OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Chris H Mahn (chmahnduke-energy.com)
Date: Wed Aug 08 2001 - 06:24:58 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
    majordomoiss.net Contact issforum-owneriss.net for help with any problems!
    ----------------------------------------------------------------------------

     I've been getting quite a few RS Kills. The first slew of them was on the
    19th of July, and then they started up this past week. Most of them are
    going to addresses that are currently not being used.

     This has something to do with the code red worm, but I can't figure out
    what that something is. Can anybody proffer an idea? Thanks.

    Chris Mahn

                                                                                                         
                        Gene LeDuc
                        <Gene.LeDucmktdev.tns To: "'Ronald_W_Blacknavtrans.navy.mil'"
                        ofres.com> <Ronald_W_Blacknavtrans.navy.mil>, "Lindley, Jim
                        Sent by: (ISSAtlanta)" <JLindleyiss.net>
                        owner-issforumiss.net cc: issforumiss.net
                                                      bcc:
                                                      Subject: RE: Experiencing RealSecure Kills
                        08/06/2001 12:11 PM from Far East to nonexistant sy stems
                                                                                                         
                                                                                                         

    TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
    majordomoiss.net Contact issforum-owneriss.net for help with any
    problems!
    ----------------------------------------------------------------------------

    I got one last week with a genuine customer id. It was targetted at port
    80
    on a w95 machine that does not have a web server (or anything else
    listening
    on 80). I called the university that the packet came from and found out
    that the source box had been hit with code red at about the same time. Is
    this new behavior for CR?

    > -----Original Message-----
    > From: Ronald_W_Blacknavtrans.navy.mil
    > [mailto:Ronald_W_Blacknavtrans.navy.mil]
    > Sent: Friday, August 03, 2001 9:49 AM
    > To: Lindley, Jim (ISSAtlanta)
    > Cc: issforumiss.net
    > Subject: Experiencing RealSecure Kills from Far East to nonexistant
    > systems
    >
    >
    >
    > TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of
    > your message to
    > majordomoiss.net Contact issforum-owneriss.net for help
    > with any problems!
    > --------------------------------------------------------------
    > --------------
    >
    > Is anyone else seeing RealSecure Kills originating from
    > systems in the Far East
    > targeting nonexistant systems? I've seen numerous occurances
    > from more than
    > one site. This seems to be associated with the Code Red Worm
    > outbreak.
    >
    > ron___________________________________________________________
    > ___________
    >
    > Visit our World Wide Web site at: http://www.navtrans.navy.mil
    >
    >