North American Network Operators Group|
Date Prev | Date Next |
Date Index |
Thread Index |
Author Index |
RE: Code Red : Any whitehouse.gov people around?
- From: Dave Stewart
- Date: Fri Jul 20 11:44:21 2001
At 10:04 AM 7/20/2001, Mike Najarian wrote:
While there's incomplete information available in the standard places, it
appears to be a hardcoded IP.
Has anyone gutted an infected box to determine whether it's going to go for
or a hardcoded IP?
I, along with many others, have null routed it.... Symantec's site claims
the IP address is no longer active at any rate.
It *appears* that from xx-20-xxxx through xx-28-xxxx, this thing will
attack that IP address... meaning that measures already in place will
minimize damage from the portion of the code that attempts to flood
18.104.22.168. Networks where 22.214.171.124 isn't blocked could see
network congestion, I suppose, if they host a large number of infected
I've seen a claim that if the date is greater than 28, the threads just go
into an infinite sleep.
From what I can see, I would expect another round of probes to take place
starting on 01-August-2001...