[55304] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Anybody doing a "Code Green" for 1434?

daemon@ATHENA.MIT.EDU (Stewart, William C (Bill), SALES)
Mon Jan 27 00:35:55 2003

Date: Mon, 27 Jan 2003 00:35:19 -0500
From: "Stewart, William C (Bill), SALES" <billstewart@att.com>
To: <nanog@trapdoor.merit.edu>
Errors-To: owner-nanog-outgoing@merit.edu


Back when the Code Red worm came out, somebody wrote a program
that responded to Code Red probes by using the same hole to
break into the infected server and disable it.
Is anybody doing that with this worm?
Or does it step on the infected process too hard for that to work?

Even if people don't want to run it on the open internet,
due to concerns about appropriateness of reverse hacking,
it might be useful for inside-the-firewall cleanup=20
for corporations that get hit.

	Thanks;  Bill Stewart, billstewart at att dot com
			bill.stewart at pobox dot com

home help back first fref pref prev next nref lref last post