probed by Code Red
#1
Posted 02 August 2001 - 07:59 AM
#2
Posted 02 August 2001 - 08:15 AM
#3
Posted 02 August 2001 - 08:24 AM
#4
Posted 02 August 2001 - 08:56 AM
Whew! Disaster avoided...for now. ;(
#5
Posted 02 August 2001 - 02:17 PM
I've been patching 50+ servers and only a few Win2kSP1 managed to take the patch without reboot.
All with NT4 and Wink2SP2 I had to reboot.
The funny thing is that I was thinking about patching about 10 but when I ran the CodeRed-scanner it was over 50 boxes with IIS running 8)
If any of you want the app I was talking about send me a mail. Just type a range of ip:s and the app will scan them for unpatched IIS-boxes, great for a large network.
/Toby
#6
Posted 02 August 2001 - 04:19 PM
#7
Posted 02 August 2001 - 04:36 PM
#9
Posted 02 August 2001 - 06:46 PM
yesterday i downloaded the patch for Code Red and it says i dont need it >??
is that right ?
#10
Posted 02 August 2001 - 07:23 PM
Now it's me feeling like that, wondering why I had to reboot
I got the option to reboot later but did'nt wait. Anyway I have checked them all after reboot and the patch worked so it's safe....for now
Clutch you got mail...
Waddy, thats strange. Have you stopped the IIS-service, not that should matter it should install anyway...
/Toby
#11
Posted 02 August 2001 - 07:38 PM
Go this site and dowload the trail *NOW* !!
This is one of the best products I have ever used and I'll keep telling that to my boss until I get money for licenses
And no, I don't work for them
http://www.stbernard.com/products/updateexpert/products_updateexpert.asp
/Toby
#12
Posted 28 August 2001 - 07:38 AM
#13
Posted 06 September 2001 - 07:37 AM
how we rid of this thing anyway without restarting? i have an uptime of 47 days and i'd like to keep it that way.
#14
Posted 06 September 2001 - 07:49 AM
Also, CRII "installs" a backdoor that allows people to use your server for other tasks, and there are automated tools out there that will scan for these servers that are infected. So, it would be prudent to install the patch and reboot.
#15
Posted 07 September 2001 - 05:38 PM
This RED CODE just affect Windows 2000 Server? or the PRO as well?
#16
Posted 07 September 2001 - 06:53 PM
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms01-033.asp
#17
Posted 07 September 2001 - 07:08 PM
http://www.microsoft.com/technet/treevie...ools/redfix.asp
#18
Posted 17 September 2001 - 08:32 PM
2001-09-17 01:34:10 209.39.238.104 - 10.160.20.14 GET /default.ida XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a 200 171 3818 63 HTTP/1.0 - - - -
Does this mean I am infected by the Code Red, or I am just being probbed? I have these sporatically in my IIS Log.
I ran symantec's tool to check and see if I have the code red, but it says it didn't detect it.
I have installed all the patches and such.
TIA
#19
Posted 18 September 2001 - 02:06 AM
#20
Posted 19 September 2001 - 05:48 AM

Help










