Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ALERT -- New IIS worm!

Status
Not open for further replies.

rycamor

Programmer
Jun 3, 1999
1,426
US
Check out
Apparenty this one is worse than Code Red. My Apache box has already had over 1000 attempts since this morning, and this is just my DSL firewall at home.

It infects IIS servers, and then does two things:
1) sends GET requests to infect other machines in the IP block
2) attaches a "readme.eml" file to every document server, which usually gets automatically executed by IE5+, thereby writing some changes to the registry, and emailing some registry information elsewhere.

DON'T browse with IE right now, Get Netscape, Mozilla, or Opera, please.
 
Yep, it looks like this is going to be a bad one. ISPs all over town are shutting down webservers and installing heavy-duty firewalls. These webservers have to be shut down until the firewall is in place, because some of them are getting attacks generating thousands of lines a minute in their logs.

So, even if you are not directly vulnerable, the virus simply mounts the biggest DoS attack yet seen on the Net.

Ironically, if you look at the link above for the internet traffic report, at the moment it shows 100% packet loss for ALL major routers. I don't think that is actually the case; this is obviously because they themselves have been blanketed by these IIS worm requests.

I've been lucky so far, only receiving 8300 requests since yesterday morning, but remember, this is for a private DSL connection. The public hosting services with Class B subnets are just getting killed.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top