OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Russ (Russ.CooperRC.ON.CA)
Date: Sat Aug 04 2001 - 22:48:17 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----

    Just a quick FYI, there is a new version of Code Red which appears to
    be spreading rather rapidly.

    - - Appears to be a new re-write.

    - - Drops some sort of remote access trojan.

    - - Turns off System File Checker (Windows File Protection.)

    - - Moves CMD.EXE to the scripts directory in IIS

    - - Looks like the way they make the entry into code very differently
    than before.

    - - If your IDS is looking for "NNNN", forget it (but then you should
    have been shot if you used this string anyway)

    Cheers,
    Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor

    p.s. if we don't respond right away its because we're now going to go
    and light the fireworks here at my retreat. Might as well have lots
    of fireworks tonight!

    -----BEGIN PGP SIGNATURE-----
    Version: PGP Personal Privacy 6.5.2

    iQCVAwUBO2zCARBh2Kw/l7p5AQH95wQAqjGp7vRYK8SYky/ydyU1wxBmCe2c8Mpd
    DBdxrv+TY9112ZuH663ZspUOXThS9oeEyT4sdbVYNv8Z28nMipbioyTXYa5dw8po
    21tkilo6ZoGX+AmKJ6Kz7WDvMpHpEfzDr3JHGtxuev0/rclXeRSN4urypMR3YnRz
    uw5ZW/F3U/I=
    =OhCV
    -----END PGP SIGNATURE-----

    ----------------------------------------------------------------------------
    Delivery co-sponsored by Trend Micro
    ============================================================================
    TREND MICRO REAL-TIME VIRUS ALERTS
    If you would like to know about a virus outbreak before CNN and ZDNet get
    Trend Micro Virus Info Feed FREE. Simply copy and paste a small piece of
    code to give your visitors a real-time top 10 list and the latest virus
    advisories. Setup takes just 10 minutes and requires no server-side code on
    your Web site. All content is updated automatically from Trend Micro's Web
    site.
    http://www.antivirus.com/banners/tracking.asp?si=8&bi=237&ul=/syndication/
    vinfo/
    ----------------------------------------------------------------------------