If I were a hacker ...
Results 1 to 10 of 10

Thread: If I were a hacker ...

  1. #1
    Join Date
    Dec 2000
    Location
    Dallas, TX USA
    Posts
    2,916

    If I were a hacker ...

    Hackers normally have to scan the Internet looking for vulnerable systems. However, every Code Red probe I get identifies a system that doesn't have the latest MS patch.

    I wonder how many hackers are installing their own Trojans in Code Red infected systems?

    ------------------
    Jerry CTX
    Computer (In)Security

  2. #2
    IMM is offline Virtual PC Specialist!!!
    Join Date
    Nov 1999
    Location
    N. Vancouver, BC, Can.
    Posts
    2,438
    Some I spose. You won't be able to track all thos hits you get down - try it

  3. #3
    Join Date
    Oct 2000
    Location
    graham, tx, us
    Posts
    7,156
    Been gone for awhile, but have an observation. Some sources imply/say Code Red is big and bad, while others indicate not a problem. Which is it jerryctx, or is the info on your site?

    Or how about a short educational piece of your thoughts on the subject.

    ------------------
    Seek knowledge and all else will follow


    Please post back results - Press Ctl D to bookmark

    Information

  4. #4
    Join Date
    Dec 2000
    Location
    Dallas, TX USA
    Posts
    2,916
    Nothing on my site... Too many others tracking viruses and I don't cover server problems (Code Red only infects MS servers). A search of the web for "Code Red" should turn up lots of sites.

    It is "bad" in the sense that it has probably infected more servers than any other worm and it is affecting performance on the Net.

    ------------------
    Jerry CTX
    Computer (In)Security

  5. #5
    Join Date
    Sep 2000
    Location
    076W17 36N51
    Posts
    1,653
    I thought Code Red only used IIS machines as "zombies" to lauch Denial Of Services attacks on goverment sites... Am I missing Something?!? I've also read it only affects IIS4 and 5. I've heard different things about IIS6, WinXp Server...

    ------------------
    Don't click this!!!
    Do'nt take a Shock Rifle to a Flak Cannon fight...

  6. #6
    Join Date
    Feb 2001
    Location
    Adelaide, South Australia
    Posts
    6,447
    MiseryQ, that's true of the original Code Red, but the fact that a machine got infected with it reveals an underlying vulnerability - you know for sure that machine hasn't been patched. Code Red 2 includes installing a backdoor as part of its payload, so it would be trivial to launch CR2 at a machine then use that backdoor to mess with it. Or you could create your own custom attack. Basically, instead of servers sitting and silently waiting for a chance attack, you have servers jumping up and down yelling "Attack me! I'm insecure!" to the rest of the world.
    Safe computing is a habit, not a toolkit.

  7. #7
    Join Date
    Oct 2000
    Location
    graham, tx, us
    Posts
    7,156
    Would this be why that only certain segments of the web have had problems? Seems like the problems come and go.

    ------------------
    Seek knowledge and all else will follow


    Please post back results - Press Ctl D to bookmark

    Information

  8. #8
    Join Date
    Apr 2000
    Location
    The Sticks of Upstate New York (Wayyy north of Albany)
    Posts
    526
    Yet another reason to run Unix/Linux servers. Fortunately the majority are. I had that figure around here somewhere.... Oh yes, here it is. Approximately 62% of all internet servers run Apache, on Unix/Linux, that leaves 38% running various combos of MS NT, 2000, Novell, Solaris, blah, blah. Really though, is it that hard for the IT person to install a simple patch? Jeez, isn't that what this person is supposed to be doing for a living?

    ------------------
    A)bort,R)etry,I)nfluence with a large hammer.
    A)bort,R)etry,I)nfluence with a large hammer.

  9. #9
    Join Date
    Jan 2000
    Location
    Pittsburgh, PA, USA
    Posts
    1,176
    NeoGeek...
    not to be a pain, but could you document your sources....I think that figure is a little out dated...
    don't get me wrong, I'd use my linux box over an NT machine for any server stuff...
    I just think the figures are a little wrong...
    maybe I'm wrong though...


    ------------------
    Mark
    ------
    Please remember to post back about the updated status of your inquiry, we're here to help!
    zamiel
    the angel of hurricanes
    [email protected]

  10. #10
    Join Date
    Apr 2000
    Location
    The Sticks of Upstate New York (Wayyy north of Albany)
    Posts
    526
    http://www.netcraft.com/survey/

    ------------------
    A)bort,R)etry,I)nfluence with a large hammer.
    A)bort,R)etry,I)nfluence with a large hammer.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •