Compatible Support Forums: Getting probed by Code Red

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Getting probed by Code Red

#1 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 02 August 2001 - 07:59 AM

Anybody here getting probed yet? My server at home got hit 4 times today (that I know of). I just started playing with ODBC logging to SQL so I could generate reports regarding usage, when I noticed this nice new "parameters" field that I have never bothered with before. Well, the reason why I noticed is that there are a bunch of "N"s followed by a specific series of characters. In addition, all four IPs were IIS boxes (1 from Spain, 2 from The Netherlands, and 1 from South Korea), all four were looking for the same file, and all four passed the same amount of info (via the parameter string, I imagine). I just wondered how many others have been swept here.
0

#2 User is offline   CUViper 

  • old hand
  • Group: Members
  • Posts: 1120
  • Joined: 23-January 00

Posted 02 August 2001 - 08:15 AM

I work at an isp, and today we were logging code red probes on our servers about every 15 seconds.... pretty insane...
0

#3 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 02 August 2001 - 08:24 AM

Ouch. Still kinda hard to believe that so much havoc can be averted with a patch that doesn't even require a reboot (at least in Win2K anyway).
0

#4 User is offline   Brian Frank 

  • Carpal Tunnel
  • Group: Members
  • Posts: 3088
  • Joined: 21-January 01

Posted 02 August 2001 - 08:56 AM

I got Win2k at home and grabbed that patch ASAP. I guess it's nowhere near as bad as for a server--which I have no clue how bad it must be for you guys.
Whew! Disaster avoided...for now. ;(
0

#5 User is offline   Toby 

  • enthusiast
  • Group: Members
  • Posts: 313
  • Joined: 17-January 00

Posted 02 August 2001 - 02:17 PM

No reboot eh? You lucky bastard wink

I've been patching 50+ servers and only a few Win2kSP1 managed to take the patch without reboot.

All with NT4 and Wink2SP2 I had to reboot.

The funny thing is that I was thinking about patching about 10 but when I ran the CodeRed-scanner it was over 50 boxes with IIS running 8)

If any of you want the app I was talking about send me a mail. Just type a range of ip:s and the app will scan them for unpatched IIS-boxes, great for a large network.

/Toby
0

#6 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 02 August 2001 - 04:19 PM

That's odd, Toby. I patched 5 servers running Win2K SP2, and none of them needed the reboot. Also, you will be getting an email from me.

smile
0

#7 User is offline   Ge0ph 

  • enthusiast
  • Group: Members
  • Posts: 220
  • Joined: 03-March 00

Posted 02 August 2001 - 04:36 PM

The patch requires at least SP1 and if you don't have that then you will need a reboot. However none of mine needed are reboot for just the patch.
0

#8 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 02 August 2001 - 06:01 PM

Cool, I thought I was going crazy for a moment there.

wink
0

#9 User is offline   waddy 

  • journeyman
  • Group: Members
  • Posts: 66
  • Joined: 02-August 01

Posted 02 August 2001 - 06:46 PM

i downloaded and installed SP2 about a week ago ...

yesterday i downloaded the patch for Code Red and it says i dont need it >??

is that right ?
0

#10 User is offline   Toby 

  • enthusiast
  • Group: Members
  • Posts: 313
  • Joined: 17-January 00

Posted 02 August 2001 - 07:23 PM

Quote:
Cool, I thought I was going crazy for a moment there.


Now it's me feeling like that, wondering why I had to reboot confused

I got the option to reboot later but did'nt wait. Anyway I have checked them all after reboot and the patch worked so it's safe....for now wink

Clutch you got mail...

Waddy, thats strange. Have you stopped the IIS-service, not that should matter it should install anyway...


/Toby
0

#11 User is offline   Toby 

  • enthusiast
  • Group: Members
  • Posts: 313
  • Joined: 17-January 00

Posted 02 August 2001 - 07:38 PM

While we're in the subject of pathing..

Go this site and dowload the trail *NOW* !!

This is one of the best products I have ever used and I'll keep telling that to my boss until I get money for licenses laugh

And no, I don't work for them wink

http://www.stbernard.com/products/updateexpert/products_updateexpert.asp

/Toby
0

#12 User is offline   cablehog 

  • newbie
  • Group: Members
  • Posts: 27
  • Joined: 08-May 00

Posted 28 August 2001 - 07:38 AM

Be warned! I too downloaded the Microsoft patch from their site the first day they offered it, but unfortunately, they came out with another one down the road because the first one didn't work. Go figure, here I was thinking, "Yeah, go ahead with your Code Red crap" and it turned out that I wasn't protected. Oh well. Just wanted to give a heads up!
0

#13 User is offline   HELLBRINGER 

  • addict
  • Group: Members
  • Posts: 468
  • Joined: 27-June 01

Posted 06 September 2001 - 07:37 AM

i get over 200 hits a day by it on my megabytemike.com server... damn that thing to hell... but i hate IIS and dont use it so it h as not caused any problems yet except for the annoying norton antivirus popping up every 5 seconds "YOU GOT THE CODE RED WORM!!!!!" lol so annoying...

how we rid of this thing anyway without restarting? i have an uptime of 47 days and i'd like to keep it that way. smile
0

#14 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 06 September 2001 - 07:49 AM

Install the patch, then reboot. That should clear it out and keep it from coming back. In addition, if you are infected you are generating a ton of traffic and would be in fact, part of the problem rather than the solution.

Also, CRII "installs" a backdoor that allows people to use your server for other tasks, and there are automated tools out there that will scan for these servers that are infected. So, it would be prudent to install the patch and reboot.
0

#15 User is offline   ftmiranda 

  • newbie
  • Group: Members
  • Posts: 36
  • Joined: 18-July 01

Posted 07 September 2001 - 05:38 PM

Quick question....

This RED CODE just affect Windows 2000 Server? or the PRO as well?
0

#16 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 07 September 2001 - 06:53 PM

Short answer; it affects Pro as well. Long answer:

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms01-033.asp
0

#17 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 07 September 2001 - 07:08 PM

Also, here is a tool for those that have been infected, but you should read the "CAUTIONS" section of this page. It points out that there may be other effects of these worms that may not be easily spotted.

http://www.microsoft.com/technet/treevie...ools/redfix.asp
0

#18 User is offline   kgeissler 

  • enthusiast
  • Group: Members
  • Posts: 362
  • Joined: 16-March 00

Posted 17 September 2001 - 08:32 PM

Here is a sample from my IIS 5 Log:

2001-09-17 01:34:10 209.39.238.104 - 10.160.20.14 GET /default.ida XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a 200 171 3818 63 HTTP/1.0 - - - -

Does this mean I am infected by the Code Red, or I am just being probbed? I have these sporatically in my IIS Log.

I ran symantec's tool to check and see if I have the code red, but it says it didn't detect it.

I have installed all the patches and such.

TIA
0

#19 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 18 September 2001 - 02:06 AM

That just means you are getting probed. If you use the IIS tool "URLScan", it will actually refer the incoming request against a set of rules, and will simply generate a 404 error and return that to the client.
0

#20 User is offline   clutch 

  • Carpal Tunnel
  • Group: Moderators
  • Posts: 3859
  • Joined: 29-March 00

Posted 19 September 2001 - 05:48 AM

Well, it appears that there's another automated tool for attacking web servers. Please look out for anything request is trying to get to the system directory. Atreyu and myself are getting pounded with the $hit out of nowhere, but URLScan has been canning all of the requests on my server.
0

Share this topic:


  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users