OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Scott Wunsch (bugtraqtracking.wunsch.org)
Date: Wed Aug 01 2001 - 13:06:42 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Glancing at my Apache logs, I noticed what looked like a typical Code Red
    hit at 11:50:59 CST from 61.141.213.162 (which resolves to a name in .cn).
    I fired up my web browser and pointed it at that IP, wondering whether it
    was defaced by CRv1, or looked normal (i.e., CRv2).

    It appears likely to be defaced, all right, but not with the usual CRv1
    message. Could we have yet another new strain out there?

    In case the box has been cleaned up, I mirrored the defaced page at
    <http://www.wunsch.org/mirrors/codered/>. The text is as follows, in red
    on a black background:

    > fuck CHINA Government
    >
    > fuck PoizonBOx
    >
    > contact:sysadmcnyahoo.com.cn

    -- 
    Take care,
    Scott \\'unsch
    

    ... St... St... Stu... St... Stuttering Ta... Tagline.

    -----BEGIN PGP SIGNATURE----- Comment: Digitally signed

    iD8DBQE7aEUxe10JZB+UucMRAigbAKCh2L/QcGkn8oVCkLcQS51SUHFInQCg1uaz g+dFDp+0hn3DO5OMSX62Hno= =VGmp -----END PGP SIGNATURE-----