Code Red v3 is out
Sunday, August 5, 2001 by MobiusCo | Discussion: WinCustomize Talk
Also if anyone has looked at their stats for thier websites and seen high number failures to access a file called default.ida from my understanding this failure shows the server your site is hosted on was under attack but the ISP was smart and did the updates to prevent the attack from doing any damage.
Reply #2 Sunday, August 5, 2001 11:45 AM
Reply #3 Sunday, August 5, 2001 11:52 AM

Reply #4 Sunday, August 5, 2001 12:17 PM
code red also attacks certain cisco routers, but i am not sure if the newest code red affects them, or if it was only the first version.
Reply #5 Sunday, August 5, 2001 12:22 PM
here is a link to the one write up about the version three... And yes HeyYou I agree you always need to do the updates to protect yourself from the IIS and all other holes in the apps. That is why it is good to keep up to date on all patches, and developments. I thought it would be good to warn people about the new version release that hit the net yesterday.
Reply #6 Sunday, August 5, 2001 3:56 PM
1. What we explained is CodeRed exploit a vulnerability in IIS which is due by an unsecured dll. Everybody that runs IIS *have* to patch their system. That's it. We never said people with Unix or Linus server should patch or that if your firewall blocks inbound/outbound connection on port 80 you should be concerned (although patching is still a good thing to do). Still, if a PC contaminated by CodeRed sends me an malformed HTTP GET request (outbound connection), then there's good chance that inbound connections are also permitted which means they effectively have a "full hole" in their security, firewall or not. So they're vulnerable.
2. The firewall discussion wasn't really related to CodeRed anyway. It was just a variation of the current thread

Again, no offense here. Just wanted to clear things up

Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Sunday, August 5, 2001 11:39 AM
The most frightning thing is that all these IP I have in my log are in fact people who runs an unpatched version of IIS which are 100% vulnerable to other attacks. Since the virus only uses a known vulnerability from IIS, it means anybody can actually infiltrate one of these systems w/o the users even knowing it.
So if you happen to use IIS, BE CAREFUL AND DOWNLOAD THE PATCH ASAP!!!