[21656] in bugtraq

home help back first fref pref prev next nref lref last post

Two birds with one worm.

daemon@ATHENA.MIT.EDU (Jason Hansen)
Thu Jul 19 14:30:47 2001

Date: Thu, 19 Jul 2001 11:27:55 -0600
From: Jason Hansen <jhansen@xmission.com>
To: bugtraq@securityfocus.com
Message-ID: <20010719112755.B11048@xmission.com>
Reply-To: jhansen@xmission.com
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

It looks like the "Code Red" worm has the added side effect of crashing
Cisco (675/678) DSL CPEs running any CBOS prior to 2.4.1. The GET it sends
looking for IIS servers hardlocks any modem with the web management
interface enabled.

CBOS v2.4.2 is unaffected.  Also, turning off the web interface with 'set
web disabled' also prevents the crashes.

	Jason Hansen

-- 
--------------------------------------------------------------------------
Jason Hansen                                          jhansen@xmission.com
      "The necktie is a serpentlike symbol of evil worn by humales."      
  ---from an Xist space transmission intercepted by the U.S. Navy, 1960.  

home help back first fref pref prev next nref lref last post